Diagnostic

Device & Endpoint Security Baseline

Standardize how devices are set up, secured, and owned, across Intune, Windows 365, and Azure Virtual Desktop.

"Every laptop is set up differently, I am not sure who is responsible for managing them, and remote access costs more than it should."

A smaller Compact scope (from $3,000) covers eligible bounded environments, confirmed before you pay.

5.0out of 5

Top Rated on Upwork · 100% Job Success · on every client-rated engagement, scored by Upwork. Delivered work →

What moves the number: tenants, sign-in, how many apps sign in through Microsoft 365, mail, Azure and endpoints. Headcount is only one of them. The scope-fit check tells you where you land →

What you walk away with

What you keep when this is done

You keep a written record of what is broken, what it is costing you, and what it costs to fix, in a form your leadership can act on. It also sets the fixed price of the fix, so nothing after this is open ended.

  • A single list of the laptops, desktops and phones signing in to your company data, showing which ones are managed and which ones are not.
  • A device by device table of which machines pass the security rules you already have in place and which fail them.
  • A cost comparison: what your desktops and remote access cost the way you run them now, against what the same setup would cost delivered from Microsoft's cloud, on Windows 365 or Azure Virtual Desktop.
  • The places where your device rules and your sign-in rules do not line up, including the gap that lets a device you do not manage sign in anyway.
  • The order to fix it in: which settings to standardize first, how a new laptop should arrive already set up, and what can wait. Enrolling devices and applying the settings are quoted separately.

The card is the tenant-wide posture summary, where devices are one of its four rows. The device by device inventory, the compliance table and the cost model this diagnostic produces sit underneath that one row.

How the diagnostic works

01Read-only inspection

Your live environment is inspected directly, read-only. Nothing changes and nothing breaks.

02Findings, scored and priced

You see what is actually risky, what it is costing you, and a fixed quote to fix what matters. Ranked in plain language.

03Your plan, either way

The remediation plan is yours to keep. Take the fix at the quoted price, or hand the plan to your own team or another vendor.

This is for you if

  • You have a real decision or risk on the line: an audit, a renewal, a migration, a board question, or an AI rollout.
  • You want findings at the sample report's level of specificity: named roles, quantified waste, tested assumptions.
  • You want the price fixed in writing before the work starts.

It is not for you if

  • You need a quick checkbox scan rather than findings you plan to act on.
  • You are looking for open-ended staff augmentation with no defined finish line.

After the diagnostic

Remediation is scoped from the evidence

Remediation is quoted as a fixed scope rather than open-ended hours. The diagnostic shows exactly which of these you need, and what it should cost.

Stabilize

Close the urgent gaps the evidence surfaced, on a fixed scope, before they become an incident.

Control

Stand up the controls and operating model the environment was missing, in staged, measurable releases.

Oversee

Fractional Architecture Oversight once the foundation is in place: scheduled senior review on a defined monthly cadence, offered as a follow-on. Implementation is separately scoped.

Delivery, access, and scope boundaries

Typical delivery

10 business days, elapsed. The window begins after the scope is confirmed, the kickoff is complete, required access works, and requested exports and documentation have been provided. Client, licensing, or third-party delays pause the timeline.

Access needed

Read-only Intune, Entra ID and Defender reporting, including device inventory, compliance, configuration profiles, Autopilot and application information. Access is time-limited, protected with MFA, and read-only wherever the platform allows. Credentials should never be submitted through the website.

Not included

No device enrollment, policy deployment, Autopilot rebuild, application packaging, end-user support, or remediation.

Every assessment includes one kickoff and one findings review; extra workshops or revision rounds are a change order. Unless the signed statement of work says otherwise, no assessment includes production changes, remediation, implementation, emergency incident response, 24/7 availability, software or licensing costs, legal attestation, or third-party vendor fees. The signed statement of work controls if it differs from this page.

$4,250

Device & Endpoint Security Baseline

Talk through the problem