Three things, in the order we are strongest.
| Managed Intune$6 per device per month | Security and hardeningfrom $250, fixed price | MSP support, Level 2 and 3hourly or a monthly block | |
|---|---|---|---|
| Who it is for | Firms of ten to a hundred people that have Intune and nobody whose job it is to look after it. | Firms being asked for security evidence by a client, an insurer or their own board. | MSPs and IT firms that need Microsoft depth without hiring a specialist. |
| What it covers | Enrolment, configuration, apps, update rings and endpoint security, with a monthly drift review. | Your Microsoft 365 and endpoint estate measured against a published standard, then brought up to it. | Level 2 and 3 escalation on Intune, Entra, Defender and Microsoft 365, on your tools and under your name. |
| What you get out of it | Devices that stay compliant without anybody chasing them, and a monthly report a director or an insurer can read. | The evidence pack that answers a client questionnaire instead of stalling the deal, licence waste removed, and the gaps closed before somebody else finds them. | Tickets that stop bouncing back to the same queue, and your own engineers learning from the notes we leave behind. |
| Standards it maps to | CIS Microsoft 365 and Windows benchmarks | NIST CSF 2.0, CIS benchmarks, ACSC Essential Eight | Whatever your client contracts already require |
| How it runs | Month to month. Stop any month. | A fixed price project, two to four weeks. | Agreed up front, with non solicitation in writing before the first ticket. |
| Access we need | Least privilege named accounts or a GDAP relationship. Never standing Global Admin. | Read only to assess. Agreed admin, logged, to fix. | Whatever your PSA and tenant model already allows. |
| First step | A baseline of your tenant in month one, with the broken and risky bits in writing. | The $250 Health Check, two days. It comes off the price if you go on to the full assessment. | A call, then one real ticket to see how we work. |
| Price | $6per device per month, minimum $300 | $250 to $750hardening by fixed quote | By arrangementhourly or a monthly block of hours |
| Read more | Managed Intune → | Security and hardening → | MSP support, Level 2 and 3 → |
Managed Intune
- Who it is for
- Firms of ten to a hundred people that have Intune and nobody whose job it is to look after it.
- What it covers
- Enrolment, configuration, apps, update rings and endpoint security, with a monthly drift review.
- What you get out of it
- Devices that stay compliant without anybody chasing them, and a monthly report a director or an insurer can read.
- Standards it maps to
- CIS Microsoft 365 and Windows benchmarks
- How it runs
- Month to month. Stop any month.
- Access we need
- Least privilege named accounts or a GDAP relationship. Never standing Global Admin.
- First step
- A baseline of your tenant in month one, with the broken and risky bits in writing.
- Price
- $6, per device per month, minimum $300
Security and hardening
- Who it is for
- Firms being asked for security evidence by a client, an insurer or their own board.
- What it covers
- Your Microsoft 365 and endpoint estate measured against a published standard, then brought up to it.
- What you get out of it
- The evidence pack that answers a client questionnaire instead of stalling the deal, licence waste removed, and the gaps closed before somebody else finds them.
- Standards it maps to
- NIST CSF 2.0, CIS benchmarks, ACSC Essential Eight
- How it runs
- A fixed price project, two to four weeks.
- Access we need
- Read only to assess. Agreed admin, logged, to fix.
- First step
- The $250 Health Check, two days. It comes off the price if you go on to the full assessment.
- Price
- $250 to $750, hardening by fixed quote
MSP support, Level 2 and 3
- Who it is for
- MSPs and IT firms that need Microsoft depth without hiring a specialist.
- What it covers
- Level 2 and 3 escalation on Intune, Entra, Defender and Microsoft 365, on your tools and under your name.
- What you get out of it
- Tickets that stop bouncing back to the same queue, and your own engineers learning from the notes we leave behind.
- Standards it maps to
- Whatever your client contracts already require
- How it runs
- Agreed up front, with non solicitation in writing before the first ticket.
- Access we need
- Whatever your PSA and tenant model already allows.
- First step
- A call, then one real ticket to see how we work.
- Price
- By arrangement, hourly or a monthly block of hours
A small fee against a real number.
A questionnaire you cannot answer
A bigger customer or an insurer asks for evidence of MFA, encryption and patching. Until you have it the deal waits. The report that answers it starts at $250.
Seats nobody is using
Unused and wrongly assigned licences turn up in most tenants we look at, on a tenant of any size that often covers the fee on its own. That saving then repeats every month.
Drift you notice after the incident
$6 per device per month. Fifty devices is $300, our minimum, and that is the whole job: drift review, apps, update rings, requests and a report. Not an hour of somebody's time.
Firms that have Microsoft 365, and nobody to run it.
Compliance numbers nobody investigates
The dashboard says 14 devices non compliant. It said 11 last month. Nobody knows which ones, or why.
A Company Portal full of old versions
Apps packaged at rollout and never touched since, so people install the current version themselves, outside Intune.
Update rings nobody adjusted
Deferrals set in 2024, deadlines that never fire, and a Windows 11 upgrade stalled at 60 percent.
No evidence when it is asked for
A client or an insurer wants proof of encryption, patching and MFA, and nobody can produce it from the tenant.
Not sure where you stand? Ten questions, two minutes, no email →
Four steps, no surprises.
A 15 minute call
You describe the business and the fleet. We tell you honestly whether it is ready to be managed or needs fixing first.
Access you approve
Least privilege named accounts with MFA, or a GDAP relationship. Never standing Global Admin. Switch it off any time.
A baseline in writing
Every policy, app, ring and enrolment setting documented in month one, with the broken and risky bits flagged.
The monthly cycle
Drift review, apps updated, rings checked, requests handled, and a report a director or an insurer can read.
The kind of jobs we actually do.
Intune from nothing
Enrolment, compliance, Conditional Access and disk encryption from a blank tenant, then kept running month to month since October 2025.
Read more →Windows and Mac, one console
Entra ID Platform SSO on macOS, FileVault escrow, Defender on both platforms, Apple Business Manager for zero touch setup.
Read more →Apps that install the same way every time
Installers wrapped to run silently, detection rules that check a real file version, every package tested clean and on an upgrade.
Read more →