Microsoft security

Microsoft security services that decide what people, and AI, can reach

Identity, email and app, endpoint and data protection configured in the Microsoft 365 you already license, so attacks are stopped and AI assistants only see what each user should.

Free · about one week · read-only

Most organizations already own the controls. We switch them on properly.

Microsoft 365 security services that decide what people and AI can reach

Short answer

Communication Square configures Microsoft security for businesses and public agencies: identity protection with Entra ID, email and app protection with Defender for Office 365, endpoint protection with Defender for Endpoint and Intune, and data protection with Purview sensitivity labels and data loss prevention. The same controls decide what Copilot and other AI assistants can reach.

Starting points

Where Microsoft security services usually start

Identity“We have had a compromised account.”MFA, conditional access and sign-in risk policies so one password is never enough.See identity protection
Email“Phishing keeps getting through.”Defender for Office 365 policies, safe links and attachments, and user reporting.See email protection
Data“We are about to switch on Copilot.”Sensitivity labels, DLP and oversharing clean-up before AI sees your files.See the AI readiness assessment

The cost of waiting

Breaches cost more when AI is ungoverned

$4.99Mwas the global average cost of a data breach in 2026, and $5.39M when shadow AI was involved.Source: IBM Cost of a Data Breach 2026, via Cybersecurity Dive
92%of organizations with an AI-related security incident lacked proper AI access controls.Source: IBM Cost of a Data Breach 2026, via Cybersecurity Dive

What it really is

Security you own is not security you have

Most Microsoft 365 plans already include strong controls. The gap is configuration: switched off, half set up or never tuned.

Identity protectionMFA, conditional access, privileged access.
Email and app protectionPhishing, malware and risky apps.
Endpoint protectionDefender for Endpoint with Intune policy.
Data protectionLabels, DLP and retention with Purview.
Agent identityOwners and least privilege for AI agents.
MonitoringAlerts watched and acted on.

Your options

Leave the defaults, buy another tool, or configure what you own

The cheapest security improvement is usually the one already in your license.

Microsoft defaultsAdd a third-party toolConfigure what you own (us)
CostIncludedAnother subscriptionIncluded licenses, fixed-price setup
CoveragePartialOne areaIdentity, email, endpoint and data
AI exposureNot addressedRarelyLabels and DLP decide what AI can reach
MonitoringNoneVendor consoleManaged service option, monthly report
Government cloudVariesOften unsupportedGCC and GCC High delivered

What is included

What the work covers

Identity protection

Entra ID MFA, conditional access, sign-in risk and privileged access, including service accounts and AI agents.

Email and app protection

Defender for Office 365 policies, safe links, safe attachments and app governance.

Endpoint protection

Defender for Endpoint onboarding with Intune policies and attack surface reduction.

Data protection

Purview sensitivity labels, DLP, retention and oversharing clean-up before AI.

Secure Score review

Baseline and target Microsoft Secure Score, with each change documented.

Monitoring option

Alerts watched and triaged under AI-powered managed services.

Our approach

From findings to configured controls

  1. AssessRead-only review of identity, email, endpoint and data settings.
  2. PlanRanked fixes with user impact and a fixed price.
  3. ConfigureControls switched on in stages, piloted with a small group first.
  4. Hand overDocumentation, admin training and optional monitoring.

Our promise: every change is piloted before it reaches everyone, and documented so your team can see exactly what was set.

AI on this foundation

The controls that decide what AI can reach

Copilot and every AI assistant inherit the permissions and labels in your tenant. Getting security right is most of getting AI right.

AI data readinessLabels and DLP before Copilot or agents go live.
Agent identitiesOwners, least privilege and access reviews for agents.
Prompt and output controlsDLP that stops sensitive data entering AI tools.
Shadow AIApproved tools inside your tenant instead of blocked ones.

Proof

Where we have done this

Ongoing
City of Osage BeachMicrosoft 365 GCC with 24×7 threat alerts, identity protection and Microsoft 365 support.Identity · threat monitoring · GCC
Renewed yearly
Charter Township of YpsilantiMicrosoft 365 G3 in the Government Community Cloud with Defender for Office 365, awarded by RFP.Defender for Office 365 · GCC
Delivered
Metropolitan Community College, Kansas CityMulti-factor authentication and Microsoft 365 security hardening alongside an Azure migration.MFA · security hardening · Azure

See our government record

The offer

Start with a free Microsoft 365 assessment

A read-only look at your tenant: licenses, accounts, security hygiene and what this project would involve, with a fixed-price plan you keep.

