Microsoft + ClaudeOne partner for the cloud you run and the AI you put on top of it.
Avalon Web ServicesMicrosoft · Claude · Security

Buy a tool, or have someone watch it for you

There are three ways to keep an eye on a Microsoft 365 tenant: use what you already pay for, buy software that watches it, or pay someone to watch it for you. The comparison usually gets made on features and price, and both are the wrong axis. What actually separates them is who is accountable for looking when nothing is obviously wrong, and what that party can change while they are looking. A read-only integration holds no write scope at all. The default admin relationship a managed provider receives can reset a password and disable an account. Settle that question before the feature list.

Written by
Arif Ali Mughal
Published
Reading time
8 min

01 / 11

The question underneath the question

This decision gets framed as a product comparison: features on the left, price on the right, pick a column. It is the wrong shape for the problem, and it is why so many of these purchases quietly change nothing.

Microsoft is unusually plain about where the line falls. In its shared responsibility model, whatever the deployment, you always retain the following responsibilities: Data... Endpoints... Accounts... Access management. For a SaaS tenant, the configuration and the identities in it are yours. Nothing you buy moves that line — it only changes who is standing on your side of it.

So the real question is not which product is better. It is who is accountable for looking when nothing is obviously wrong, and — the part nobody puts in the comparison — what that party can change while they are looking. Those two questions sort the options faster than any feature table.

02 / 11

Option one: what you already pay for

Start here, because a surprising number of organisations buy a second thing before switching on the first. Every tenant has Microsoft Secure Score, service health, and sign-in and audit logging. Business Premium adds Entra ID P1, Intune and Defender for Business on top.

What you do not get is set by licence, and it is worth knowing the specific gates before you conclude the built-in tier is thin. Conditional Access requires Microsoft Entra ID P1 licenses. Identity Protection is the sharper cut: on P1 the risky users and risky sign-ins reports show limited information only, risk detections are not available at all, and risk-based policies need P2. Privileged Identity Management needs P2 or an Entra ID Governance licence. Defender XDR's unified incident queue needs a qualifying plan, which Business Premium has and a bare E3 does not.

None of that is a reason to buy anything. It is the map you need to tell whether your problem is a missing capability or a missing habit — because only one of those has a product attached.

03 / 11

Option two: software you run

The second option is a product that reads your tenant on a schedule and puts the answers on one screen. Typically it connects as a multi-tenant application you consent to, holding Microsoft Graph application permissions.

What it genuinely changes: the looking becomes continuous rather than occasional, the answers arrive in one place rather than six, and history accumulates past the point where Microsoft's own retention would have dropped it. That is real value and it is not nothing.

What it does not change is the part people assume it does. A tool does not decide that something matters, and it does not open the portal and fix it. It raises the ceiling on what you could notice; it does nothing about whether anybody is reading. If the honest answer to who reads this dashboard on a Tuesday is nobody, a second dashboard is not the purchase you need.

04 / 11

Option three: someone watches it for you

The third option buys attention rather than software. Somebody outside your organisation is contractually on the hook for looking, and for telling you what they found.

This is the option that addresses the accountability problem, because accountability is the thing being bought. It survives your one technical person leaving, which neither of the others does, and it is the only one where the answer to who reads this on a Tuesday has a name attached.

It is also the option that costs you something the other two do not, and the price is not the retainer. It is access.

05 / 11

The access question nobody puts in the comparison

There are two quite different ways an outside party gets into a Microsoft 365 tenant, and they are not close to equivalent.

The first is a read-only application registration. Microsoft Graph permissions are explicit and additive: an application granted only read permissions has no write scope, so there is no code path by which it changes anything. That is an architectural property, not a promise — you can read the consent screen and verify it yourself.

The second is a GDAP relationship — granular delegated admin privileges, the mechanism by which a provider in Microsoft's partner programme administers your tenant. GDAP is a real improvement on what came before: least-privilege by design, roles chosen rather than blanket, and time-bound, with a documented maximum of two years and requests that expire after ninety days if you never respond.

But least-privilege by design means scoped by what you approve, and the default role set Microsoft assigns in its own migration path includes User Administrator, a role Microsoft describes as able to manage all aspects of users and groups, including resetting passwords for limited admins — in practice creating, deleting, disabling and enabling accounts and forcing sign-outs. Helpdesk Administrator, also in that default set, can reset passwords for non-administrators.

That is not a scandal. If you hired someone to fix things, they cannot fix anything without it. Our argument, and we will label it as ours: match the access to the job. Monitoring does not need write access. Remediation does. A provider who asks for one set when doing the other job should be able to explain why.

WHAT THE OUTSIDE PARTY CAN DO BUILT-IN ONLY NOTHING There is no outside party. READ-ONLY APP REGISTRATION READ ONLY Reads exactly the permissions you granted. No write scope is granted, so none exists. GDAP ADMIN RELATIONSHIP READ AND CHANGE The default role set includes User Administrator, which can create, delete and disable users, and reset passwords. Scoped by what you approve, not by design. ACCESS GRANTED TO THE OUTSIDE PARTY The middle step is architectural: a read-only app has no write scope. The right-hand step is a policy choice you approve. Read from Microsoft Learn on 16 September 2026. GDAP is least-privilege by design; the roles it carries are the ones you approve.
The feature comparison rarely includes this axis, and it is the one that matters most. A read-only integration cannot change your tenant because it holds no write scope. The default admin relationship a managed provider receives can reset a password and disable an account on day one — which is correct if you hired them to fix things, and more access than the job needs if you hired them to watch.

06 / 11

The three options, side by side

Read the first two rows before the last four. Cost tends to decide these purchases, and cost is the row that matters least.

