Independent M365 Health Check · Fixed price · Done in a week

Your Microsoft 365 bill probably contains waste. And your security has gaps that do not show from the outside.

If licenses have been bought over the years and the environment has been maintained by several hands, wasted spend and security gaps are found practically always. A free 30-minute call tells you whether that is true for you too. After that, the Health Check shows in one week what you pay for unnecessarily and what needs fixing first.

Fixed priceDone within a week of granting accessUsefulness guarantee
Target audience

Who this is for

The Health Check suits organizations of 10–500 people that use Microsoft 365. My contact is usually the person responsible for IT and its costs, for example the head of IT, the CFO or the CEO.

Do you recognize any of these:

  • The Microsoft bill is one of the largest IT costs, but nobody can say in five minutes how many E3, Business Premium and Basic licenses are in use and why.
  • The license bill went up with Microsoft's July 2026 price increase, and nobody checked usage at the same time.
  • MFA is on and Secure Score shows green, but nobody has gone through the whole environment systematically.
  • The IT partner bills monthly, but you do not know what is concretely being done about security.
  • A major customer, an insurer or the board has started asking about your security posture (NIS2), and you do not have a fact-based answer.

Not suitable for organizations with fewer than 10 users or for the public sector.

Start here

Let's find out in 30 minutes whether the review is worth doing

Fill in your details and you can book a time directly from my calendar, or I will call you. In the discovery call we go through the size of your environment, the licensing situation and what the review covers for an organization your size. The call is free and there is no commitment.

Your details go only to me. No newsletter, no resellers.

Results

What the review typically finds

Professional organization with several hundred users: 15,000 € saved per month

Every user had the same license tier regardless of what they used. People on long parental leave, field workers and shared mailboxes cost the same as the CFO. When licenses were matched to actual use, the bill dropped by 15,000 € per month. The work started with a fifteen-minute phone call.

I do not promise the same amount to anyone. Typically a mixed-license environment contains 10–30 % over-licensing. The saving is always calculated the same way: look at what each user actually uses and compare it with what their license is paying for.

Group of over 500 people with its own IT department: multi-factor authentication was "on"

MFA was in use and trusted. The review showed that less than half of sign-ins passed through the policy that actually requires it. Access control consisted of dozens of individual rules added over the years, whose combined effect nobody had checked. Several admin-level accounts had no MFA at all, there were around ten permanent global admins, and several partners had delegated admin rights to the environment.

None of this showed from the outside, and not a single finding required new licenses. Everything was fixable with the existing ones.

28Microsoft certifications
25+years in ICT
100+M365 environments reviewed
Discovery call

Even the discovery call gives you something

Before the call I check your domain's email protection from public records and tell you the result in the call. It is the same check a phisher starts with. We also go through what the review covers for an organization your size and what it does not. If the review is not sensible for you, I will say so.

What the review is based on

Three things that are in order after the review

1. Licensing matched to use

Each user's actual usage (sign-ins, email, Teams, Office apps, storage) tells which license tier is enough for them. You see duplicate licenses, unused licenses, users on the wrong tier and whether licenses have been bought sensibly: annual commitment with annual billing or monthly pricing by credit card. The result is a savings estimate in euros and a license map you can take to the CFO.

2. A patched security baseline

The whole environment is reviewed: identity (Entra ID, MFA, Conditional Access, admins), devices (Intune, Defender), data (SharePoint, OneDrive, sharing), email (protection and filtering) and applications (third-party permissions). Hundreds of checks against a CIS and Zero Trust baseline. Most findings are fixable with the licenses you already have.

3. A remediation path management understands

The report is not a hundred pages of tool output. Every finding is numbered, prioritized (critical, high, medium) and comes with a concrete fix, a recommended order and a size estimate of the work. The first page is a summary you can show to the CEO, the board or the insurer as it is. We go through the report together in a 60-minute debrief. The fixes can be done by your own IT, your current partner or me.

When these three are in place, you only pay for licenses that are used, you know where the gaps are and you have the list to fix them. In most cases the license savings fund the fixes.

How it goes

Four steps, one week

  1. Discovery call, 30 min.

    We agree the scope and go through what you expect from the review.

  2. Access, about 15 min of your time.

    We agree the method: either you register the review apps yourself following my instructions and grant them limited read permissions, or you give me a temporary admin role for the duration of the review. Neither changes a single setting, and I do not see the content of emails or files. Everything is removed after the review.

  3. Review, one week.

    Automated checks, my own scripts and a specialist's eye. Users notice nothing.

  4. Report and debrief, 60 min.

    We go through the findings and agree what to do first.

Price

Fixed price, usefulness guarantee

Fixed price

No hourly billing, no surprises, no ongoing commitment. The price is agreed in the discovery call once the size and scope of the environment are known.

Usefulness guarantee

You decide whether the report was useful. If you do not feel you got value from it, you pay nothing. The only thing I ask in return is a 20-minute conversation about what did not work.

Who does the review
Jami Susijärvi

Jami Susijärvi

Oy Wolflake Consulting Ab, Tampere, Finland. 25 years in ICT, 28 Microsoft certifications (including SC-100, MS-102, AZ-305), Microsoft Certified Trainer. Independent: I have no reason to recommend anything you do not need.

Frequently asked

Questions and answers

We already have an IT partner. Is this duplicate work?

No. Your partner runs the environment, I review it. Even a good partner has a blind spot for its own work, and few will bill you for finding savings in their own invoice. The report gives you both a shared, prioritized list.

Is someone going to criticize my work?

The review assesses the environment, not people. Almost every M365 environment has been built over the years by several hands, and the findings are similar almost everywhere. The report is written so that you can take it to management as your own achievement.

Is 15,000 € per month too good to be true?

It is one client's result, not a promise. The mechanism is simple: look at what each user actually uses and compare it with what their license is paying for. For you the number may be a hundred euros or ten thousand, or licensing may already be in order. The review tells you your number; security findings, on the other hand, are found practically always.

What permissions do you need?

Limited read permissions, which we go through in the discovery call. I do not change settings and I do not see the content of emails or files. Permissions and temporary review apps are removed immediately after the review.

Does the review disrupt work?

No. Users notice nothing. From you it takes about 15 minutes to grant permissions and an hour for the debrief.

What does the review cost?

A fixed price, no hourly billing and no ongoing commitment. I tell you the price in the discovery call once the size and scope of the environment are known. The cheapest reviews on the market are automated click tests without context; this is a specialist-led review with hundreds of checks, a license analysis in euros and a prioritized remediation path. In most cases the license savings cover the price many times over in the first year.

What happens after the review?

You decide. You can fix the findings yourself, with your partner or with me. If you want help with remediation or ongoing monitoring, that can be agreed separately. It is not a condition.

Next step

How to get started

  1. Fill in the form.

    Under a minute.

  2. Book the discovery call.

    You immediately get the option to book a time from my calendar. If no suitable time is available, I will call you on the next business day. Before the call I check your domain's email protection.

  3. Decide for yourself.

    After the discovery call you decide whether to proceed.

No commitment, no payment. In the worst case you spent 30 minutes and got an independent assessment of your environment.