Service

What we watch, what we fix and how it works

Our platform reads your tenant 24/7 – people only deal with what's worth it. And what we find, we fix for you: remediation hours are prepaid in the monthly fee.

What we watch

Eight areas under watch

01
Security score and its decline

We track Secure Score daily. When a large customer asks you to prove how you're secured, you have something to show – and you won't hear about a decline first in an annual audit.

02
Configuration drift from the approved state

Who changed what and when, caught within hours. Nobody turns a protection off without anyone noticing for six months. You decide whether the change stands.

03
Who holds admin rights

Top-level permissions outside the approved list mean an immediate alert. A former colleague or a contractor you parted ways with won't reach your data.

04
External sharing and guests

Anonymous links, forgotten guests and apps someone granted access to your mailbox. A quote or a contract won't sit for years on a link anyone can open.

05
Licences and waste

Inactive accounts and unused licences. You stop paying for people who no longer work for you – the saving often covers part of the fee.

06
Upcoming Microsoft changes

We read Microsoft's announcements for you. Your people won't wake up to a change nobody knew about.

07
Backups and mail

Protection against spoofed e-mail and the state of your backups. Your invoice won't reach a customer as a forgery and a deleted file has somewhere to fall back to.

08
Azure subscription OPTIONAL

Costs and anomalies, security recommendations, orphaned resources. The cloud bill won't surprise you at the end of the month.

What we handle for you

Monitoring is half the service. The other half is hands.

A finding nobody acts on is just one more e-mail. That's why the monitoring comes with work – remediation hours are prepaid in the monthly fee and your people have somewhere to write.

01
Remediation within the fee

3 hours a month in Managed, 6 in Full. You don't raise an order for every little thing – we deal with what needs dealing with.

02
Configuration changes and upkeep

Policies, Conditional Access, permissions, sharing, retention. We keep the baseline current, not frozen in time.

03
Fixing what monitoring finds

What the platform finds, we also fix. For risky changes we ask first – the decision stays yours.

04
Support for admins and management

Admin-to-admin consultations, escalation and cover when your admin is on holiday or off sick.

05
User helpdesk FULL

Your people write straight to us – by e-mail or in Teams, 8×5. We reply within 4 working hours.

06
Joiners and leavers FULL

Account, licence, mailbox, access, groups. And a clean close on the way out – so nobody leaves a door open behind them.

Beyond the prepaid hours a senior rate of 2 200 Kč/h applies. No forced projects, no minimum spend – unused hours don't roll over, but nobody pushes you to burn them either.
How it works

Three steps, nothing gets installed

1
Consent in one click

Nothing gets installed. We read your tenant through official Microsoft APIs, read-only.

2
We fix the healthy state

The approved configuration becomes the baseline. From then on we watch every deviation.

3
You get a report and peace

Every month a readable report with recommendations. Critical things we handle straight away.

You can leave any time – you delete our access in one click and get the complete documentation.
Before you decide

Your first month with us, day by day

Nowhere in it is a day where you'd have to switch something off, reinstall anything or let a stranger near your computers. Until the end of the first week you commit to nothing.

  1. Today, in seconds
    Domain check

    You enter your domain and immediately see what's visible from the outside – whether mail can be sent on your behalf, whether your domain is about to expire. No sign-up and no access to your environment.

  2. Within 48 hours
    Tenant audit and its result

    We go through the Microsoft 365 configuration – admin rights, MFA, external sharing, guests, licences, backups. You get a list of findings ordered by risk, not alphabetically. Reading only, we change nothing.

  3. Then it's your turn
    A decision without pressure

    The findings are yours even if we part ways. You can fix them yourself or with your current provider – we hold nothing hostage.

  4. Week 1
    Monitoring switched on

    Consent in one click, read-only access through official Microsoft APIs. Nothing gets installed – not on a server, not on the computers. We fix today's state as the baseline so there's something to measure deviations against.

  5. Weeks 2–4
    First fixes

    We take the findings starting from the riskiest. You approve what should change; we do it and write it down. From then on we alert you whenever the configuration drifts from the approved state.

