Skip links

Secure Microsoft 365 Applications with Izi-Telecoms

M365 Management

Izi-telecoms Services is pleased to provide Advanced Services for Microsoft 365 Management (the “Service(s)”) in accordance with this Service Description (“Service Description”). Your quote or other mutually agreed upon form of invoice or order acknowledgment will include the name of the service(s) and available service options that you purchased. For additional assistance or to request a copy of your service contract(s), contact technical support or your sales representative.

M365 Tenant Management

Izi-telecoms will perform the following Tenant Management activities:

  • Initiation and planning of the Microsoft 365 Managed Service. This includes meeting with key stakeholders to review the services, planning the delivery of services, and setting up processes and procedures to begin service delivery operations.
  • Service Request Delivery. Service Requests are the key task control object of the engagement and allow the capture of details and information about a request for service. A Service Request can be a proactive request for assistance, administration, or research for a project or problem, or it can be a reactive request to help manage a problem and control an error situation.
  • Problem Management and Error Control includes proactively monitoring and reviewing Microsoft 365 Health, Messages and Alerts in addition to our own information channels to ensure efficient performance of Customer’s tenant and to mitigate any events that could impact Customer’s
  • The Advanced Services Client Service Engineer is the 2nd level escalation point for problem scenarios and error conditions and provides direct technical support by leveraging subject matter
  • The Client Service Engineer provides a liaison into Microsoft Product Support for product related error conditions by leveraging the Izi-telecoms Services partnership with Microsoft to facilitate error resolution.
  • The Advanced Services Experience Manager coordinates and presents performance reports which are provided on a regular schedule.

M365 User Management

Azure Active Directory is the identity management source for Microsoft 365 user accounts and is managed in much the same way as Windows Server Active Directory but is instead cloud-based.

Customer’s implementation of Microsoft 365 may be configured to leverage both Azure Active Directory and Customer’s existing Windows Server Active Directory using Azure Active Directory Connect and Active Directory Federation Services and will be established prior to Izi-telecoms engaging to monitor it or add, delete, or change users. Microsoft 365 services in this Service Description includes the Azure Active Directory components only and is not inclusive of Windows Server Active Directory. This demarcation point requires collaboration with the Customer’s IT team to ensure proper directory services for the organization.

M365 Application Workload Administration

Application Workload Administration manages user and application features of Microsoft 365 applications such as new user setup, changes and deletions, license management, group management, application configuration change management, and security and compliance rules and actions.

The Microsoft 365 workload administration for this scope of work is focused on the following two key areas:

  • Microsoft 365 identity management and ensuring the cloud identities are properly created and
  • Exchange Online management of groups, contacts, shared mailboxes, distribution lists, rooms, resources, and other application configurations.

Service Interface Guide for ITSM Tools

A Client Service Engineer is available during standard business hours (Monday through Friday, 8 a.m. to 5 p.m. local time), excluding holidays. The Client Service Engineer may designate a backup point of contact as required for periods of planned time off.

Some of our service delivery tasks will require Global Administrator permissions to the production tenant in addition to leveraging a variety of tools and PowerShell scripts to automate tasks. Izi-telecoms Services will coordinate and comply with secure methods and information security policies to ensure the highest integrity in the protection of information.

Izi-telecoms Services will provide Level 2 support for system administrators and named stakeholders. Support is delivered via direct engagement with the Client Service Engineer.

