SOW Rev2
Signed Statement of Work — full scope and deliverables
CASE STUDY
Enterprise-grade security baseline for Contoso Ltd aligned to Zero Trust principles using Microsoft 365 E3 + Security P2 licensing.
OVERVIEW
This project implements an enterprise-grade Microsoft 365 security baseline across six phases, with each phase requiring written client approval before deployment. All pre-deployment configuration documents have been prepared and are pending approval.
Discovery, licensing confirmation, SOW approval, admin workstation setup.
PIM, Conditional Access, MFA, break-glass accounts, role eligibility.
Defender for Office 365 P2, Safe Links, Safe Attachments, DKIM, DMARC, SPF.
Defender for Endpoint P2, Intune configuration, compliance policies, ASR rules.
Sensitivity labels, DLP policies, endpoint DLP, data classification schema.
Unified audit log, alert policies, Secure Score assessment, remediation plan.
SECURITY ARCHITECTURE
All components work together to create a comprehensive Zero Trust security posture. Each phase builds on previous foundations, ensuring layered protection across identity, email, endpoints, and data.
DEPLOYMENT CAPABILITIES
No implicit trust. Every access request verified through MFA, device compliance, risk assessment, and Conditional Access policies. Break-glass accounts protected but monitored.
Multi-layer threat detection: email phishing + malware (Safe Links/Attachments), endpoint threats (EDR + AIR), and user behavior anomalies (Identity Protection). Automated remediation for low/medium severity.
Comprehensive logging of all identity, email, endpoint, and data access events. Unified Audit Log for compliance investigations. Alert policies notify security team of high-risk activities in real-time.
DLP policies prevent sensitive data (credit cards, SSN, PII) from being emailed, uploaded to personal cloud storage, or copied to USB drives. Graduated enforcement: audit → quarantine → block.
All Windows devices required to have BitLocker encryption, Secure Boot, Windows Firewall, Defender real-time protection, and ASR rules blocking attack vectors. Non-compliance triggers remote lock after 7 days.
Admin roles made eligible-only (not standing). Tier 1 admins require approval + MFA + justification (4hr max). Quarterly Access Reviews ensure role necessity. PIM alerts if activation outside business hours.
DMARC/SPF/DKIM prevent domain spoofing. Safe Links block malicious URLs at click-time. Safe Attachments use sandboxing for unknown files. Anti-phishing targets executive impersonation. ZAP removes phishing post-delivery.
Baseline implementation adds 50–85 points to Microsoft Secure Score. Quantifiable security improvements demonstrable to board/executive leadership. Ongoing remediation plan for remaining gaps.
All policies, rules, and configurations stored in Git. PowerShell/Graph scripts enable repeatable deployments across multiple tenants. Version control + peer review for all security changes.
Baseline meets requirements for HIPAA, PCI-DSS, SOC2, and ISO 27001 foundational controls. Audit logs satisfy regulatory retention requirements. Sensitivity labels enable data classification compliance.
Break-glass accounts provide emergency access if all Conditional Access policies fail. MFA exemption for emergency scenarios. Offline access to sensitive data during Azure AD outages (cached credentials).
App Protection Policies (MAM) control corporate data on personal devices without requiring full device enrollment. Offline wipe if device lost. Copy/paste restrictions prevent data exfiltration.
PHASE 2 — IDENTITY & ACCESS CONTROL
Status: Ready to Deploy — Pending Client Approval
Deploy in Report-Only mode first — enforce after 72hr review with client
PHASE 3 — EMAIL & THREAT PROTECTION
Status: Queued — Starts after Phase 2 sign-off
p=none → Monitor aggregate reports (2 weeks)p=quarantine → Review & remediate misaligned sendersp=reject → Full enforcement (client approval per stage)PHASE 4 — ENDPOINT SECURITY & EDR
Status: Queued — Starts after Phase 3 sign-off
Non-compliance actions: Day 0 → Mark | Day 1 → Email | Day 7 → Remote lock
Level 2 (All users):
Level 3 (Finance, HR, Exec, IT Admins):
PHASE 5 — DATA PROTECTION & GOVERNANCE
Status: Queued — Starts after Phase 4 sign-off
⚠️ Classification schema workshop required with client before deployment
All policies deploy in Test/Audit mode first — client reviews before enforcement
PHASE 6 — COMPLIANCE, AUDIT & SECURE SCORE
Status: Queued — Starts after Phase 5 sign-off
| Phase 2 — Identity | +15 to +25 pts |
| Phase 3 — Email | +8 to +15 pts |
| Phase 4 — Endpoint | +15 to +25 pts |
| Phase 5 — Data | +8 to +12 pts |
| Phase 6 — Compliance | +5 to +10 pts |
| Total Estimated Gain | +50 to +85 pts |
SUPPORTING INFRASTRUCTURE
All tools installed via Install-AdminWorkstation.ps1 and Customize-MannyTerminal.ps1.
Quick Connect Commands
Connect-M365 # Graph + Exchange Online
Connect-Intune # Intune via Graph
Connect-AzureAdmin # Azure (Az module)
Connect-All # All services at once
Disconnect-All # Clean disconnect
Set-ClientContext # Switch Az + Graph tenant by client name
azctx # Show current Azure context
m365ctx # Show current Graph/M365 context
PROJECT DOCUMENTS
Signed Statement of Work — full scope and deliverables
Identity & Access Control + Email Security configuration plan
Endpoint Security & Intune configuration plan
Data Protection, Governance, Compliance & Audit configuration plan
Available upon request:
Service Provider: Contoso MSP / WolfSky Cloud
Client: Contoso Ltd
Engagement Lead: TBD
DOCUMENTATION
Explore detailed deployment guides, prerequisites, and workstation setup. For the complete repository and all supporting documents, view the private GitHub repository.
This project implements an enterprise-grade Microsoft 365 security baseline for Contoso Ltd, aligned to Zero Trust principles using Microsoft 365 E3 + Security P2 licensing.
Status: Ready to Deploy (Pending Approval)
📊 Secure Score Impact: +15–25 pts
Status: Queued (Starts after Phase 2)
📊 Secure Score Impact: +8–15 pts
Status: Queued (Starts after Phase 3)
📊 Secure Score Impact: +15–25 pts
Status: Queued (Starts after Phase 4)
📊 Secure Score Impact: +8–12 pts
Status: Queued (Starts after Phase 5)
📊 Secure Score Impact: +5–10 pts
All phases deploy in validation/audit/report-only mode first before final enforcement.
Complete toolchain installed via Install-AdminWorkstation.ps1 and Customize-MannyTerminal.ps1.
Microsoft.Graph • ExchangeOnlineManagement • MicrosoftTeams • PnP.PowerShell
Az • Az.PolicyInsights • Az.OperationalInsights • Az.Security
PSFramework • PSScriptAnalyzer • MSAL.PS • ImportExcel • PSWriteHTML
Connect-M365 # Graph + Exchange Online
Connect-Intune # Intune via Graph
Connect-AzureAdmin # Azure (Az module)
Connect-All # All services at once
Disconnect-All # Clean disconnect
Set-ClientContext # Switch Az + Graph tenant by client name
azctx # Show current Azure context
m365ctx # Show current Graph/M365 context
Up to 2 weeks before kickoff
4–6 weeks from kickoff
50% at initiation / 50% at completion
2 weeks after Phase 6 completion
Available upon request:
INTERESTED IN SIMILAR WORK?
A 30-minute alignment call to walk through your environment, discuss fit, and identify a starting point — whether that's a project, staff augmentation, or a managed service.