Microsoft 365 Security · Upper Midwest, 100% Remote
Microsoft grades your Microsoft 365 on what you’ve configured. It doesn’t check what’s actually enforced, and it stays quiet on most of the things that get small businesses breached. In about a week, Redpine tells you which of those you have — in plain English, at a fixed price.
No agents installed · nothing changed in your systems · no obligation
Why this matters
Microsoft 365 ships secure-capable, not secure-configured. The controls that stop most attacks are already in your license — they just have to be switched on correctly, and almost nobody does. But the tenants we assess are usually not missing the obvious things. They have a mailbox quietly forwarding to a personal Gmail account, an app password that doesn’t expire until 2099, or a vendor’s app sitting in an admin role nobody remembers approving. None of those show up on a score.
The assessment
Simple & safe
You approve a read-only app. No agents, no software installed, nobody interrupted.
We review identity, admin rights, apps, mail rules and sharing. Nothing is changed.
Ranked findings and a roadmap, in language anyone in the business can read.
We walk you through it. You choose what gets fixed, and by whom.
Straightforward
Pick the tier that fits your size. Every price is flat and agreed before we start — no hourly surprises. If you’d rather we did the fixing too, that’s a separate project you approve separately.
Fixing everything else: Remediation projects from $2,500 · Keeping it fixed: Redpine Watch, below
Redpine Watch
An assessment is a photograph. Tenants drift — someone is made an admin for an afternoon and stays one, a new vendor app gets approved, a forwarding rule appears. Watch is the standing arrangement that catches it.
From $400/month. Priced by user count; quoted with your assessment.
Watch is not a 24/7 security operations center. We are not watching alerts overnight, and we are not your incident responder if something happens at 2am.
If that’s what you need, say so on the call — it’s a real requirement for some businesses, and we’ll tell you so and point you to someone who does it, rather than sell you something adjacent.
Watch is drift detection and steady upkeep by someone who already knows your tenant. For most businesses our size, that’s the job that was going undone.
Why Redpine
Not “we’re careful” — the access we use is read-only by construction. If you later ask us to fix things, that’s separate access you approve in writing, it lasts only for the agreed work, and it removes itself when the work is done. We show you where to confirm it’s gone.
The report names any check we couldn’t run and why — because a silent gap is worse than a known one. Findings in plain English, a fixed price you know before we begin, and no pressure to buy the fix from us.
Straight answers
You should — it’s free and it’s useful. But it grades what you’ve configured, not what’s enforced. It will credit you for multi-factor authentication your staff have registered even when no policy actually requires it, which is the most common serious problem we find. It also has no check at all for mailbox rules forwarding your mail outside the company, app passwords that never expire, or outside apps holding admin rights — three of the things most likely to hurt you. And it hands you an unordered to-do list; some of its own recommendations conflict with each other, and on a smaller license, doing one of them in the wrong order can lock you out of your own tenant.
For the assessment, you approve a read-only application. It is incapable of changing anything in your tenant, and no software is installed anywhere.
If you later hire us to fix things, that’s a second, separate application with write access. You approve it in writing, for a defined window of work. When the work is finished, that access deletes itself — we don’t rely on you remembering to revoke it. You can confirm it’s gone yourself in your Microsoft admin center under Enterprise Applications, and we’ll show you exactly where to look.
No. Nothing is installed, no passwords change, and nobody is locked out or prompted for anything. The assessment reads configuration only. Most clients run it during a normal business day and their team never knows it happened.
This isn’t a referendum on your IT provider — they were handed the same misleading score you were, and most of what we find was never on their to-do list because Microsoft never flagged it. Think of it the way you’d think about your accountant and your auditor: different jobs, and the second one is more useful precisely because it’s independent. We’re happy to deliver findings directly to your IT provider so they can do the fixing.
We tell you plainly, rank it by what it would actually cost you, and give you a safe order to fix it. The report is yours either way. You can hand it to your own IT people, work through it yourself, or hire us — and there’s no pressure toward the last one. If we find evidence of an active compromise, we’ll tell you immediately rather than waiting for the report.
Partly, and we’re specific about which part. We can evidence the identity controls carriers ask about — multi-factor enforcement, admin account separation, legacy sign-in, external forwarding, who holds privileged access — with a dated third-party report rather than a checkbox. We cannot answer questions about your backups, endpoint protection, network, staff training, or incident response plan, because those aren’t in Microsoft 365. We’ll hand you a worksheet for those instead of guessing, because a wrong “yes” on an application is a denied claim two years later.
A free 15-minute call — no obligation, no sales pressure.
Book your free call