Current-state map

Licenses, accounts and configuration as they are today.

Risk and gap list

What to fix first, ranked by risk and effort.

Plan and fixed price

Scope, timeline and a fixed price for the work.

  • Free for customers and non-customers
  • About one week
  • Read-only: nothing changes
  • The plan is yours to keep

Why free? It is how we scope a fixed price we can stand behind, and it shows you what to fix whether or not you hire us.

How it runs

Day 0Scoping call with the engineer who would run the work.

Days 1–2You grant temporary read-only access.

Days 2–4We review the environment.

Day 5Findings and a fixed-price plan. Access is removed.

We reply within one business day.

Read-only access you grant and remove. Nothing in your environment changes, and no content leaves your tenant.

Why us

A Microsoft partner that builds, licenses and runs it

Microsoft Solutions PartnerData & AI, Infrastructure and Digital & App Innovation (Azure) and Modern Work designations, recognized by Microsoft.
Tier-1 Cloud Solution ProviderLicenses, projects and managed services from one partner.
Government cloud authorizedAOS-G for GCC High; GCC delivered for agencies every year.
We stay after go-liveAI-powered managed services keep it running and reported.
Microsoft Solutions Partner designations: Data & AI, Infrastructure and Digital & App Innovation (Azure) and Modern Work

Transparent investment

What the work typically costs

Published, fixed prices for the common cases. The free assessment confirms scope before you commit.

EngagementTypical timelineTypical investment
Microsoft 365 security assessmentAbout one weekFree
Identity and email protection: MFA, conditional access, Defender for Office 3652–3 weeks$6,900
Endpoint protection: Defender for Endpoint with Intune policiesAbout 3 weeks$7,900
Data protection and AI readiness: Purview labels, DLP, oversharing clean-up3–6 weeksFrom $9,900
Complete Microsoft 365 security program (all four areas)6–10 weeks$24,900
Ongoing monitoringMonthlyFrom $500 a month

Fixed prices cover up to 250 users; larger estates are priced in the free assessment. License upgrades, where needed, are at Microsoft’s price.

EngagementTypical timelineTypical investment
Microsoft 365 security assessmentAbout one weekFree
Identity and email protection: MFA, conditional access, Defender for Office 3652–3 weeks$14,900
Endpoint protection: Defender for Endpoint with Intune policiesAbout 3 weeks$29,900
Data protection and AI readiness: Purview labels, DLP, oversharing clean-up3–6 weeksFrom $44,900
Complete Microsoft 365 security program (all four areas)6–10 weeks$74,900
Ongoing monitoringMonthlyFrom $1,250 a month

Government prices include procurement documentation, accessibility and records requirements, and delivery in Microsoft’s Government Community Cloud where required.

Common questions

Microsoft security services: questions buyers search for

Does Microsoft 365 include security?

Yes. Every Microsoft 365 plan includes core protection such as multifactor authentication and email filtering, and plans such as Business Premium, E3 and E5 add Defender, Intune and Purview controls. Most organizations already own more security than they have switched on; our Microsoft security services configure what your licenses include before suggesting anything new.

What does a Microsoft 365 security assessment cover?

Our free Microsoft 365 security assessment is read-only and takes about a week. It reviews identity (MFA and conditional access), email protection, device compliance and how widely data is shared, against what your licenses include, and ends with a ranked fix list and a fixed price for each fix.

Are you a Microsoft Defender implementation partner?

Yes. We deploy Defender for Office 365 as part of identity and email protection (2 to 3 weeks) and Defender for Endpoint with Intune policies (about 3 weeks), then tune alerts so someone acts on them. Ongoing monitoring is available under managed services.

Questions buyers ask

Before you decide

Do we need to buy Microsoft 365 E5?

Not always. Many controls are in Business Premium and E3. The assessment shows what your current licenses include and where an upgrade would pay for itself.

Will MFA and conditional access disrupt staff?

We pilot with a small group, communicate changes in advance and roll out in stages, so staff see one short prompt rather than a lockout.

Can you work in GCC or GCC High?

Yes. We are an AOS-G partner and configure security in government clouds.

Is this a one-off project or ongoing?

Either. Configuration is a fixed-price project; monitoring afterwards is optional under AI-powered managed services.

Switch on the security you already pay for

Start with a free, read-only Microsoft 365 security assessment and a ranked fix list.

Microsoft security services that decide what people and AI can reach