Microsoft 365 and Entra ID, configured to be defensible
A default tenant is configured to work on day one, not to hold up when somebody asks how an account was accessed and by whom. The work here is the gap between those two states: mail flow, conditional access, retention, and audit trails set up for an organization that has to be able to answer that question.
What this practice covers
Microsoft 365 and Entra ID configured for organizations that need to defend their inbox and their identity surface. Compliance-ready audit trails, secure mail flow, conditional access, and routing automation for the mail that has to be acted on rather than read.
Identity is the first surface, because it is the one attackers actually go for. Conditional access decides which sign-ins are permitted from where and on what, so that a stolen password on its own does not get anybody in. The work is matching those rules to how the organization genuinely operates, since a policy strict enough to be admired and too strict to work with gets disabled within a fortnight.
Mail flow is the second. Secure routing, controlled retention, and the ability to say what was kept and for how long, which stops being an abstract question the first time somebody outside the business asks it. Retention in particular is a policy decision wearing a technical costume, and it wants deciding deliberately rather than inheriting a default.
Audit trails are the third and the one most often discovered missing. Logging that can reconstruct who accessed what, months later, for somebody who was not there, is what turns a security posture into something demonstrable. Retrofitting it after the fact is possible; having it from the start is considerably cheaper.
Who this is for
Professional-services organizations where confidentiality is the governing constraint rather than a preference. Law firms, practices, and advisory businesses whose inbox holds client confidences, contracts, and instructions that carry money, and where the cost of an incident is measured in obligations rather than inconvenience.
Regulated businesses that will eventually be asked to demonstrate a control rather than describe one. The distinction matters: a great deal of security work looks identical from the outside right up to the moment somebody wants the evidence, and that is the moment audit-ready logging either exists or does not.
And any organization at the point where the tenant has grown past what one person configured in an afternoon. Accounts belonging to people who left, permissions granted for a project that ended, and mailboxes nobody owns are the ordinary state of a tenant that has been running for a few years without anyone specifically responsible for it.
Shipped, not proposed
Anonymized by client request. The identity and retention engagement sits alongside the rest of what HDS does.
Mid-size law firm
Regional firm, partner-led. The mail estate was the firm's working record, which made how it was secured, routed, and retained a governing constraint on everything built around it.
- Secure M365 email pipeline with controlled retention
- Audit-ready access logging
The search layer built on top of that estate belongs to a different practice and is described under AI and autonomous systems rather than counted twice here.
What it is built on
Microsoft 365, Entra ID, Exchange Online, Conditional Access. Native Microsoft tooling rather than a third-party layer over it, because the controls that have to be demonstrable later are the ones the platform itself records. If your tenant is already configured and the honest finding is that it only needs a review rather than a project, that is what you will be told. Worth a conversation to talk about your tenant before anything is proposed.
Questions this practice gets asked
We already have Microsoft 365. What is left to do?
Having the licences and having the tenant configured are different things. A default tenant is built to work on day one for the widest possible range of customers, not to be defensible for yours. Conditional access, retention, and audit logging are all present and mostly unconfigured, which is exactly the state that looks fine until somebody asks for evidence.
What does conditional access actually change day to day?
For most people, very little, which is the point. It decides which sign-ins are allowed from where and on what, so a credential that leaks is not by itself enough to get in. Done badly it locks out the people trying to work; done properly it is a rule set matched to how the organization genuinely operates rather than a template applied wholesale.
Is this only relevant for regulated businesses?
Regulated organizations feel it first because somebody eventually asks them to prove it. The underlying exposure is the same for anyone whose email holds contracts, client confidences, or payment instructions, and the difference is only whether the consequence of an incident is a bad week or a disclosure obligation.
Can you handle a migration onto Microsoft 365 as well as configuring it?
Yes, and the configuration questions are best answered during the move rather than after. Retention rules, access boundaries, and mail routing are far cheaper to decide while the mailboxes are being moved than to retrofit onto a tenant people are already working in.
What does routing automation mean here?
Mail that has to be acted on rather than read. Inbound that carries operational load, filings, notices, requests with deadlines attached, gets classified and routed to whoever owns it instead of sitting in a shared mailbox until somebody notices. It is the same discipline as the rest of this practice: the cost of a miss is what sets the design.
Could you show who accessed what, if somebody asked tomorrow?
Start with a free scoping conversation with Mike Hyams, the person who builds and supports the work.