TSR Solutions Managed IT & security

Co-Managed Guardian

Guardian's monitoring, security operations and tooling behind your own IT team.

Who it is for

Businesses with in-house IT staff who want to keep the front line and hand security, servers and the network to TSR.

Co-Managed Guardian gives your internal IT team the same platform TSR runs for fully managed clients — 24×7 detection and response, log retention, DNS filtering, patching, monitoring and documentation — while your team keeps tier-1 support and administrative control. TSR looks after security, servers and the network, takes after-hours escalations and carries the security operations centre relationship. Your team gets the tools, the portal and an engineer to call, without giving up the parts of IT it already does well.

Inside the rate

  • 24×7 managed detection and response by a staffed security operations centre
  • Logs kept off the machine that generated them, and DNS filtering on and off the network
  • Patching, configuration enforcement and zero-touch deployment for every endpoint
  • Help desk and onsite support for security, servers and the network, plus a 24×7 on-call engineer
  • Your team keeps user tickets, administrative rights and day-to-day decisions
  • Shared ticket portal, monitoring console and documentation your team can work in
  • Quarterly business review and vCIO planning alongside your IT lead
  • Microsoft 365 security baseline maintained by TSR, with drift reported to your team

What it does not do

  • User help desk. Your team owns tier-1 tickets; TSR's help desk covers security, servers and the network and takes escalations.
  • Day-to-day administrative decisions. Your team keeps admin control; TSR maintains the security baseline and flags drift rather than overriding it.
  • Incident remediation beyond the immediate response, which is time and materials per the TSR Services Guide.
  • Migration projects, which are scoped and quoted separately.

Services with this package

Included in the rate

Available as add-ons

What happens after you sign

Billing starts when the last workstream closes, not when the contract is signed.

  1. 1.Week 1

    Discovery and the ownership split

    We document the environment with your IT lead and agree, in writing, who owns tickets, admin rights, patch approval, vendor calls and after-hours. The default is that your team keeps tier-1 and admin and TSR takes security, servers, network and escalations. Device and user counts are reconciled so the billable number is agreed, not assumed.

  2. 2.Weeks 2–3

    Endpoint security cutover

    TSR onboards Defender for Business through Intune and deploys the detection agent; your team keeps its admin access and sees everything in the same console. Legacy antivirus is removed only after Defender is confirmed active on each device, and a test detection proves that alerts reach TSR.

  3. 3.Weeks 3–4

    SIEM and DNS filtering enablement

    Monitoring scope is agreed with your team, log sources are onboarded and forwarding verified, and DNS filtering rolls out with an initial policy your team can request changes to through the portal.

  4. 4.Weeks 4–5

    Identity consolidation

    TSR reviews the Entra ID baseline and proposes the changes; your team approves them and keeps global admin. MFA and Conditional Access are enforced, self-service password reset is enabled, and any standalone MFA product is retired once seats match headcount.

Built on

  • MicrosoftMicrosoft 365, Entra ID, Intune and Defender for Business
  • Blackpoint Cyber24×7 managed detection and response
  • NinjaOneEndpoint monitoring, patching and remote support
  • AutoElevatePrivilege management
  • HuduDocumentation and credential vaulting
  • Phin SecuritySecurity awareness training and phishing simulation

Co-Managed Guardian questions

How is the split decided?

At kickoff we write down who owns what: tickets, admin rights, patch approval, vendor calls and after-hours. The default is that your team keeps tier-1 and admin, and TSR takes security, servers, network and escalations.

Does our team get access to TSR's tools?

Yes. Your team works in the same ticket portal, monitoring console and documentation system as TSR's engineers, with access scoped to your environment.

What if our IT person is on leave?

TSR can cover tier-1 for an agreed period at the hourly rate in the TSR Services Guide, and the on-call engineer is already in place for after-hours.

Can we move to full Guardian later?

Yes. The platform is identical, so the change is a contract update and a help desk handover rather than a new onboarding.

Request a Co-Managed Guardian quote

User count, locations and whether you have IT staff today is enough for a first number. An engineer replies within one business day.

Prefer to talk? Call 262-292-2000.