Microsoft 365 Security Hardening Services — Entra & Intune

  • South San Francisco, California, United States
  • Consultancy
  • Remote

Job Description:

About goCloudOffice®

goCloudOffice® is a modern, AI-driven IT consulting company. Founded in 2003 and based in Silicon Valley, we serve customers nationwide across the United States. Our customers are small businesses of 5 to 50 people, in industries that include biotechnology, law and professional services. They own their business applications, and we run their IT with senior engineering judgment and AI-augmented support that has been in daily production since summer 2024.

The engagement

Engagement: Microsoft 365 security hardening services for a biotechnology customer in South San Francisco that is preparing for commercial launch.

The services strengthen the customer's Microsoft 365 environment across identity, endpoints, data governance, collaboration, threat protection, email and domain security, and the business applications that sign in through Microsoft Entra ID. They leave behind documentation that a third-party assessor can verify.

This is a business-to-business engagement under a master services agreement and a statement of work between goCloudOffice® and your business, which invoices for the services it delivers.

Engagement contact: the goCloudOffice® account lead. The provider directs its own work and personnel.

The provider coordinates hand-offs with the customer's IT lead and with goCloudOffice®'s existing providers, and the customer's leadership makes the business and risk decisions the work calls for.

Scope of services

  • Identity and access. Conditional Access designed, piloted in report-only mode and enforced; emergency-access accounts; phishing-resistant multi-factor authentication for administrators; privileged-access reviews; a documented policy register.
  • Endpoints. Intune compliance policies for Windows and macOS; app protection for personal mobile devices; Windows LAPS and a managed approach to local administrator rights; Microsoft Secure Score remediation; Microsoft Defender aligned with a third-party endpoint detection and response platform.
  • Data governance. Microsoft Purview retention, sensitivity labels and data loss prevention, each proven in simulation or with a pilot group before enforcement.
  • Collaboration. SharePoint, OneDrive and Teams external-sharing, guest-access and lifecycle settings, and a secure site and permission design for content moving into SharePoint.
  • Threat protection and monitoring. Defender for Office 365 preset policies, unified audit logging and alert policies.
  • Email and domain security. SPF, DKIM and DMARC enforcement staged to reject, MTA-STS, and registrar and DNS hardening.
  • Business applications. Single sign-on and SCIM provisioning from Microsoft Entra ID to the customer's business applications, and a joiner, mover and leaver process driven by the HR system.
  • Governance and evidence. A Microsoft 365 incident response plan with a tabletop exercise, Microsoft 365 evidence connected to a compliance platform, an audit-readiness register for regulated records, and decision memos that set out options, costs and risks for the customer's leadership.
  • AI-assisted delivery. AI tools used as a daily part of the work, with every output verified before it reaches a customer system.

Services must meet the customer's security, access and confidentiality policies and the service levels in the statement of work.

The provider uses its own equipment and business identity; goCloudOffice® grants only the proprietary system access the services require. In the customer's Microsoft 365 tenant, the provider works through named, least-privilege administrator accounts in its own name, approved by the customer and logged.

The customer's leadership owns licensing, vendor contracts, risk acceptance and business policy. The provider prepares the options and delivers the approach the customer chooses.

What your business brings (required qualifications)

1. An independently established IT security services business. Your business:

  • operates under its own business name, including in customer systems and at customer sites;
  • regularly contracts with other businesses and advertises its services to the public;
  • holds the business licenses and registrations its work requires (for example, in its home city, and in South San Francisco where site visits require it);
  • carries general liability insurance (USD 1M per occurrence, USD 2M aggregate), technology errors-and-omissions and cyber insurance (USD 1M per claim; USD 2M preferred), hired and non-owned auto insurance (USD 1M) where the services include site visits, and workers' compensation where the business has W-2 personnel;
  • provides its own equipment.

A corporation, or an LLC taxed as an S-corporation, whose own W-2 personnel perform the services is preferred. Sole proprietorships and single-member LLCs are also considered.

2. Typically seven or more years of hands-on experience securing and administering Microsoft 365 environments.

3. Microsoft Entra ID identity protection: Conditional Access designed and rolled out in stages with report-only mode first, emergency-access accounts, phishing-resistant multi-factor authentication (FIDO2 security keys and passkeys), and Privileged Identity Management.

4. Microsoft Intune endpoint security: compliance policies for Windows and macOS, app protection policies for personal mobile devices, Windows LAPS, and managed approaches to local administrator rights.

5. Microsoft Defender and endpoint detection and response: Defender for Office 365 and Defender for Endpoint, including Defender working alongside a third-party EDR platform, and migrations between EDR platforms (for example, to CrowdStrike Falcon).

6. Microsoft Purview data governance: retention policies, sensitivity labels, data loss prevention, and audit logging with alert policies.

