TSR Solutions Managed IT & security

What happens after you sign

Four to six weeks from kickoff to steady state. Every step has a deliverable you can check, and recurring billing starts only when the last workstream closes.

Managed IT onboarding

Four to six weeks from kickoff to go-live, run remotely during business hours. Nothing is switched off until its replacement is confirmed working, and your first recurring invoice is not raised until every contracted service has been verified as delivered.

  1. 1

    Week 1

    Discovery and scoping

    We learn how your business runs before we touch anything. Engineers document the network, inventory every device and account, review the current backup and security posture, and note any compliance obligations. The device and user counts we agree here are the counts you are billed on.

    • Network, device and account inventory reconciled against headcount
    • Security posture and backup review with gaps listed
    • Compliance requirements and key contacts recorded
    • Written onboarding plan with owners and dates
  2. 2

    Weeks 2–3

    Endpoint security cutover

    Defender for Business is onboarded through Intune to the TSR baseline and the detection agent is deployed to every device. Legacy antivirus is removed only after Defender is confirmed active on that machine, and alert routing into TSR is proven with a test detection before we rely on it.

    • Defender for Business active and reporting on every device
    • Detection agent deployed and a test alert received by TSR
    • Legacy antivirus removed per device, not in bulk
    • Patch policy applied and monitoring live in the ticket portal
  3. 3

    Weeks 3–4

    SIEM and DNS filtering enablement

    We agree which devices and network segments are monitored, then onboard the log sources and verify that logs are leaving each machine. DNS filtering rolls out with an initial category and threat policy that follows laptops off the office network.

    • Monitoring scope agreed and log forwarding verified per source
    • DNS filtering active on and off network with the initial policy
    • Behavioural baseline period started (the first 30 days tune the alerts)
  4. 4

    Weeks 4–5

    Identity consolidation

    We check the Entra ID baseline for MFA coverage, Conditional Access and self-service password reset, close the gaps, and retire any standalone MFA product once its seats are reconciled to headcount. Inactive licensed accounts are dealt with so you stop paying for people who have left.

    • MFA and Conditional Access enforced for every user
    • Self-service password reset enabled
    • Standalone MFA retired and licences reconciled
    • Inactive accounts disabled or removed
  5. 5

    Weeks 5–6

    Documentation, training and contract transition

    Network and IP documentation is completed, admin credentials are verified and vaulted, and escalation paths are recorded so support never depends on one person's memory. Your people learn how to reach the help desk and use the portal. The contract is built at the agreed counts and any superseded lines are end-dated. This step is the gate on billing.

    • Documentation complete per entity, credentials vaulted
    • Emergency contacts and escalation paths recorded
    • End-user session on the help desk, portal and what to expect
    • Contract finalised at agreed counts; superseded services end-dated
    • Every contracted service verified as delivered before the first invoice
  6. 6

    First 30 days after go-live

    Tuning and first review

    The SIEM learns what normal looks like, so expect some false positives while analysts tune it. At the end of the month we review ticket volumes, alert quality and anything that surprised us, and schedule your first quarterly business review.

    • Alert tuning complete and false positives reduced
    • First monthly report reviewed with you
    • Quarterly business review booked and roadmap started

Co-managed onboarding

The same four to six weeks and the same platform, with one difference: your internal IT team stays in charge of tier-1 support and administration. Kickoff writes down who owns what, and every workstream is done with your team rather than around it. Billing starts only when the last workstream closes.

  1. 1

    Week 1

    Discovery and the ownership split

    We document the environment with your IT lead and agree, in writing, who owns tickets, admin rights, patch approval, vendor calls and after-hours. The default is that your team keeps tier-1 and admin and TSR takes security, servers, network and escalations. Device and user counts are reconciled so the billable number is agreed, not assumed.

    • Responsibility matrix signed off by your IT lead and TSR
    • Inventory reconciled against headcount
    • Security posture and backup review shared with your team
    • Escalation path from your help desk to TSR defined
  2. 2

    Weeks 2–3

    Endpoint security cutover

    TSR onboards Defender for Business through Intune and deploys the detection agent; your team keeps its admin access and sees everything in the same console. Legacy antivirus is removed only after Defender is confirmed active on each device, and a test detection proves that alerts reach TSR.

    • Defender for Business active on every device, visible to both teams
    • Detection agent deployed and a test alert received by TSR
    • Legacy antivirus removed per device
    • Patch policy agreed with your team and applied
  3. 3

    Weeks 3–4

    SIEM and DNS filtering enablement

    Monitoring scope is agreed with your team, log sources are onboarded and forwarding verified, and DNS filtering rolls out with an initial policy your team can request changes to through the portal.

    • Monitoring scope agreed and log forwarding verified
    • DNS filtering active on and off network
    • Policy change process for your team documented
  4. 4

    Weeks 4–5

    Identity consolidation

    TSR reviews the Entra ID baseline and proposes the changes; your team approves them and keeps global admin. MFA and Conditional Access are enforced, self-service password reset is enabled, and any standalone MFA product is retired once seats match headcount.

    • MFA and Conditional Access enforced with your team's sign-off
    • Standalone MFA retired and licences reconciled
    • Admin roles reviewed; your team retains global admin
  5. 5

    Weeks 5–6

    Documentation, tool access and contract transition

    Documentation is completed in a shared system both teams work in, credentials are vaulted with access for your named admins, and your team is trained on the ticket portal, monitoring console and how to escalate to TSR. The contract is built at the agreed counts. This step is the gate on billing.

    • Shared documentation complete and credentials vaulted
    • Your team given access to the portal, monitoring console and documentation
    • Escalation and after-hours process rehearsed with your team
    • Contract finalised at agreed counts; every service verified before the first invoice
  6. 6

    First 30 days after go-live

    Tuning and first review

    Analysts tune the SIEM while it learns your normal, and TSR and your IT lead review the first month together: ticket flow between the two teams, alert quality and anything the responsibility matrix got wrong.

    • Alert tuning complete
    • Responsibility matrix reviewed and adjusted if needed
    • First monthly report reviewed with your IT lead

Want to see the kickoff checklist before you sign?

Ask for it. We would rather you know what the first six weeks look like than be surprised in week two.