602-725-2818Licensed, insured & bondedSchedule a Consultation
Call 602-725-2818Consultation

Home / Managed IT / SaaS, Email & API

Section C · Services 08–10

Your data lives in systems you do not host.

Microsoft 365 and Google Workspace administration, SaaS and cloud posture management, mail platform and deliverability, and the discovery, governance and protection of the APIs quietly holding standing access to your data. Managed with the same rigour as the network itself.

Book a consultation →All managed IT services
Microsoft 365 · Google WorkspaceAzure · AWS · Google CloudSPF · DKIM · DMARCOWASP API Top 10

08 · SaaS & cloud management

Most organizations cannot list their own applications

The average business now runs dozens of cloud applications, a significant share of them adopted by a department without IT’s involvement. Each one holds company data, each one has its own permission model, and each one is a place a former employee may still have an account. Bringing them under management starts with finding them.

Tenant administration

Microsoft 365, Google Workspace and core SaaS administration — users, groups, policies and licensing, managed as configuration rather than as one-off changes.

SaaS discovery

Finding both sanctioned and shadow applications, including the AI tools that staff have adopted independently, with usage and spend visibility attached.

SaaS posture management

Continuous configuration checks against best-practice baselines, with drift alerts and remediation when a setting is changed and nobody records why.

Connected-app governance

Reviewing OAuth consents, third-party integrations, API tokens and risky permissions. This is the category most often missed entirely, and the one that survives a password reset.

Cloud posture management

Misconfiguration monitoring and remediation across Azure, AWS and Google Cloud — public storage, over-broad roles and unencrypted resources.

Backup & licensing

SaaS data backup and restore, unused licence reclamation and renewal management. Cloud platforms replicate your data; they do not protect you from deleting it.

The licence reclamation point is worth stating plainly because it is the one that pays for itself. On almost every assessment we find licences assigned to people who left, duplicate products covering the same function, and tiers purchased for a feature nobody ended up using. That is a recurring cost with no owner, and it is recoverable.

09 · Email & SMTP services

Email is still the front door

Email remains the most common initial access route into an organization, and it is simultaneously the system a business can least afford to have unavailable or untrusted. Managed mail covers three distinct jobs: running the platform, authenticating it so the rest of the world believes it, and responding when something gets through.

Mail platform & SMTP

  • Exchange Online and Google Workspace administration
  • Domain, DNS and MX record management
  • Mail flow rules, connectors and SMTP relay for applications and devices
  • Shared mailboxes, distribution lists and migrations
  • Deliverability and blocklist monitoring
  • Archiving, journaling, retention and legal hold

Protect & authenticate

  • SPF, DKIM and DMARC managed through to enforcement
  • Anti-phishing, anti-malware, sandboxing and link protection
  • Impersonation and business email compromise defence
  • Encryption and data loss prevention policies
  • Quarantine management and safe-sender policies
  • Phishing simulation and user training

Respond & recover

  • User-reported phishing triage
  • Malicious message search and purge across mailboxes
  • Account takeover response: session revoke, reset and rule cleanup
  • Mail flow outage troubleshooting
  • Message trace and header forensics
  • Spoofing and domain abuse takedown support

The authentication journey matters more than most organizations realize. Publishing SPF and DKIM records is the easy part; the work is moving DMARC from monitor-only through quarantine to enforcement without breaking legitimate mail sent by your own applications, invoicing systems and marketing platforms. Done in the wrong order — enforcement first, inventory second — it sends your own invoices to spam. Done properly, it stops other people sending mail as you.

Account takeover response belongs here rather than in a separate incident bucket, because the destructive part of a compromised mailbox is usually the inbox rule quietly forwarding finance correspondence to an external address. Revoking the session and resetting the password without removing that rule leaves the attacker’s access intact.

10 · API security & integrations

The connections nobody inventoried

APIs connect your applications, your partners and your data, and they are typically created by a project team, documented once, and then never reviewed. They hold standing credentials, they frequently bypass the controls applied to user traffic, and they rarely appear on a risk register. We treat them in four stages.

