Nobody owns the controls in your Microsoft 365.

You are on Microsoft 365, you have somewhere between 25 and 500 people on it, and you have no full-time security person. The settings that decide whether a stolen password turns into a real incident were mostly left where they landed years ago, and the person who would fix them is already doing everything else. Ten business days, remote, one fixed price — and a one-page register at the end that says what is on, when it changed, who owns it, and how you would prove it.

No access, nothing to install, no call. One page on a private link within two business days.

Founding three: the first three Control Sprints booked by Oct 31, 2026 are $1,500.

Five questions your tenant cannot answer today.

Not one of these needs a new product. Every one of them needs somebody to sit down for ten days and finish it.

The question, asked on a bad dayWhat the register says at the end

Is multi-factor actually on for everyone?

Every account, method by method, with the date it was enforced and the named exceptions.

Can somebody still sign in the old way?

Legacy sign-in blocked, with the report-only run that proved nothing broke first.

Can anyone on the internet send mail as us?

DMARC at enforcement, SPF and DKIM aligned, MTA-STS published, with the dates.

Who has Global Admin, exactly?

The trimmed list, plus two break-glass accounts documented where you can find them.

What happens the day somebody leaves?

A written joiner/leaver runbook your team can run without you in the room.

One person, and he has done this before.

GablePath Digital is Mark Restivo. He has run identity and onboarding provisioning and administered Microsoft 365, Active Directory and Hyper-V for a trading-technology firm. That work is confidential, so this page will not name the firm, show its code, or borrow its numbers.

Here is what this page does not have: a client list, a logo wall, a case study, or a certification badge. GablePath Digital LLC is a New Jersey company formed in 2026 and this is a new offer. The first three sprints are priced to change that, and the trade is written down below. Everything else you can check before spending anything — the exposure check needs no access at all, and the written agreement is published in full.

Ten business days, and you know what happens on each of them.

Remote. One kickoff call, one readout call, and a register you can open at any point in between. Nothing is switched on tenant-wide on day one, and nothing changes without you being told first.

  1. 01

    Days 1–2 — Read the tenant

    Read-only first: sign-in methods, admin roles, Conditional Access, mail authentication, sharing and guest settings, audit logging. You get the register populated with the starting state before a single setting is changed.

  2. 02

    Days 3–5 — Identity

    Multi-factor everywhere, a Conditional Access baseline, legacy sign-in methods turned off, admin roles trimmed to the people who need them, and two break-glass accounts created and documented. Every change a user can feel runs report-only first.

  3. 03

    Days 6–8 — Email and hygiene

    SPF, DKIM and DMARC taken to enforcement in steps, MTA-STS published, external senders tagged, anti-phishing and safe-links policies where the licence allows, audit logging on, a retention baseline set, shared mailboxes and stale guest accounts cleaned up.

  4. 04

    Days 9–10 — Hand it over

    The joiner/leaver runbook written for your team, the register finished — every control with a status, a date, an owner and its evidence — and a 30-minute readout where we walk it line by line. The admin account the sprint used is disabled or deleted while you watch.

Four groups of controls, in plain English.

Written as outcomes, not product names. Where a control needs a licence you do not have, it goes in the register marked “not licensed”, with what the upgrade would buy — we do not resell licences and we do not quietly skip the line.

Identity — who can sign in

  • Multi-factor authentication required on every account, including the administrators who exempted themselves from it
  • A Conditional Access baseline: block sign-ins from places you never work, require a trusted method, re-authenticate on the risky ones
  • Legacy sign-in methods turned off — the old protocols that skip multi-factor entirely
  • Admin roles trimmed to the people who actually need them; everyone else moved to a standard account
  • Two break-glass accounts created, excluded from the policies, and documented where you can find them at three in the morning

Email — who can send as you

  • SPF, DKIM and DMARC published and taken to enforcement in steps, so mail forged in your name is rejected instead of delivered
  • MTA-STS published, so mail sent to you is encrypted in transit and cannot be quietly downgraded
  • External senders tagged in the client, so “the CEO” asking for gift cards arrives visibly marked as an outsider
  • Anti-phishing and safe-links policies configured where your licence includes them
  • The mail-flow rules nobody remembers writing reviewed — starting with anything forwarding mail out of the company