Support for system problems and tenant errors is provided both in a response model and through proactive tasks and activities. The objective of problem and error management is avoidance through proactive monitoring, predictive anomaly and log analysis, and daily dashboard reviews. Common tasks include:

  • Proactively monitor Microsoft 365 Tenant services and take necessary action to address
    • Active users and Groups Activity
    • Exchange Activity, App Usage and Mailbox Usage
  • Proactive and predicative issue management
    • Identify potential operational risks and plan necessary action plans, tasks, and changes required to address issue
    • Manage Message Center queue and engage Customer point of contact Service Customer Manager, as appropriate
  • Evaluate new Microsoft 365 features as they are released and conduct an assessment in the context of the Customer’s tenant, strategies, and objectives to determine an adoption

The Client Service Engineer will leverage Customer’s tenant administration tool through the Customer’s Microsoft portal to manage Customer tenant, aggregate information, and take appropriate actions to manage new problems, known errors, or potential threats. The Advanced Services Experience Manager from Izi-telecoms Services will establish and maintain a communication process with the Customer for information sharing, notifications, alerts, and requests for change. In a Microsoft 365 environment, the Client Service Engineer works with other stakeholders, including local teams that support on premise and other environments, Microsoft support and product engineering, who may create fixes to the products.

M365 Management Module Security Features

M365 Management of security features is designed to ensure the appropriate configuration of the following software titles and to provide monitoring and performance reporting to ensure appropriate function.

  • Information Protection
    • Windows Information Protection & Azure Information Protection: Izi-telecoms Services will configure and manage the M365 cloud management portal, including the following tasks:
      • Working with the Customer to define data classifications and tags
      • Tracking and analyzing data signals in the portal
      • Developing a policy for sharing documents including printing, emailing, editing

Security Management

  • Microsoft Secure Score: Microsoft secure score is a tool that will be used to manage the health of a Customer’s IT environment based on security factors collected from Microsoft Defender ATP. With this information Izi-telecoms Services can:
    • Use the information to determine corrective steps to take in the Customer’s IT environment
    • Confer with the Customer changes needed to improve their secure score
    • Help implement the recommended changes
  • Microsoft Security and Compliance Center: Izi-telecoms Services will confer with the Customer regarding the Customer’s compliance requirements and configure the Customer’s software accordingly. Izi-telecoms Services will also do the following:
    • Review risk-based compliance score with Customer to determine remediations in the environment that can improve the score
    • Edit compliance areas as needed and tailor them to the Customer industry/environment
    • Run audits and assessments against various groups in the organization
  • Azure AD Identity Protection: Izi-telecoms Services will configure the vulnerability detection and automated remediation policy with the Customer and will manage alerts and ongoing configuration changes through the Azure console or through Azure sentinel if applicable
    • Review reports for risky users, sign-ins, and detections
  • Azure Advanced Threat Protection: Izi-telecoms will manage the identity threats using Azure ATP which is a cloud-based solution that monitors for advanced threats, insider threats, and compromised users. Azure ATP allows Izi-telecoms Services to:
    • Monitor for anomalous activity
    • Look for compromised credentials, lateral movements, domain dominance, and other suspicious behaviour
    • Provide monitoring for identity management
    • Generate detailed reporting to Customer stakeholders on alerts
    • Access key alert reports on threats that need immediate remediation
  • Office Advanced Threat Protection: Izi-telecoms Services will enforce policies based on Customer-configured threat protection policies for the technology and monitor the solution for Threats that will be reported to the Customer and recommended actions may be taken, or actions may be advised for the Customer to perform. Examples of items that may be included in reports include the following:
    • Recommendation to configure safe links and attachments
    • Security findings on threat protection status by file type
    • Results of real-time detections of security events
  • Microsoft Cloud App Security: Izi-telecoms Services will configure management portal and configure a policy for cloud app security, which will allow Izi-telecoms Services to:
    • Monitor for threats and anomalies in the portal
    • Recommend actions to the Customer for improving security
    • Provide alerts regarding threats in the Customer’s IT environment and remediate or advise Customer on remediation actions
    • Advise Customer when new cloud connections are made from end-users

Control Microsoft 365

The major problem with managing Microsoft 365 is that you’re either a global admin or you’re nothing. This introduces risk as your entire support team needs access to all of your customers tenants, or delays as tickets get escalated for actioning. Enter Izi-Telecoms, for Microsoft 365 management.

Manage Microsoft 365 with Izi-Telecoms, contact us for our full list of services.

Let's Start the Conversation
This website uses cookies to improve your web experience.