TSR Solutions Managed IT & security

Guardian

Full managed IT with 24×7 detection and response, built on Microsoft 365 Business Premium.

Who it is for

Businesses that want IT and security run for them, on one per-user rate.

Guardian is TSR's current managed services plan: one per-user rate, one invoice line, covering monitoring, patching, service desk, identity, endpoint protection, 24×7 managed detection and response, off-host log retention and DNS filtering. It is built on the Microsoft 365 Business Premium security stack you already license — Defender for Business, Entra ID, Intune — so it removes third-party agents and duplicate licences rather than adding them. If you are mid-migration, Guardian picks up where the project leaves off.

Inside the rate

  • 24×7 managed detection and response by a staffed security operations centre, not an alert queue
  • Security and system logs kept off the machine that generated them, so an intruder cannot erase the copy
  • DNS filtering on and off the corporate network to break the tool-download and command-and-control step
  • Defender for Business managed through Intune, already licensed in Business Premium, no extra agent
  • MFA and Conditional Access enforced in Entra ID, with self-service password reset
  • 24×7 workstation monitoring, patching and secure remote support on a defined patch policy
  • Users run without local admin rights; elevation is granted per application, not permanently
  • Help desk for every user, a 24×7 on-call engineer, and documentation that does not live in one person's head

What it does not do

  • Incident remediation beyond the immediate response. Guardian shortens the time between an intrusion and its discovery; cleanup is time and materials per the TSR Services Guide.
  • A firewall. DNS filtering addresses the outbound path; it is not a substitute for a managed firewall or for secure application development.
  • Migration projects. Entra ID, Intune, server and domain migrations are scoped and quoted separately; Guardian consumes the result rather than re-billing it.
  • A guarantee. Guardian is defence in depth, not a warranty that every malicious activity is detected, avoided or recovered.

Today, and under Guardian

The changes we make most often when a business moves to this package, and why.

Today Under Guardian Why
No managed detection and response Blackpoint SOC, 24×7 Antivirus inspects files. An attacker in memory or using the operating system's own tools produces no file to inspect.
Logs held locally at default retention SIEM with off-host retention Default Windows retention is days, on the machine the intruder controls.
No DNS-layer filtering DNS filtering on and off the network The cheapest place to break the tool-download and command-and-control chain, and it covers laptops away from the office.
Third-party endpoint antivirus (for example Sophos) Defender for Business Already licensed in Business Premium, same Intune console, native SOC telemetry, one fewer agent.
Standalone MFA (for example Duo) Entra ID MFA belongs with the identity it protects. Adds Conditional Access and self-service password reset, and removes a seat count that drifts.
NinjaOne, AutoElevate and a service desk already in place Unchanged Existing TSR clients re-onboard rather than rebuild.

Services with this package

Included in the rate

Available as add-ons

What happens after you sign

Billing starts when the last workstream closes, not when the contract is signed.

  1. 1.Week 1

    Discovery and scoping

    We learn how your business runs before we touch anything. Engineers document the network, inventory every device and account, review the current backup and security posture, and note any compliance obligations. The device and user counts we agree here are the counts you are billed on.

  2. 2.Weeks 2–3

    Endpoint security cutover

    Defender for Business is onboarded through Intune to the TSR baseline and the detection agent is deployed to every device. Legacy antivirus is removed only after Defender is confirmed active on that machine, and alert routing into TSR is proven with a test detection before we rely on it.

  3. 3.Weeks 3–4

    SIEM and DNS filtering enablement

    We agree which devices and network segments are monitored, then onboard the log sources and verify that logs are leaving each machine. DNS filtering rolls out with an initial category and threat policy that follows laptops off the office network.

  4. 4.Weeks 4–5

    Identity consolidation

    We check the Entra ID baseline for MFA coverage, Conditional Access and self-service password reset, close the gaps, and retire any standalone MFA product once its seats are reconciled to headcount. Inactive licensed accounts are dealt with so you stop paying for people who have left.

Built on

  • MicrosoftMicrosoft 365, Entra ID, Intune and Defender for Business
  • Blackpoint Cyber24×7 managed detection and response
  • NinjaOneEndpoint monitoring, patching and remote support
  • AutoElevatePrivilege management
  • HuduDocumentation and credential vaulting
  • Phin SecuritySecurity awareness training and phishing simulation

Guardian questions

Do we need Microsoft 365 Business Premium?

Yes. Guardian uses Defender for Business, Entra ID and Intune, which Business Premium includes. If you are on a lower plan, the uplift is part of the quote and usually replaces licences you already pay a third party for.

What happens in the first 30 days?

The SIEM learns what normal looks like on your network. Expect some false positives and know that tuning is still under way. After that the analysts have a baseline to compare against.

We already use Sophos and Duo. What changes?

Defender for Business replaces Sophos once it is confirmed active on each device, and Entra ID takes over MFA once seats are reconciled to headcount. Both retired lines end in the same billing period.

When does billing start?

When the last onboarding workstream closes. Every contracted service is verified as delivered before the first Guardian invoice.

If the SOC detects something, who cleans it up?

The SOC contains the immediate threat and TSR responds. Rebuilding machines, restoring data and forensics beyond that immediate response are time and materials under the TSR Services Guide.

Request a Guardian quote

User count, locations and whether you have IT staff today is enough for a first number. An engineer replies within one business day.

Prefer to talk? Call 262-292-2000.