Thoughts & PR

Managed services for Microsoft 365: Much more than a support desk

For organisations running Microsoft 365, the managed services model we recommend is a 12-month advisory engagement that delivers measurable outcomes across five core areas: security, optimisation, enablement, AI governance, and data protection.

A common approach to managed services focuses on SLA metrics like response times, ticket volume, and uptime percentages. These measures matter, but a model focused only on responsiveness can leave businesses with unaddressed security gaps and licences they aren’t using to their full potential. This article explains what effective managed services should be delivering for South African companies.

Key takeaways

  • Managed services is built on five measurable capabilities: security posture, licence cost optimisation, enablement, AI governance, and data protection. It goes beyond a support desk.
  • Security comes first. Microsoft Secure Score helps track your security posture; it is not a calculation of breach probability or financial exposure.
  • Our approach uses a 12-month engagement. Value builds quarterly; an organisation won’t get all the benefit in month one, although significant gains can start early.
  • Success is measured by business outcomes, including cost savings, security improvements, training adoption, and reduced shadow AI exposure, alongside SLA response times.
  • This model often makes sense above 20 Microsoft users, although technical complexity and risk matter more than headcount alone. Smaller teams may benefit from lighter-touch guidance.

The foundation of managed services is always security

Before any discussion of cost savings or training, a managed services engagement begins by figuring out where the organisation stands from a security perspective. This assessment needs to focus on specific areas:

  • Who has access to what? Admin privileges should be restricted to those who need them. Identify unnecessary permissions in your tenant and remove them.
  • What devices are in use? Devices accessing corporate resources should meet your organisation’s access and compliance policies. Unmanaged devices can create avoidable exposure.
  • What applications are secured? Review the configuration of Microsoft 365, Azure, and Dynamics 365 against your requirements. Buying a licence does not replace the work of configuring and maintaining security controls.
  • What state is your data in? Documents scattered across desktops and USB drives are vulnerable. The standard should be managed storage in OneDrive and SharePoint, with appropriate access, retention, backup, and recovery arrangements.
  • Are you compliant? POPIA requires reasonable technical and organisational safeguards for personal information. These safeguards need regular review. A weak security posture creates governance risks far wider than just IT.

The measurement tool is Microsoft Secure Score

Microsoft Secure Score is shown as a percentage, alongside the points achieved out of the total possible points. The total is not fixed at 100. For example, a score of 34% means the organisation has achieved 34% of the available points in that score view.

Agree a target and action plan that fit your environment. A target such as 85% is an engagement objective, not a Microsoft compliance threshold or a guarantee against a breach. Practical starting points include multi-factor authentication and reviewing privileged access. The points available depend on the specific recommendation and its implementation.

For CFOs, it’s important to view a breach as something broader than downtime. A breach can disrupt financial systems and create regulatory exposure. Secure Score is one input to that discussion; it does not quantify the financial risk on its own.

The five focus areas for managed services

1. Security posture (the foundation)

Everything starts here. On the back of the security assessment, a managed services partner might recommend enabling multi-factor authentication. Ownership of these decisions is shared.

2. Optimisation (cost reduction)

A typical finding is that organisations are over-licensed or under-using existing licences.

In our experience, addressing that can yield 20 to 40 percent licence cost reduction in the first quarter, depending on the starting position, contract terms, and available changes. This is not a guaranteed saving. The reduction comes from right-sizing. A user who needs project management capabilities may need a different plan from a user who only needs email. Consolidation and tier-matching can reduce unnecessary spend while retaining required features.

3. Enablement (training)

You can optimise licences, but if your users don’t know how to use what they’ve licensed, the investment is wasted. This element of managed services targets a broad range of capabilities:

  • OneDrive and SharePoint discipline: Version history, recycle bins, and configured retention provide useful recovery capabilities. They do not automatically establish a separate backup service. Users need to understand how to save, share, and recover files, and what additional protection the organisation has arranged.
  • Email and calendar management: How to schedule meetings, delegate calendar access and more. These are not advanced skills, but they’re rarely taught.
  • Basic data hygiene: How to classify sensitive documents, or avoid accidentally sharing confidential data. This is crucial because unstructured data (documents, emails, spreadsheets) is what AI tools will eventually access.
  • Project management and other applications: If you’ve licensed Project, do your users know it exists? Do they have access? Can they run a report?

Training is a year-long engagement. The first month might be foundational skills. Months 4-8 focus on application adoption. Then months 9-12 prepare for strategic initiatives (like AI adoption).