Hygiene — what you can prove later

  • Audit logging turned on and confirmed, so the next question about who did what has an answer
  • A retention baseline, so nothing that matters disappears on a 30-day default
  • Shared mailboxes reviewed: who has access, and whether the account behind the mailbox can still sign in
  • Guest accounts inventoried — who they are, who invited them, and which ones go
  • Intune quick wins where you are licensed for them: device compliance and the basics, not a rollout

People — what happens on Monday

  • A written joiner/leaver runbook: the exact steps to open and close an account, in order, that somebody who is not you can follow
  • Offboarding that actually ends access — sessions revoked, tokens invalidated, mailbox converted, licences reclaimed
  • The register handed over as your document, not ours, so whoever comes next inherits it
  • A 30-minute readout walking the register line by line, and the recording if you want one

One page you can hand to an auditor, an insurer, or your replacement.

Every control in one table: what it is, whether it is on, the date it changed, who owns it from here, and the evidence that proves it. That is the sprint's whole output — not a forty-page report nobody opens twice.

Illustrative — from the sprint template, not a client.

ControlStatusDayOwnerEvidence
Multi-factor required for all usersDoneDay 3GablePathPolicy “MFA-All-Users”; report-only 3 days, enforced with 0 blocked sign-ins
Legacy authentication blockedDoneDay 4GablePathPolicy “Block-Legacy-Auth”; sign-in log filtered to legacy = 0 over 7 days
Global Administrator accounts trimmedDoneDay 5Client ITBefore 11, after 3 plus 2 break-glass; role-assignment export attached
Break-glass accounts documentedDoneDay 5Client ITTwo cloud-only accounts, excluded from Conditional Access, sealed in the client's password manager
DMARC at enforcement (p=reject)DoneDay 8GablePathDNS record plus 7 days of aggregate reports showing aligned pass on all legitimate senders
MTA-STS published (mode: enforce)DoneDay 8GablePathPolicy file served over HTTPS plus the _mta-sts TXT record
Joiner/leaver runbook signed offDoneDay 10Client ITRunbook v1 walked end to end with the service desk during the readout
Intune device compliance baselineNot licensedDay 9Client ITBusiness Standard tenant; needs Business Premium. Quoted separately, not silently skipped

Rows marked “not licensed” are real. The register records what your licence does not allow and what it would take, rather than leaving the line blank and hoping nobody counts.

$2,500 fixed

Ten business days, remote. $1,500 for the founding three.

  • Identity: multi-factor everywhere, a Conditional Access baseline, legacy sign-in off, admin roles trimmed, two break-glass accounts documented
  • Email: SPF, DKIM and DMARC to enforcement, MTA-STS, external-sender tagging, anti-phishing and safe-links where licensed
  • Hygiene: audit logging on, a retention baseline, shared mailboxes and guest accounts cleaned up, Intune quick wins where licensed
  • People: a written joiner/leaver runbook your team can run without you
  • A one-page Control Register — every control with a status, a date, an owner and its evidence
  • A 30-minute readout, and the admin access the sprint used removed while you watch

If the delivered sprint is not what your order form describes, tell us within 30 days of the readout and we correct it or refund every amount you have paid — we choose which, and we say so here rather than leaving you to find out. §5.1 and §9 of the written agreement, published in full.

Get my free exposure check

$7,500 to $15,000

$7,500 to 150 seats. $15,000 to 500 seats. Optional care at $500/month.

  • New-hire provisioning automated across Entra ID, Exchange and Teams — and on-premises Active Directory where you still have it
  • Offboarding automated the same way, so access ends the day employment does
  • An approval step before anything is created or removed, with the approver named on the request
  • An audit trail of every run: who asked, who approved, what changed, and when
  • Built on what you already pay for, handed over documented, with the runbook that goes with it
  • Optional $500/month care: we keep it running as your tenant changes

The same promise as the sprint: if what we deliver is not what your order form describes, tell us within 30 days and we correct it or refund every amount you have paid — we choose which. §5.1 and §9. Scope and price are put in writing before any work starts.

