Layer3 Logo

Microsoft 365

Microsoft 365 with clear ownership

The licence was never the hard part.

Microsoft 365 management is part of Managed IT and Co-Managed IT, not a separate product. Layer3 standardises and monitors tenant policy, tracks Secure Score to an agreed target and backs up Microsoft 365 data independently of Microsoft's native retention. It requires Microsoft 365 Business Premium or above; Business Basic and Standard do not include the controls this page describes.

Bundled

Part of Managed IT and Co-Managed IT, not sold on its own

Business Premium+

The licensing floor this level of management requires

80%

Secure Score target, tracked every vCIO review

Annual to quarterly

Review cadence - annual at Protect, quarterly at Sentinel

01

The case for change

The licence gets bought. The configuration doesn't happen on its own.

Microsoft 365 ships with real security and governance capability, and most tenants use almost none of it. Nobody owns the drift, nobody is watching the score move, and nobody has checked whether "Microsoft backs it up" is actually true.

Configuration

Licence paid for, capability unused

Conditional access, Defender for Business and Intune all ship inside Business Premium. Left at Microsoft's defaults, most of what you're paying for sits switched off.

Drift

Policy that doesn't stay policy

One admin changes a setting to unblock a user, another adds an exception for a vendor, and six months later nobody can say what the baseline actually is any more.

Backup

Native retention isn't backup

Microsoft's own retention is short-window and built for litigation holds, not recovery. A deleted SharePoint library or a compromised mailbox can outlast it.

What's included

Nine things that happen to your tenant whether you notice or not.

Part of Managed IT and Co-Managed IT for every customer on Business Premium or above - none of this is an add-on.

User, licence and mailbox administration

Onboarding, offboarding, licence assignment and mailbox management handled as routine, not a ticket queue.

Policy baseline and drift monitoring

A defined tenant security baseline, deployed and monitored for drift across every user, device and workload.

Secure Score and posture

Tracked continuously against an 80% target and reported at every vCIO review, not measured once and left.

Conditional access and MFA

Sign-in policy enforced by role, device and risk level, not left at whatever Microsoft ships by default.

Teams and SharePoint governance

Sharing, guest access and site sprawl kept inside a policy someone actually owns.

Mailbox and domain threat protection

Phishing, spoofing and domain-impersonation controls layered on top of Microsoft's own filtering.

Backup and retention

Independent backup for mailboxes, SharePoint, OneDrive and Teams, retained to a policy Layer3 sets, not Microsoft's default.

Compliance and data loss prevention

Retention labels and DLP policy aligned to what your industry and your customers actually require.

Licence lifecycle and cost

Unused and duplicate licences found and removed, and licence tier matched to what each role actually needs.

How it is managed

Two platforms, doing the two things a spreadsheet and a hope can't.

Policy management and backup are both run on dedicated platforms, not through the Microsoft admin centre by hand.

01

Policy management

Tenant security policy is deployed and monitored through Inforcer, a platform built for standardising Microsoft 365 configuration across a tenant. It's how baseline drift gets caught in days, not at the next audit.

02

Backup

Microsoft 365 data is backed up independently through Cove, with retention set to Layer3's policy rather than Microsoft's short-window default - so a deleted mailbox or a corrupted SharePoint library is a restore, not a loss.

Service levels

What's tracked, and how often it's reviewed.

Secure Score

Target

80%, tracked continuously against Microsoft's own scoring model.

Cadence

Reported and actioned at every vCIO review - annual at Protect, quarterly at Sentinel.

Owner

Movement and remediation priorities are a standing input to your vCIO roadmap, not a one-off audit.

Licensing prerequisite

Floor

Microsoft 365 Business Premium or above.

Why

Conditional access, Intune and Defender for Business aren't in Business Basic or Standard.

Below the floor

We'll tell you plainly if a licence upgrade needs to happen before this level of management is possible.

The stack behind it

Named platforms, not a black box.

Two of these carry the argument on this page; the third is part of the wider stack.

Questions

Microsoft 365, answered

Wondering how this fits with your existing plan? Here's what customers ask before we start.

Book a discovery call

No. It's part of Managed IT and Co-Managed IT — there's no standalone Microsoft 365 plan.

Microsoft 365 Business Premium or above. Business Basic and Standard don't include Conditional Access, Intune or Defender for Business, which this depth of policy and security management depends on.

It's the platform Layer3 uses to standardise and monitor Microsoft 365 security policy across your tenant — deployment, drift detection and enforcement, rather than checking settings by hand.

We track it continuously against an 80% target, and it's reported and actioned at every vCIO review — annual at Protect, quarterly at Sentinel.

No — Microsoft's native retention is short-window and built for litigation holds, not recovery. We run independent backup through Cove, with retention set to our policy rather than Microsoft's default.

Yes — sharing, guest access and site sprawl are part of the same baseline as the rest of the tenant, not a separate exercise.

Secure Score and tenant posture are a standing input to that roadmap, tracked and reported at every review rather than assessed once and forgotten.

Ready to review your Microsoft 365 tenant?

Layer3

Book a discovery call - 30 minutes, no obligation