EndKeep is an independent Microsoft 365 security and endpoint practice for companies of 10 to 100 people. You already pay Microsoft for serious security tooling. I make sure it is actually switched on, then keep it that way. Remote, fixed price, and you deal with the engineer, not an account manager.
If you are on Microsoft 365 Business Premium you already own Intune, Conditional Access, Defender and BitLocker. In most 10 to 100 person companies they sit unconfigured, and the owner finds out the hard way.
Without enforced MFA and Conditional Access, any phished password opens that mailbox from anywhere on earth.
Unencrypted, unpatched devices full of company data, and no way to wipe one when someone leaves.
Old accounts stay enabled for months. Ex staff keep reading email nobody remembers they can see.
A bigger customer or insurer asks for MFA, encryption and patching evidence, and nobody can produce it.
No open ended consulting. You know what it costs and exactly what you get before you say yes. Everything is read only until you decide otherwise.
A quick, honest look at the settings that matter most. Good if you just want to know how exposed you are.
Your whole tenant scored against Microsoft best practice and the CIS benchmark, written so a director can read it.
I implement what the assessment found, in an agreed order, with a defined end.
Security drifts back within months if nobody is watching. Pick the piece you want off your plate.
| Plan | What I do every month | Price |
|---|---|---|
| Endpoint Patching | Windows and third party updates through Intune, update rings with sane deadlines, monthly patch report, failed devices chased. | from $8per user / month |
| Intune Management | Patching plus device enrolment, compliance, app deployment, Autopilot for new laptops, joiner and leaver device handling, policy changes on request. | from $20per user / month |
| EndKeep Managed | Everything above plus identity and Conditional Access, Defender alerts reviewed, licence tidy up, Secure Score tracked, staff onboarding and offboarding, and a monthly report a non technical director can read. | from $45per user / month |
Minimum monthly contract applies. Prices are for the management of your tenant, Microsoft licences are billed by Microsoft as now. Roughly half what a US or UK provider charges for the same work.
Sixteen years in IT, the last eight on Microsoft endpoint and security work for managed service providers and their clients. Around 25 Microsoft 365 tenants delivered, several thousand Windows, Mac, iPhone and Android devices under management along the way.
Yes, I am in Pakistan. The work happens over a screen share and a read only account either way, wherever your provider sits. I keep hours that overlap yours, you get the same person every time, and the report is yours to keep whether or not you hire me to fix anything.
The same Intune, Autopilot and Defender practice I run for healthcare, infrastructure and finance clients, applied to your thirty seat firm at a price built for it.
Every question is answered by the person who actually configured your tenant.
My own tenant runs the exact baseline I deploy: Conditional Access, Intune compliance, Defender, DKIM and DMARC. Ask to see it live on the first call.
I do not do helpdesk, printers, break fix or on site visits. If you need someone to walk over to a desk, keep your local IT company and let me do the security layer they are not doing.
Enrolment, compliance, Conditional Access and disk encryption set up from a blank tenant, then kept running month to month.
Ongoing since October 2025Entra ID Platform SSO on macOS, FileVault with recovery key escrow, Defender on both platforms, and Apple Business Manager for zero touch setup.
Managed service provider clientInstallers wrapped so they run silently, detection rules that check a real file version, and every package tested on a clean machine, an upgrade, and with the app open.
Typical packaging engagementTick everything you know is true for your business. Be honest, nobody is watching.
For this kind of work, no. Whether your provider is across town or across the world, Microsoft 365 is configured through a browser with an account you create and can switch off. I work hours that overlap yours, we speak on video, and everything I change is documented. If you need someone physically in the office, that is not me, and I will say so on the first call.
Keep them. Most local IT firms are good at helpdesk and hardware and stretched thin on Microsoft security. I do the security layer, hand them the documentation, and stay out of their way. Often that works better for everyone.
For an assessment, a read only account (Global Reader and Security Reader) with MFA that you create and delete afterwards. I never ask for Global Admin to look. For hardening or monthly work we agree the access up front and it is logged.
Not if it is done in order. Every change goes to report only first, then a pilot group, then everyone, with a break glass account in place. That is the whole point of paying someone who has done it before.
Yes. The controls I put in map directly onto Cyber Essentials in the UK, the ACSC Essential Eight in Australia and the CIS Microsoft 365 benchmark. The assessment report doubles as the evidence pack most questionnaires and insurers ask for.
You keep everything: the report, the configuration, the documentation, the runbooks. Monthly plans have a minimum term, then 30 days notice. There is no lock in because there is nothing of mine in your tenant.
A free 15 minute call, no slides. Tell me roughly how many people and devices, and I will tell you what I would look at first.