Get my free exposure check

Both start the same way: the free exposure check, then a short call to scope. Automation work is quoted in writing before anything begins. These are the real prices, not a starting band — your order form repeats the same numbers before any payment. Every promise here is written into the written agreement — published in full, no email required. If the two ever differ, whichever version is better for you controls (§2).

Four fields. Two business days.

The domain is the only thing we actually need — everything else is how we send the report back. No access, nothing to install, no agreement, and no call unless you ask for one.

That box is an automatic “not a robot” check from Cloudflare. It usually passes on its own; sometimes it wants one tap.

No sales call. No credit card. No obligation. Prefer email? hello@gablepath.com — or call (862) 432-1963.

What we look at, and what you get.

Public signals only: whether DMARC exists and what it tells receivers to do, whether SPF and DKIM line up with it, whether MTA-STS is published, where your mail actually lands, whether the tenant is Microsoft 365 and how it answers autodiscover, and whether the old sign-in endpoints are still open. Nothing is installed, nothing is scanned from the inside, and no credential is used — every one of those answers is already public. You get one page on a private, unindexed link within two business days: what we found, what it means, and the order we would fix it in. If that page is all you ever take from us, that is a fine outcome. What we do with the details you send is written in plain English on the privacy page.

Run it under your own name.

If you are an MSP and the ten-day pass is the gap in your stack, we will run it white-label: your name on the register, your relationship with the client, our ten days underneath. Same fixed price, same guarantee. We do not contact your client outside the engagement and we do not sell them anything afterwards.

Email hello@gablepath.com and say which tenant sizes you carry
01What access do you need?

Global Administrator in your tenant for the ten business days, through a named service account you create for the sprint — not a personal login and not a shared credential. Every change lands in the register as it is made, and the account is disabled or deleted on the last day while you watch. We do not read mailbox contents, files, or messages.

02Will anything go down?

No downtime is planned, and nothing is switched on tenant-wide on day one. The changes users can feel — multi-factor enforcement, blocking legacy sign-in, DMARC moving to enforcement — run report-only or in a pilot group first, and you are told before each one goes live. If a change would break something, the report-only run says so before it is enforced.

03Which licences does this work with?

Business Basic, Business Standard, Business Premium, E3 and E5. Premium and E5 unlock more — Conditional Access, Intune, and the anti-phishing and safe-links policies. On Basic or Standard we do everything the licence allows, mark the rest of the register “not licensed”, and tell you what the upgrade would buy. We do not resell licences and we take nothing from Microsoft.

04What if we are not on Microsoft 365?

Then this is not for you, and we would rather say so than stretch. The sprint is specific to Microsoft 365 and Entra ID. Google Workspace is out of scope.

05Who actually does the work?

Mark, personally. Nothing is subcontracted or sent offshore, and you are not handed to a junior after the sale. That is also the honest limit on how many of these can run at once, which is why the founding rate is three and not thirty.

06What does the free check cost us later?

Nothing, and it is not a trap. It carries no obligation and no call is attached unless you ask for one. If your domain comes back clean we will tell you that too — the report is worth more to you if we are willing to say there is nothing here to sell.

07How is this different from a vulnerability scan?

A scan produces findings. This produces changed settings, a register that names an owner for each one, and a runbook your team can run next month. Nobody leaves holding a list of things to do.

08We already have an MSP.

Good — bring them in. The register is written to be handed to whoever runs your tenant day to day, and plenty of MSPs are glad to have someone else do the ten-day pass. If yours would rather run it themselves, we will do it under their name.

Start with the part that costs you nothing.

The external exposure check needs no access, installs nothing, and comes back on a private link within two business days.

Get my free exposure check

No sales call. No credit card. No obligation.

Founding three: the first three Control Sprints booked by Oct 31, 2026 are $1,500.

Call (862) 432-1963