0%

Preparing the page

Managed vs In-House Microsoft 365 Security: How to Choose the Right Model

Should you run Microsoft 365 security in-house or use a managed service? Compare cost, coverage, skills and control, plus a hybrid model that avoids lock-in.

Joseph

Joseph · Cloud Consulting

· 4 min read

Share
Placeholder illustration

You have deployed Entra ID, Intune, Defender XDR and Purview. Now someone has to run it: watch alerts at 2 a.m., patch devices, review access, tune policies and respond to incidents. Should that be your team or a partner?

This guide compares managed Microsoft 365 security with in-house operations honestly, including when each makes sense.

What does operating Microsoft 365 security involve?

  • Monitoring and response: triaging Defender XDR incidents and alerts 24/7
  • Device operations: patching, compliance remediation, app updates
  • Identity operations: access reviews, privileged role management, guest clean-up
  • Policy tuning: Conditional Access, DLP, attack surface reduction
  • Reporting: health, posture, compliance evidence for audits
  • Change management: keeping up with Microsoft's frequent feature changes

Managed vs in-house: comparison

FactorIn-houseManaged service
24/7 coverageNeeds a rotation of several trained staffIncluded, SLA-backed
Time to capabilityMonths to hire and trainWeeks
Expertise breadthLimited to team's experienceBroad, across many tenants
Business contextDeepMust be built through onboarding
ControlFullShared, defined by contract
Cost profileSalaries, training, tools, attrition riskPredictable monthly fee
RiskKey-person dependencyVendor lock-in, if poorly structured

When does in-house make sense?

  • You already have a security team that can staff 24/7 coverage
  • You operate in a highly specialised environment requiring deep internal context
  • Regulations or policy require internal staff for certain functions
  • Security operations is a strategic capability you want to build

When does a managed service make sense?

  • You cannot staff a 24/7 rotation
  • Your IT team is stretched across many responsibilities
  • You need capability quickly, for example after an incident or audit finding
  • You want predictable costs and SLA-backed response

What about a hybrid model?

Many organisations choose a hybrid: a managed provider handles 24/7 monitoring, patching and first response, while an internal team owns strategy, business context and decisions. This keeps control internal while removing the hardest operational burden.

Hybrid responsibility split
This keeps control internal while removing the hardest operational burden.

How do you avoid vendor lock-in with a managed provider?

Ask these questions before signing:

  1. Do we keep full ownership of our tenant and licences?
  2. Are all runbooks, configurations and documentation ours?
  3. Can we move to self-run, and what does the handover include?
  4. What are the response and resolution SLAs?
  5. What reports do we receive, and how often?
  6. How are changes approved?

How Crozaint approaches this decision

Crozaint lets you choose after the assessment, not before. Our engagement starts with a 2–4 week assessment and a 4–12 week deployment. Then you pick:

  • Crozaint Managed: 24/7 SOC operations, automated patching, SLA-backed support and monthly health reports
  • Your Team Operated: full handover of runbooks, playbooks, documentation and staff training

Both models are reversible. You keep ownership of your tenant and licences either way. Lock-in, ownership and reversibility are among the first questions clients ask, and we answer them in writing.

Common mistakes to avoid

  • Assuming one security engineer equals 24/7 coverage
  • Signing a managed contract without clear ownership terms
  • Outsourcing operations but not decision-making clarity
  • No reporting cadence or SLA metrics
  • Ignoring the cost of attrition in an in-house team

Conclusion

The right model depends on whether you can staff 24/7 and how fast you need capability. Whatever you choose, keep ownership, documentation and the option to change your mind.

Weighing managed vs in-house? Book a 30-minute discovery call with Crozaint.

Frequently Asked Questions

What is managed Microsoft 365 security?

Managed Microsoft 365 security is a service where a partner operates your Microsoft 365 security stack, including monitoring Defender alerts, responding to incidents, patching devices, reviewing access and tuning policies, under defined SLAs. Your organisation retains ownership of the tenant and makes key decisions.

How many people does 24/7 security monitoring need?

Covering 24 hours a day, seven days a week with one person on shift at all times typically requires at least five to six trained staff once leave, training and attrition are considered. That is why many organisations use a managed service or a hybrid model.

Will we lose control of our tenant with a managed service?

You should not. A well-structured managed service leaves tenant ownership, licences, configurations and documentation with you, with changes approved through agreed processes. Confirm these terms in the contract, along with a clear exit and handover process.

Can we switch from managed to in-house later?

Yes, if the provider supports it. Look for full documentation, runbooks and training as part of the handover. Crozaint's managed and self-run models are both reversible, so you can start managed and move in-house later, or the reverse.

What is a managed SOC?

A managed SOC, security operations centre, is an outsourced team that monitors security alerts, investigates incidents and coordinates response around the clock. For Microsoft 365, a managed SOC typically works within Defender XDR and Microsoft Sentinel on behalf of the client.

Joseph

Written by

Joseph

Cloud Consulting · 15 articles

Joseph has spent fifteen years at the operating end of infrastructure — from data-centre and network operations to multi-cloud consulting across AWS, Azure and GCP. He turns unreadable cloud bills into decisions teams can act on, and he knows the automation underneath them — Terraform, Ansible, Kubernetes — well enough to make the savings stick.

Nidhish JoyReviewed for technical accuracy by Nidhish Joy, Co-founder & CEO.

After the reading

Reading About Digital Workplace & Security Is the Easy Part.Doing It in Your Estate Is Ours.

Thirty minutes with the people who wrote this. We look at your setup, say what we would fix first and leave you with a plan, whether or not you go further with us.

  • A look at your estate, not a demo
  • What we would fix first, and why
  • A plan you keep, whether or not you hire us
Joseph

Talk to Joseph

Wrote this article · Cloud Consulting

Thirty minutes on your estate. Joseph looks at what you have and tells you what we would do first.

Book 30 Minutes

No deck, no pitch, no commitment.