Home » Cloud Services » Microsoft 365

Cloud — Microsoft 365

Microsoft 365 support and administration for New York businesses

Your tenant holds your email, files, chat, and every identity in the company. Stedholm administers and hardens it as one platform — Entra ID, Intune, Defender, Exchange Online, Teams, and SharePoint — instead of five portals nobody owns.

Administration and hardening are the same job

Microsoft 365’s defaults favor collaboration over control, which is reasonable for Microsoft and risky for you. Out of the box: sharing links that work for anyone, mail protocols that bypass MFA, personal devices syncing company files, and admin roles held permanently by people who needed them once. A tenant set up on migration day and untouched since is the most common finding in our assessments.

We do not sell “support” that resets passwords while the tenant stays soft. Administration and hardening are one motion: every ticket is handled against a written configuration baseline, and every hardening change is sequenced so it does not break the way your people actually work. The same baseline feeds our security operations — sign-in logs, audit logs, and Defender alerts are monitored around the clock by our tooling, with engineer escalation.

This service is part of our cloud practice, and pairs with email security for the phishing problem specifically.

What we administer

One platform, six surfaces. Scope is written down per client; this is the standard footprint.

  • Entra ID

    Conditional Access policy design, MFA enforcement, legacy authentication shutdown, privileged roles granted just-in-time, and guest access reviewed on a schedule.

  • Intune

    Device enrollment and compliance policy, disk encryption enforcement, application deployment and updates, and remote wipe for the laptop that stays in the taxi.

  • Defender

    Anti-phishing, Safe Links, and Safe Attachments policy tuning; alert triage that ends with a human decision, not an unread email.

  • Exchange Online

    Mail flow and transport rules, SPF, DKIM, and DMARC done correctly, mailbox lifecycle, and shared mailbox hygiene.

  • Teams & SharePoint governance

    External sharing policy, site and team sprawl control, permission reviews, and retention configured deliberately rather than by default.

  • Licensing

    Quarterly right-sizing across Business Premium, E3, and E5 — the plan mix is an engineering decision, and unused seats are the cheapest finding in IT.

Hardened to be evidenced

For regulated firms, tenant configuration is compliance posture. NYDFS Part 500’s November 2025 amendments broadened who must use MFA; the FTC Safeguards Rule expects demonstrable access controls; client security questionnaires ask how sharing and retention are governed. We configure these controls so the evidence exists before anyone asks for it.

That matters most for the clients we build for: financial services firms certifying under NYDFS 23 NYCRR 500, law firms answering outside-counsel guidelines, and CPA firms operating the Safeguards Rule’s required elements.

We prepare and operate controls; we are not a law firm or an auditor, and we say so whenever the line matters.

How we take over a tenant

Nothing changes in your tenant until the plan is approved in writing.

  1. Baseline review

    A read-only assessment: identity posture, sharing configuration, mail authentication, device management state, licensing, and admin role inventory. You receive the findings document either way.

  2. Hardening plan

    Prioritized changes sequenced to avoid breaking workflows — Conditional Access ships in report-only mode first, users are told what will change and when, and every step has a rollback.

  3. Steady-state administration

    Tickets handled against the baseline, changes documented and attributed, monthly reporting, and a quarterly review of licenses, access, and anything Microsoft changed underneath us.

Common questions

Will hardening break the way people work?

Not if it is sequenced properly. We stage policies in report-only mode, review what would have been blocked, fix the legitimate cases, and only then enforce. The disruptive version of this work comes from flipping switches without that discipline.

Our Secure Score is decent. Doesn't that mean we're fine?

Secure Score is a useful signal and a poor finish line. It weights actions generically, ignores your regulatory context, and can be gamed by accepting risk in the console. We use it as one input to a baseline built around how your firm actually operates.

We still have on-premises Active Directory. Is that a problem?

No — hybrid identity is normal at this size. We manage Entra Connect sync, keep the on-prem side patched and monitored as part of infrastructure services, and plan the path to cloud-only where it makes sense.

Is Microsoft 365 data backed up automatically?

No. Retention and recycle bins are recovery conveniences inside the platform, not backup. We treat independent backup as part of running a tenant properly — the reasoning is on the cloud backup page.

Get your tenant onto a baseline you can defend.

Start with the read-only review — you keep the findings document whatever you decide.