4. AI strategy and governance

Many organisations are exploring AI before they have clear governance in place. Shadow AI means employees using AI tools outside the organisation’s approval and oversight. For example, uploading a client database to a personal ChatGPT account can put it outside approved controls. Whether content is used for training depends on the product and settings; ChatGPT users can turn off training in Data Controls. The governance problem is the unapproved handling of business data, not an assumption that every upload becomes training data.

Organisations can address this through a governed deployment of Microsoft Copilot in Microsoft 365, formerly Microsoft 365 Copilot. It uses existing access permissions, and Microsoft states that prompts, responses, and Microsoft Graph data are not used to train foundation models. Data is processed under the applicable service commitments, rather than simply staying inside a tenant. Web search, agents, and third-party models can involve different processing and terms, so administrators must review the enabled features and model settings.

The governance piece is equally important. Which users get Copilot access? What data can they input? What audit trails do you need? As new AI capabilities emerge, the governance framework must adapt.

This is not a one-time setup, but a matter of ongoing strategic discipline.

5. Data protection (backup)

Managed services should define the backup and recovery arrangements for Microsoft 365 email, documents, and shared sites. Agree the protected data, retention periods, recovery targets, and restore-testing responsibilities. Microsoft 365 Backup or another suitable backup service needs to be configured; storage and synchronisation alone are not the complete recovery plan. If a device is stolen, ransomware strikes, or data is accidentally deleted, those arrangements determine your recovery options.

Why SLAs miss the point

Many organisations, particularly CFOs encountering managed services for the first time, assume it’s a modernised version of the old SLA model. Someone to call when systems break, measured by response time and ticket volume.

For example, an SLA report might say that a provider fixed 47 tickets last month at a 95% resolution rate. An outcomes report should also show verified licence savings, security controls implemented, users trained to competency, and steps taken to reduce shadow AI exposure.

Any engagement that measures activity and neglects impact should undergo review by the C-suite, including the CFO who needs visibility into cost and value.

Reporting and accountability

How often does a CFO see reporting on this work?

Ideally, there should be at least quarterly meetings with the CFO, CIO, and CEO. In some cases, monthly meetings are necessary, particularly if the organisation is far from best practice.

Reports should show:

  • Licensing progress: Current state vs. target state, savings achieved, and variance analysis on monthly spend.
  • Security trajectory: Comparing historic and current Secure Scores. Specific recommendations delivered and accepted.
  • Enablement metrics: Rate of training completion and adoption, then usage of licensed features.
  • Strategic readiness: Is AI governance in place? Has the organisation gained control over its shadow AI footprint? These questions are critical for compliance going forward.

For the CFO, this kind of reporting replaces the vague promise of “we’ll manage your IT” with concrete visibility into where money is going and whether it’s working. The evidence should include:

  • Verified licence cost reductions against the agreed baseline
  • Secure Score progress, the controls implemented, and remaining risks
  • Training completion and evidence of adoption
  • Actions taken to reduce shadow AI exposure
  • A clear roadmap for AI adoption

Minimum viable scale: at what organisation size does this make sense?

For organisations with fewer than 20 Microsoft users, a full advisory engagement may cost more than the value it delivers. Lighter-touch guidance can be more appropriate. Above that level, the complexity often creates a stronger case for proactive management, training, and governance.

However, organisational size is not the main criterion. The real qualifier is user density, technical complexity, and risk. A 25-person professional services firm with 20 Microsoft 365 users may benefit from managed services. A 200-person company with only five users may need a different approach.

What comes next

This is the foundation. This is what managed services actually delivers: security, optimisation, enablement, AI strategy, and data protection, packaged as a continuous improvement partnership over 12 months.

The next step is understanding how to evaluate vendors and how this works in practice. That’s another conversation.

But the first conversation with your CFO must start here: managed services is not a support desk. It’s an advisory partnership that changes how you buy, secure, use, and evolve your Microsoft technology.

Next: How to Choose a Managed Services Vendor

Managed services done right delivers on five capabilities: security, optimisation, enablement, AI strategy, and data protection. All of it is measured and refined continuously over 12 months.

The next question most CFOs ask is straightforward: how do I pick a vendor who actually delivers on this? Read How to Choose a Managed Services Vendor, or contact Braintree to discuss your Microsoft environment.

Further reading

Related Posts

Choosing a managed services provider is not a...

Go-live gets the applause. The multi-year relationship that...

Microsoft began staged licence validation for Dynamics 365...