Skip to content

Microsoft 365 & Cloud

Microsoft 365 is not set it and forget it.

Most businesses assume someone is managing their 365 tenant. Most of the time nobody is. Identity, sharing, security settings, licensing and AI tools all the active oversight. Without that oversight security falls behind in ways that don't show up until there is an incident.

A managed IT provider with deep Microsoft 365 experience can make sure your Microsoft 365 and email are set up correctly. At 3rd Element, that means reviewing and managing tenant security, MFA and conditional access, email security (SPF, DKIM, and DMARC), sharing settings, mailbox forwarding, and admin access, then keeping it that way as your business changes.

3rd Element Consulting manages and secures Microsoft 365 tenants for growing businesses, covering identity, email, sharing, licensing, and Copilot readiness against a written configuration standard.

The pattern

When 365 is treated like email, security settings drift and nobody notices.

Most Microsoft 365 tenants are set up once and left alone. The provider moves on, the business assumes it's monitored and managed and reality is no one is actively managing identity, security settings, and sharing rules. It's not a criticism, it's just how most providers work with Microsoft 365.

Security defaults drift. Former employees stay in the system. Sharing permissions expand beyond what was intended. You overpay for licensing. And by default, users can install third party apps directly into the tenant - most businesses don't know what's happening until an incident occurs.

What we own

What we manage inside Microsoft 365.

9 areas, swipe or use arrows

Users, groups, and access

Provisioning, offboarding, license assignment, and access reviews, not done by ticket only.

MFA and sign-in security

MFA, conditional access, and admin role hygiene configured against a written standard.

Teams, SharePoint, OneDrive

Sharing rules, guest access, and file structures that match how the business actually collaborates.

Email security

Anti-phishing, mailbox rule monitoring, external sender warnings, and impersonation protection.

Licensing and cost review

What you are paying for, what is in use, and what can be consolidated, surfaced quarterly.

Microsoft 365 backup

Independent backup of mailboxes, OneDrive, SharePoint, and Teams, because Microsoft does not back up your data the way you think.

Data protection and DLP

Sensitivity labels and data loss rules tuned to how your business actually shares information.

Connected apps and integrations

Third-party apps that touch 365 reviewed for access scope, ownership, and risk.

Copilot and AI readiness

Reviewing what Copilot would expose given today's permissions, before turning it on broadly.

Microsoft 365 review

What we check

  • MFA on every account, including admins
  • conditional access policies
  • admin roles limited to the people who need them
  • email security (SPF, DKIM, DMARC) and external email tagging
  • external sharing settings in SharePoint, OneDrive, and Teams
  • mailbox forwarding to outside addresses
  • audit logging
  • licensing that supports the security features you rely on
  • Copilot readiness, if you plan to use it

See Microsoft 365 Security Gaps Most Businesses Miss.

How we work

Review the tenant, clean up what fell behind, then manage it.

We start by looking at how 365 is being used - who has access to what, what is shared externally, what licensing is in place, and how security is configured. Most tenants have more risk and exposure than anyone realized.

Whatever has fallen behind gets cleaned up against the written 365 baseline. Then 365 is managed as an ongoing system, with security and sharing rules reviewed as the business changes.

A 3rd Element technician managing a Microsoft 365 tenant at a standing workstation.

What changes

Microsoft 365 stops being a black box.

Leadership can describe what is configured and why. Offboarding actually finishes. Sharing is intentional. Licensing maps to people who are still here. AI questions can be answered before someone enables Copilot for everyone.

Who we work best with

Built for companies that want IT held to a standard.

Something brought you here. If you're with an organization of about 10 to 250 employees, headquartered in or operating across Central PA, that depends on its technology to operate and is ready to hold its IT to a written standard, you've probably outgrown whoever was managing IT before or something specific made the gap visible.

A strong fit

  • Leadership is ready to treat IT as part of how the business runs.
  • Teams tired of explaining the same problems to the same provider.
  • Operations where downtime, lost data, or a security event would put the business at risk.
  • An internal IT person who can't be a specialist in every area and doesn't have visibility into how other organizations solve the same problems.