Pillar 1

Discover

  • Continuous API inventory
  • Shadow, zombie and deprecated API detection
  • Sensitive data flow mapping
  • Third-party and partner API catalog
  • Risk scoring of exposed endpoints
Pillar 2

Govern

  • Authentication and authorization review
  • Key, token and secret rotation
  • Least-privilege scopes and access policies
  • OpenAPI specification conformance
  • API gateway policy management
Pillar 3

Protect

  • Web application and API protection
  • Rate limiting and bot mitigation
  • Behavioural anomaly and abuse detection
  • Schema validation and threat blocking
  • Volumetric and DDoS abuse mitigation
Pillar 4

Test

  • OWASP API Security Top 10 assessments
  • Dynamic testing and fuzzing in the build pipeline
  • API penetration testing
  • Regression testing after each release
  • Remediation guidance written for developers

Ongoing integration operations cover availability, latency and error-rate monitoring, webhook and connector health, certificate and key expiry tracking, and emergency key revocation when a credential is exposed. Expired certificates and silently failing webhooks cause a surprising share of outages that get misdiagnosed as network problems.

API testing follows the OWASP API Security Top 10. Email authentication follows DMARC alongside SPF and DKIM.

Findings

What a tenant review usually turns up

These are the findings that recur across almost every Microsoft 365 or Google Workspace environment we assess. None of them are exotic, none require a sophisticated attacker, and all of them are configuration rather than software defects — which means they are fixable without buying anything.

Accounts that outlived their owners

Mailboxes, licences and SaaS logins still active for people who left. Often still forwarding, occasionally still being signed into. Offboarding is treated as an email to IT rather than an evidenced checklist, so the last step is the one that gets missed.

Legacy authentication still enabled

Older protocols that cannot present a second factor remain switched on for one application nobody wants to break, which quietly exempts the whole tenant from the multi-factor policy that is assumed to be universal.

Standing OAuth grants

Third-party applications holding broad, permanent permissions to read mail or files, approved once by a user during a trial years ago. A password reset does not revoke them; only an explicit consent review does.

Global administrator sprawl

More accounts with full tenant administration than the organization can justify, typically without separate privileged accounts and sometimes without multi-factor authentication on all of them.

Unrestricted external sharing

Files and sites shared through links that work for anyone who has the URL, created for a legitimate reason and never expired. The exposure is invisible until somebody audits it.

Mail rules nobody set

Inbox rules forwarding correspondence to external addresses, or moving messages from a finance domain straight to a deleted items folder. This is the signature of a compromise in progress and it is rarely looked for.

The reason these persist is not carelessness. Each was a reasonable decision at the moment it was made — keep the legacy protocol so the scanner keeps working, approve the integration so the project ships, share the link so the client can see the file. What is missing is the periodic review that asks whether the reason still applies. That review is the actual deliverable of posture management, and it is why it is continuous rather than annual. Findings are tracked through to closure with an owner and a date, and the exceptions list — the things you have decided to accept — is maintained deliberately rather than by default.

Questions we hear first

About SaaS, email and API management

Microsoft already backs up our data, doesn’t it?

Microsoft replicates your data for availability and protects the platform — that is not the same as protecting you from your own deletions, a retention policy that expired, a malicious insider or ransomware encrypting files that then sync to the cloud. Retention windows are finite and shorter than most organizations assume. Independent SaaS backup is covered under data protection and recovery.

Why does shadow SaaS matter if it works?

Because company data sits in it, it was never reviewed, it usually has no offboarding process, and it may hold an OAuth grant into your main tenant. The risk is rarely the application itself — it is the standing access it holds and the accounts that never get removed.

Will moving DMARC to enforcement break our email?

It can, if it is done before the inventory of legitimate senders is complete. That is exactly why it is staged: publish, monitor with reporting enabled, review what is failing and why, fix the legitimate senders, then tighten. Moving straight to enforcement is the common mistake and the one that sends your own order confirmations to spam.

We don’t build APIs. Does this still apply?

Usually yes. Most organizations consume far more APIs than they publish — every SaaS integration, payment connector, webhook and automation platform is one. The governance work applies to the tokens and consents those integrations hold, whether or not you wrote any of the code.

Can you take over an environment somebody else set up?

That is the normal case. Transition begins with discovery and a configuration review rather than with changes, because inheriting an environment means inheriting decisions whose reasons are not written down. We document what exists, flag what is risky, and agree a change sequence before touching anything in production.

Find out what is connected to your tenant

A SaaS and cloud posture assessment typically surfaces applications, OAuth grants and licences nobody currently owns. We start there, then propose a plan against the findings.

Book a consultation →