Tenant complexity
Multiple tenants, identity sources, administrative boundaries, acquisitions, hybrid dependencies, unusual access patterns, or major migrations require more mapping and validation.
A useful proposal should make the work legible: what is being reviewed, how evidence is gathered, who interprets it, what you receive, and where assessment ends and implementation begins.
Price should follow a defined scope. These factors usually matter more than a single headline count.
Multiple tenants, identity sources, administrative boundaries, acquisitions, hybrid dependencies, unusual access patterns, or major migrations require more mapping and validation.
The in-scope Microsoft 365 services and licensed security capabilities determine which control domains and evidence sources apply.
User, administrator, guest, device, application, and domain counts matter most when they introduce distinct policies, ownership, exceptions, or sampling needs.
Collection method, access constraints, manual exports, interviews, third-party evidence, data-handling requirements, and unavailable signals affect effort.
A focused control review differs from a broad tenant assessment with executive reporting, technical findings, action planning, and a stakeholder readout.
Compensating controls, accepted risks, business-critical workflows, regulatory or contractual questions, and planned changes require analyst interpretation.
| Proposal question | Why it matters |
|---|---|
| What is explicitly in and out of scope? | Named tenants, products, identities, devices, domains, evidence sources, and exclusions prevent different assumptions from looking like comparable offers. |
| How is applicability decided? | A large control count is not useful if licensing, architecture, business context, and compensating controls are ignored. |
| Who reviews the evidence? | Clarify where automation assists and where an analyst validates conditions, context, risk, and recommendations. |
| What deliverables are included? | Look for technical evidence, an executive narrative, prioritized actions, dependencies, ownership guidance, and a readout appropriate to your audience. |
| How are access and evidence handled? | The proposal should state permissions, collection methods, recipients, processing, retention, and deletion expectations before access. |
| Is remediation included? | Assessment and implementation are different risk boundaries. Changes should be separately scoped, approved, tested, and accepted. |
| What causes a change in fee? | Assumptions, dependencies, client responsibilities, optional work, and change-control terms should be visible before the engagement begins. |
An assessment determines what was observed, why it matters, and what should be prioritized. A Remediation Sprint plans and implements approved changes under a separate scope. Ongoing Assurance addresses repeat review and drift over time. Separating those decisions makes access, responsibility, testing, acceptance, and fees clearer.
TenantShield publishes the current starting price on the Microsoft 365 Security Assessment service page. A specific fee should follow confirmation of environment outline, desired depth, evidence approach, timing, and deliverables. Review the sample assessment and methodology before comparing scope.
User count can help outline scale, but it does not capture tenant topology, products, identity and device variation, evidence constraints, exceptions, reporting depth, or the decision the work must support.
Only if a proposal explicitly says so. TenantShield treats assessment and implementation as separate scopes so changes, access, testing, responsibility, and acceptance are clear.
A sample helps buyers compare the depth and usability of the expected output, not just the number of checks or hours in a proposal.
Run the free checker for an initial signal, or request an assessment to confirm the environment, evidence plan, deliverables, and fee.