  6. End of the first month
    First report

    An overview management can read: what changed, what we fixed, what's left and how many hours were used. You can see what it looks like below.

What you get every month

A report that someone who doesn't run servers can read

No console dump. The first page says what changed over the month and what to do about it – the detail is at the back, for whoever wants it.

Monthly_report_March.pdf
Monthly overview · March
Your company Ltd · 34 users
78/100
↑ 12 from February
What we fixed
  • Admin rights removed from 2 people who no longer work for you
  • Two-factor authentication switched on for the remaining 6 users
  • 11 “anyone with the link” shares older than a year revoked
What we recommend next
  • 4 unused licences – a saving of CZK 3,480 a month
  • Backups have never been test-restored. We suggest a test.
  • An external company has access to 3 teams. Confirm they should?
2 h 15 minused of 3 hours in the fee
1 changeagainst the approved state – handled the same day
0 incidentsnothing that would threaten operations

A sample. The figures are illustrative – your report will contain your findings.

Why us

A Microsoft cloud specialist, not a generalist for everything

Continuous platform monitoring

Our own monitoring platform reads the tenant non-stop. A quarterly audit is a photo – we deliver the film.

Seniors, not a call centre

On the Microsoft platform since 2001, a former Microsoft MVP. What we know, we publish – “Notes from the battlefield” and sharepoint-vault are the public proof.

Predictable and without chains

A public price list, a fixed monthly fee, leave any time with no commitment. The tenant is yours – you revoke our access in one click.

AdvoPartners · Conditional Accesschanged by external IT · 26 h ago
− MFA required: all users + exception: director@advopartners.cz
Approve → baseline Reject + revert Ask the customer
Drift detection: every change against the baseline waits for your decision.
WHAT WE NEVER DO We don't read your documents, e-mails or messages. We watch settings and numbers, not content.
FAQ

Common questions about the service

Didn't find your answer? Ask – we reply by the next working day.

Write to us →
+What if you find something? Won't that put us over a barrel?

The findings are yours whether we work together or not. You get them written up and you can fix them yourself or with your current provider — we keep nothing as leverage. If you want us to fix them, we will: at the hourly rate, or within the monthly fee. But it's your choice, not a trap.

+We don't want to change providers, that's always a nightmare.

And we're not changing one. Nothing gets switched off, reinstalled and nobody takes over your IT. We switch monitoring on alongside what you have, with read-only access — and if we part ways, you remove it in one click. The first month is reading and proposals, no changes without your approval.

+We're nervous about letting a stranger near company data.

Understandably — which is why we have no access to it. We read only configuration, permissions and numbers: who holds admin rights, how sharing is set up, what the security score is. Our platform doesn't see the content of documents, e-mails or Teams messages and technically cannot. And access is read-only — even if we wanted to, we couldn't change anything without a separate account and your knowledge.

+We have our own IT admin. Won't you be competing with them?

No, we cover their back. For companies with their own IT the Monitor tier (or Managed) runs in “partner mode”: your admin gets a second pair of eyes, monitoring data and an escalation path when they're stuck or on holiday. We talk to them admin to admin. They still decide.

+How exactly do I revoke your access when we're done?

In one click: you delete our application in the admin centre and access to Microsoft 365 and Azure ends at once. No notice period, no exit fees. We keep documentation as we go, so you get a complete handover at no cost. The tenant is yours — it always was.

+You promise a fast response. What about midnight?

The platform watches non-stop, but people respond on working days. Within 4 working hours for a critical finding, within 8 for ordinary requests in Managed, within 4 for the helpdesk in Full. We don't promise 24/7 intervention — we'd rather promise only what we actually keep than leave you waiting for something that isn't coming.

+Will you be selling us licences and services we don't need?

No. The monitoring adapts to what your licences can do — where they can't, we say so plainly and advise whether an upgrade is worth it. We never sell licences for the sake of it and we take no commission on them.

Start with a free audit

An instant domain check right here on the page, a full tenant audit within 48 hours. Nothing to install, no commitment — and you can revoke our access afterwards.