How we work

  • We price for the outcome, not the lowest monthly rate. If price is the only deciding factor, we're probably not the best match.
  • We'll tell you when something needs attention, even if you didn't ask.
  • Every client runs to a security baseline: MFA, patching, and tested backups. We don't make exceptions, because we're accountable for the result.

Microsoft 365 security

Take something with you.

A free checklist of the settings most tenants never turn on. Work through it and you will close the gaps we see most often.

Common questions

Questions leadership usually asks first.

Who can help make sure our Microsoft 365 and email are set up correctly?
A managed IT provider with deep Microsoft 365 experience. 3rd Element reviews and manages Microsoft 365 tenant security, MFA and conditional access, email security including SPF, DKIM, and DMARC, sharing settings, mailbox forwarding, and admin access for businesses across Central PA and nationwide.
Does Microsoft back up our data?
Not the way most leaders assume. Microsoft protects the platform, not your data from accidental deletion ransomware or a departing employee wiping email from their mailbox. An independent backup covers your company data for when you need it most.
We were told MFA is on. Is that enough?
MFA is one control, and an important one. But, on its own doesn't cover conditional access, admin role hygiene, legacy authentication still running in the background, or what happens when an account is compromised despite MFA. We look at the full identity configuration, not just if one box was checked.
Can you help us with Copilot?
Yes - but we won't activate Copilot licenses without a data cleanup project first. Copilot inherits the permissions of whoever is running it. If sharing is overly permissive or sensitive files aren't labeled properly, Copilot will serve that information to anyone asking for it. We help you get the tenant ready before Copilot is turned on so you get the benefit without the exposure. We can also show you what AI tools are already running in your environment. Most businesses are very surprised by what is found.
Can you help with cyber insurance questions?
Yes. Most insurance applications ask about controls leadership has never had to think about before. We translate the questions, review the environment against them, and help you answer with evidence instead of guesswork. If there are gaps, we'll tell you what they are and what it takes to close them.  We also work with an insurance partner who specializes in cyber coverage - if you want additional options or a second set of eyes on the technical requirements, we can bring them in without replacing your existing broker relationship.
What is an IT Environment Review?
The IT Environment Review is free and takes about 30 minutes by video or phone. We ask a set list of questions about your environment, answer yours, and send you a written summary afterward.

Continue reading

Related work and reading.

In Harrisburg: Microsoft 365 Support

How this work applies for Harrisburg and Dauphin County organizations.

Read more: In Harrisburg: Microsoft 365 Support

Client Story: The Acquisition IT Work That Keeps Coming Back

Each acquired company arrived with its own tenant and its own settings. One standard 365 configuration replaced all of them.

Read more: Client Story: The Acquisition IT Work That Keeps Coming Back

Client Story: One Company, One Standard, Across Every Office

A global manufacturer moved every office onto the same 365 tenant standard instead of a different setup per site.

Read more: Client Story: One Company, One Standard, Across Every Office

Backup and Recovery Planning

Independent backup for mailboxes, OneDrive, SharePoint, and Teams. Because Microsoft doesn't back up your data the way most people assume.

Read more: Backup and Recovery Planning

Standards & Security Baseline

The written 365 configuration every tenant we manage is held to, not whatever the defaults happen to be.

Read more: Standards & Security Baseline

Cybersecurity Services

Identity, email, and sharing in 365 are where most modern risk actually lives.

Read more: Cybersecurity Services

Microsoft 365 security gaps most businesses miss.

The settings that stay open long after initial setup, and what they expose.

Read more: Microsoft 365 security gaps most businesses miss.

From Manual to Automated: Building Real Workflows in Microsoft 365

What the tools you already license can automate once the tenant is managed properly.

Read more: From Manual to Automated: Building Real Workflows in Microsoft 365

Next step

Get a clearer view of your IT environment.

Find out what is working, where the risks are, and what needs attention next.