7. SharePoint, OneDrive and Teams governance: external sharing, guest access, and team and site lifecycle settings.

8. Secure Score remediation and safe change practice: triaging recommendations, applying changes in piloted, reversible batches, and recording each risk decision the customer makes.

9. Email and domain security: SPF, DKIM and DMARC enforcement staged to reject, MTA-STS, and registrar and DNS hardening.

10. Application identity integration: SAML single sign-on and SCIM provisioning from Microsoft Entra ID to business applications, and joiner, mover and leaver processes driven by an HR system.

11. Audit-ready evidence: clear records of controls, configurations and decisions that a third-party assessor or a compliance platform can verify.

12. AI-assisted service delivery. Providers should demonstrate at least one year of AI-assisted service delivery in their practice (for example, AI-assisted troubleshooting, documentation or automation). We look for:

  • Tools: any mainstream assistant, such as Microsoft 365 Copilot, ChatGPT, Claude, Gemini or GitHub Copilot.
  • A clear method for checking AI output: confirming answers against vendor documentation such as Microsoft Learn, testing in report-only or simulation mode, on a test account or with a dry run (for example PowerShell's -WhatIf) before production, reading every line of a script before running it, and keeping customer data inside tools approved for it.

13. Clear communication with customer IT and executive leadership: plain-language change notices, decision memos that set out options, costs and risks, and concise written status updates.

Also valuable (preferred qualifications)

  • A. Relevant certifications, such as Microsoft Certified: Cybersecurity Architect Expert (SC-100), Identity and Access Administrator Associate (SC-300), Information Protection and Compliance Administrator Associate (SC-400, or its successor SC-401), Microsoft 365 Administrator Expert (MS-102), Endpoint Administrator Associate (MD-102) or Azure Security Engineer Associate (AZ-500). Certifications are welcome, optional evidence of this depth.
  • B. Experience in life-sciences or other regulated environments, such as 21 CFR Part 11 and GxP record-keeping, SOC 2 readiness, or IT general controls audits.
  • C. Experience connecting Microsoft 365 evidence to a compliance automation platform.
  • D. Experience writing Microsoft 365 incident response playbooks (for example, for business email compromise) and facilitating tabletop exercises.
  • E. Experience designing SharePoint site and permission architecture for content moving from another file-sharing platform, and evaluating Microsoft 365 backup options.
  • F. Experience with a remote monitoring and management platform (such as NinjaOne) and with zero-trust network access or VPN services connected to Microsoft Entra ID.
  • G. More than one qualified person in your business who can perform the services, for coverage continuity.

Rate, scope and term

  • Budgeted rate: USD 150 per hour. Providers propose their own rates and commercial terms.
  • Expected size: approximately 290 to 400 service hours between late October 2026 and February 2027, about 25 to 30 service hours per week, scheduled by the provider within customer availability windows; scope may change by statement of work.
  • Delivery: mainly remote, with occasional on-site sessions at the customer site in South San Francisco, which the provider schedules with the customer within agreed availability windows.
  • Term: a statement of work for the engagement window, organized by phase milestones, with a re-estimate after the discovery phase.

How to respond

Submit your business's qualifications: a capability statement, résumés of the personnel who would perform the services, and answers to the response questions. The questions cover business details, licenses and insurance, who performs the services, other clients, equipment, how your business secures its administrative access to client systems, availability windows and a delivery plan, your proposed rate and terms, and one example of AI-assisted service delivery. The qualification process is clear and quick:

1. A review of your response against the posted qualifications.
2. A 25-minute introductory qualification call about how your business runs.
3. A technical qualification call with a Microsoft 365 hardening scenario and a practical exercise, using the AI assistant of your choice or one we provide.
4. A conversation about the customer engagement, under a mutual nondisclosure agreement.
5. Two references from clients of comparable Microsoft 365 security engagements.
6. A final decision by goCloudOffice®'s founder.

Every respondent receives an answer. Reasonable accommodations and other adjustments to any step are available on request; the notice below explains how to reach us.

AI-assistance and privacy notice

This notice also covers vendor and consultant respondents and their personnel. goCloudOffice® uses AI-assisted tools to organize and summarize applications and proposals; people, not tools, make every selection decision. We keep records four years and never sell or share them. Privacy Notice for applicants and vendor candidates: [LINK — privacy counsel to supply]

Equal opportunity

goCloudOffice® selects providers on the posted qualifications alone. It welcomes responses from every qualified business, and considers them without regard to the race, color, religion or creed, sex, pregnancy, gender identity or expression, sexual orientation, national origin, ancestry, age, physical or mental disability, medical condition, genetic information, marital status, military or veteran status, or reproductive health decision-making of the business's owners or personnel, or any other characteristic protected by law.