MFA · Conditional Access · Intune · License waste
Microsoft 365 Security & Licensing Review for Healthcare
Most Central PA practices already pay Microsoft every month. The tenant is the network: mail, files, Teams, the identity that unlocks the EHR browser, and the laptops that go home to Hollidaysburg or Ferguson Township. The bill is rarely the interesting part. The interesting part is whether MFA is real, whether a guest link can leak a visit note, whether Intune actually manages the devices you think it does, and whether you are still paying for seats from 2022.
InTech Network Solutions is a healthcare-first MSP founded in 2013 (orthopedics, GI, specialty practices; also 25–500 employee organizations and co-managed IT). This review is a written look at security controls and license spend in Microsoft 365. It is not a migration pitch, not a “cloud transformation,” and not HIPAA certification.
Call 814-264-2444. Automated attendant. Leave a message or use the request button. We return business-hours requests. We do not claim a human answers every inbound call.
Why healthcare tenants rot in a specific way
A law firm’s Microsoft 365 mess is annoying. A specialty practice’s mess is ePHI in the wrong sharing link.
Front desk reality. Shared mailboxes, shared passwords on a sticky note, a “clinic” login so room 3 can open the EHR. That pattern survives every “we turned on MFA” project because the exception list is where the doctors live.
Providers who work everywhere. Altoona hub, Tyrone satellite, home in State College, a day in Huntingdon. Identity and device control have to follow the person. If Intune only knows the PCs that were in the building on install day, you do not have device management.
Files that outran the file server. Imaging exports, operative notes, and “temporary” ZIPs in OneDrive because the old server was slow. SharePoint guest links that never expire. That is an healthcare IT problem hiding in a Microsoft SKU.
License inertia. E3 for a scribe who left. Business Premium on a kiosk. Teams Phone add-ons nobody uses. The invoice grows; the security baseline does not.
If the real question is “is our MSP doing any of this,” start with the MSP second opinion. If the question is the HIPAA-shaped write-up (BAAs, audit logs, ePHI at rest across the whole stack), use the HIPAA IT review. This page is the Microsoft tenant.
What we review
You remain the owner of the tenant. We use Global Reader / time-boxed admin you approve. We do not take over billing as a condition of looking.
MFA — the real coverage, not the slide
Who has MFA. Who is excluded. Legacy authentication still on. Shared mailboxes and service accounts. Break-glass admins sitting in a password manager versus sitting in a Word doc on a front-desk PC in Duncansville.
Conditional Access
Are there policies, or only a screenshot from a prior vendor? Named locations, device state, admin roles, block of legacy auth, grant controls that actually grant. Empty Conditional Access with MFA-per-user is a finding we see often.
Intune and unmanaged devices
Which devices are enrolled. Which are “workplace joined” and drift. Whether a lost provider laptop can be wiped. Whether personal PCs used for ePHI are in scope at all. Unmanaged home machines in Bellefonte and Logan Township are a clinical workflow, not an edge case — treat them as such or document the exception.
Sharing, SharePoint, OneDrive, Teams
Anonymous links, external guests, expired (or never-expiring) sharing, Teams with former employees still in the roster, public sites that were “just for the renovation.” This is where ePHI leaves because someone needed to send a file at 4:55 p.m.
Mail compromise paths
Forwarding rules, inbox rules that hide mail, consent grants to random OAuth apps, overly broad send-as. Cybersecurity is the wider service; mail is still how most practices get hurt.
Admin roles and privilege
How many Global Admins. Whether the MSP’s partner relationship is GDAP with least privilege or a permanent Global Admin named after a technician who left. Whether you could recover the tenant if that vendor disappeared.
License waste
SKU-by-SKU versus actual humans and kiosks. Add-ons stacked on the wrong license. Visio/Project ghosts. We will put a cleanup list in the findings. We will not promise a savings percentage before we see the bill. We also will not recommend a cheaper SKU that drops the security features you need — that is how practices “save” their way into a gap.
Backup of Microsoft 365 itself
Native recycle bins are not a ransomware plan for Exchange and SharePoint. We will say whether you have a real M365 backup or only a file-server backup. See backup and disaster recovery.
What you get
- Written findings on MFA, Conditional Access, Intune, sharing, admin roles, mail paths, and SKUs.
- A 30-day fix list we can execute if you want us to: close MFA holes, kill anonymous links, shrink Global Admin, remove dead licenses. Thirty days is a work plan, not a guarantee that the tenant is “done.”
- A 60/90 for Intune enrollment, device compliance, and any licensing change that needs procurement.
- Your choice of operator after: keep the current MSP, co-manage beside your IT person, or move managed IT to InTech.
Help desk is how staff live with MFA and Intune after the review. If you skip that, the work gets undone at the front desk in a week.
What this is not
- Not a Microsoft partnership badge collection. We will not invent certifications.
- Not a HIPAA/HITECH certification. Pair with compliance and risk or the HIPAA IT review when you need the broader document. The M365 review is not a legal opinion.
- Not a live-answer line. Automated attendant. Contact hours: Monday–Friday, 8:00 a.m.–5:00 p.m. Eastern.
- Not a requirement to buy licenses through us.
Owner: Lance Schreffler. Phone 814-264-2444. Email contact@intechns.com. We do this for practices and 25–500 employee organizations in Altoona, State College, Huntingdon, Johnstown, Bedford, Lewistown, Clearfield, and Tyrone. No public street address. Local pages: Altoona, State College.
No testimonials, review counts, or “average license savings” on this page.
Get an M365 security & licensing review
Call 814-264-2444
Call 814-264-2444 · email contact@intechns.com. Automated attendant. Monday–Friday, 8:00 a.m.–5:00 p.m. Eastern. Or use the contact form.
