Microsoft 365 Security · Upper Midwest, 100% Remote

Your Microsoft security score says you’re fine. We check whether that’s true.

Microsoft grades your Microsoft 365 on what you’ve configured. It doesn’t check what’s actually enforced, and it stays quiet on most of the things that get small businesses breached. In about a week, Redpine tells you which of those you have — in plain English, at a fixed price.

No agents installed · nothing changed in your systems · no obligation

Why this matters

The gap is rarely where you’d look.

Microsoft 365 ships secure-capable, not secure-configured. The controls that stop most attacks are already in your license — they just have to be switched on correctly, and almost nobody does. But the tenants we assess are usually not missing the obvious things. They have a mailbox quietly forwarding to a personal Gmail account, an app password that doesn’t expire until 2099, or a vendor’s app sitting in an admin role nobody remembers approving. None of those show up on a score.

The assessment

What you get

What we examine

  • Whether MFA is enforced — not merely available
  • Who holds admin rights, and which outside apps do too
  • Mailbox rules forwarding company mail to outside addresses
  • App passwords and certificates that never expire
  • Whether files can be shared anonymously outside the company
  • Legacy sign-in methods that bypass MFA entirely

What you receive

  • A plain-English report a non-technical owner can act on
  • Findings ranked by real risk, with a safe order to fix them
  • A 30-minute review call with you and your team
  • Straight answers on which insurance questions this evidences
  • Clear next steps — do it yourself, or have us do it
  • Delivered in about one week

Simple & safe

How it works

1

Connect

You approve a read-only app. No agents, no software installed, nobody interrupted.

2

Assess

We review identity, admin rights, apps, mail rules and sharing. Nothing is changed.

3

Report

Ranked findings and a roadmap, in language anyone in the business can read.

4

Decide

We walk you through it. You choose what gets fixed, and by whom.

Straightforward

Fixed-fee. No surprises.

Pick the tier that fits your size. Every price is flat and agreed before we start — no hourly surprises. If you’d rather we did the fixing too, that’s a separate project you approve separately.

Essentials
$750
Up to 25 users
  • Full tenant assessment
  • Ranked findings + roadmap
  • 30-min review call
Get started
Most popular
Standard
$1,500
Up to 75 users
  • Everything in Essentials
  • Insurance-questionnaire worksheet
  • Written answers to the controls we evidence
Get started
Comprehensive
$2,900
Up to 150 users
  • Everything in Standard
  • We fix your top 3 findings
  • Re-scan afterward, as proof
Get started

Fixing everything else: Remediation projects from $2,500 · Keeping it fixed: Redpine Watch, below

Redpine Watch

Keeping it fixed.

An assessment is a photograph. Tenants drift — someone is made an admin for an afternoon and stays one, a new vendor app gets approved, a forwarding rule appears. Watch is the standing arrangement that catches it.

Every month

  • A fresh scan, run on the same checks as your baseline
  • A change report — what’s different since last month, and whether it matters
  • One hour of fixes included, applied the same guarded way: previewed, recorded, reversible
  • A named person to email, who answers within one business day
  • An annual refresh of your insurance answers, before renewal

From $400/month. Priced by user count; quoted with your assessment.

What Watch is not

Watch is not a 24/7 security operations center. We are not watching alerts overnight, and we are not your incident responder if something happens at 2am.

If that’s what you need, say so on the call — it’s a real requirement for some businesses, and we’ll tell you so and point you to someone who does it, rather than sell you something adjacent.

Watch is drift detection and steady upkeep by someone who already knows your tenant. For most businesses our size, that’s the job that was going undone.

Why Redpine

You can verify everything we tell you.

The assessment cannot change anything

Not “we’re careful” — the access we use is read-only by construction. If you later ask us to fix things, that’s separate access you approve in writing, it lasts only for the agreed work, and it removes itself when the work is done. We show you where to confirm it’s gone.

We tell you what we couldn’t see

The report names any check we couldn’t run and why — because a silent gap is worse than a known one. Findings in plain English, a fixed price you know before we begin, and no pressure to buy the fix from us.

Straight answers

Questions people actually ask.

Can’t I just check my Microsoft Secure Score myself?

You should — it’s free and it’s useful. But it grades what you’ve configured, not what’s enforced. It will credit you for multi-factor authentication your staff have registered even when no policy actually requires it, which is the most common serious problem we find. It also has no check at all for mailbox rules forwarding your mail outside the company, app passwords that never expire, or outside apps holding admin rights — three of the things most likely to hurt you. And it hands you an unordered to-do list; some of its own recommendations conflict with each other, and on a smaller license, doing one of them in the wrong order can lock you out of your own tenant.

What access do you need — and how do I take it back?

For the assessment, you approve a read-only application. It is incapable of changing anything in your tenant, and no software is installed anywhere.

If you later hire us to fix things, that’s a second, separate application with write access. You approve it in writing, for a defined window of work. When the work is finished, that access deletes itself — we don’t rely on you remembering to revoke it. You can confirm it’s gone yourself in your Microsoft admin center under Enterprise Applications, and we’ll show you exactly where to look.

Will this disrupt my staff?

No. Nothing is installed, no passwords change, and nobody is locked out or prompted for anything. The assessment reads configuration only. Most clients run it during a normal business day and their team never knows it happened.

We already have an IT company. Do we still need this?

This isn’t a referendum on your IT provider — they were handed the same misleading score you were, and most of what we find was never on their to-do list because Microsoft never flagged it. Think of it the way you’d think about your accountant and your auditor: different jobs, and the second one is more useful precisely because it’s independent. We’re happy to deliver findings directly to your IT provider so they can do the fixing.

What if you find something bad?

We tell you plainly, rank it by what it would actually cost you, and give you a safe order to fix it. The report is yours either way. You can hand it to your own IT people, work through it yourself, or hire us — and there’s no pressure toward the last one. If we find evidence of an active compromise, we’ll tell you immediately rather than waiting for the report.

Will this satisfy our cyber-insurance application?

Partly, and we’re specific about which part. We can evidence the identity controls carriers ask about — multi-factor enforcement, admin account separation, legacy sign-in, external forwarding, who holds privileged access — with a dated third-party report rather than a checkbox. We cannot answer questions about your backups, endpoint protection, network, staff training, or incident response plan, because those aren’t in Microsoft 365. We’ll hand you a worksheet for those instead of guessing, because a wrong “yes” on an application is a denied claim two years later.

Find out where you stand.

A free 15-minute call — no obligation, no sales pressure.

Book your free call