Already paid forSoftware you runSomeone watches
Who notices a changeNobody, unless someone opens the portalThe product, for what it watchesThe provider, on the agreed cadence
Who is accountable for lookingWhoever you named, if anyoneStill you. Software does not read itselfThem, in writing
Outside access requiredNoneA consented app registrationUsually a GDAP admin relationship
Can they change your tenantNot applicableNo, if every permission is read-onlyYes, if the approved roles allow it
When your one admin leavesThe looking stopsCollection continues, nobody reads itThe looking continues
Cost when nothing is wrongNothingThe subscriptionThe retainer
Evidence for an auditorWhatever Microsoft still retainsWhatever the product keptWhatever the contract says

07 / 11

The floor the platform sets, which none of the three beats

One thing worth knowing before you evaluate anybody's real-time claims: some of the lag is Microsoft's, and no product or provider can undercut it.

Intune device compliance is the clearest case. Before a device state appears, Microsoft says, it must check in, process the policy and report — and this process can take up to 24 hours when the device is online. Secure Score has its own rhythm: For Microsoft Teams and Microsoft Entra related recommendations, the recommendation state will get updated when changes occur in the configuration state. In addition, the recommendation state is refreshed once a month or once a week, respectively.

So a vendor promising you will know within minutes that a laptop fell out of compliance is describing something the platform does not supply. The honest version is that you will know when Microsoft knows, plus however long the collection cycle adds.

One more thing we went looking for and did not find: a Microsoft-published recommendation for how often to review your own posture. We checked the Secure Score pages, the improvement-actions guidance and the access-reviews documentation, and found cadence treated as the organisation's decision. We may have missed a page. But if nobody tells you how often to look, that is a decision you own — and it is the one all three options are really answers to.

08 / 11

What two governments tell you to ask

If you go the third route, you do not have to invent the diligence questions. Two pieces of published government guidance cover this ground, both free and neither selling anything.

The UK's National Cyber Security Centre published Choosing a managed service provider (MSP) in November 2025. It is short, plain and aimed squarely at smaller organisations. Among the things it tells you to establish before signing:

  • That software is patched within 14 days of an update being released (where the patch fixes a critical or high-risk vulnerability).
  • What backup arrangements are in place, how often these are tested and if these suit your requirements — testing, not just existence.
  • If logs are being kept for security purposes and how long these are kept for.
  • How they manage access into your systems and how those connections are secured, with two-step verification and least privilege applied.
  • Clear steps on how they will respond to any incidents and how they will engage with you — written into the contract, alongside roles, liabilities and notification timeframes.

09 / 11

And the one nobody wants to bring up

The second document is harder reading and more useful for it. In May 2022 seven agencies — CISA, the NSA and the FBI in the United States, alongside the British, Australian, Canadian and New Zealand cyber centres — published joint advisory AA22-131A on protecting managed service providers and their customers. Its subject is providers being used as a route into the customers who trusted them.

Its recommendations to customers are specific, and they are reasonable things to put to anyone you are considering, including us. Customers should ensure that their contractual arrangements mandate the use of MFA on the services and products they receive. Access should be granted on a need-to-know basis, using the principle of least privilege. Provider accounts should be restricted to systems managed by the MSP rather than dropped into your internal administrator groups. And you should review and verify all connections between internal systems, MSP systems, and other networks.

None of that makes hiring a provider a bad idea. It makes an unexamined one a bad idea, which is a different claim.

10 / 11

When the answer is: buy nothing

There is a real case here and it deserves saying plainly, because most articles like this one never reach it.

If you run Business Premium or E5, if you have somebody technical who will genuinely take a recurring hour, and if you are prepared to name that person and put the hour in a calendar, then turning on what you already own beats buying anything. Switch on Conditional Access. Look at Secure Score. Read the risky sign-ins if your licence surfaces them. You already paid for all of it, and the gap between licensing a capability and switching it on is two different administrative actions — that is our reasoning, not a statistic, because we could not find a credible one.

The case for buying is narrower than the category usually admits: it is that the recurring hour never actually happens. Not because anybody is lazy, but because the person who would do it has four other jobs, and a quiet tenant generates no pressure to look at it. If you tried the calendar version and it decayed within two months, that is real evidence about your organisation, and worth more than any feature list.

11 / 11

Where to start

Before you evaluate anything, answer the two questions at the top in writing. Who is accountable for looking, and what can they change while looking. A single page with those two answers on it will disqualify most of what you would otherwise sit through a demo for.

Then, whichever way you go, check the access against the job. If you are buying monitoring, ask whether every permission it requests is a read permission, and ask to see the consent screen before you consent to it. If you are buying remediation, expect write access and apply the controls the advisory above describes.

Disclosure, because this post compares a category we sell into. Avalon Web Services runs Avalon CloudSec, which is option two operated as option three: read-only by architecture, every Microsoft Graph permission a read permission and Azure access through Microsoft's own Reader roles, monitored by us so the recurring hour is our problem. It cannot change your tenant, which also means it cannot fix anything — every change stays with your team, in Microsoft's own screens. That trade is deliberate, and it is the wrong trade for some buyers. To work out which column you are actually in, email support@awservices.org.

Microsoft, Microsoft 365, Azure, Entra, Intune and Defender are trademarks of the Microsoft group of companies. Avalon CloudSec is an independent service and is not endorsed by Microsoft.

Primary sources

Want us to run this for you?

Start here

Tell us what'skeeping you upat night.

Most engagements start with a Cloud Health Check — one week, full audit, top-10 findings, 90-day roadmap. Many turn into a longer engagement; either way, you walk away with a prioritized plan you own.