Microsoft 365 Pulse Check

Copilot doesn’t create your data-leak problem. It indexes it.

Microsoft 365 Copilot answers from whatever the person asking can already open. The old company-wide HR folder, the Team set to Public on day one, the guest account nobody reviewed — none of that was hidden. It was just hard to find. Copilot makes it easy to find, in plain English.

Fixed fee, from $4,500 Read-only Two to three weeks You keep the report
The exposure

Three places a tenant usually leaks before anyone buys Copilot

These are how the products work, not a story about a client. The Pulse Check is built to look here first.

Overshared files

In the SharePoint admin center, Active sites sorted by Privacy. Every Public site can be read by everyone in the company, and so can Copilot when it is working for any of them.

Too many Global Admins

Microsoft’s guidance is fewer than five Global Administrators, and at least two so you cannot lock yourself out. Count active and eligible assignments. Former employees, old vendors, and migration accounts are still admins more often than people expect.

Guest access and quiet forwarding

Guest accounts that were never reviewed, and inbox rules that forward “invoice” or “wire” outside the firm. Resetting a password does not delete the rule. The rule keeps running.

How it works

A senior-led review. Read-only. Nothing changes in your tenant.

Jaras Funderburg, a senior Microsoft security lead with 20+ years in Microsoft infrastructure and security, leads every Pulse Check for Mindpod. The method is MITB (Minds In a Techs Box), Mindpod’s Microsoft tenant assessment framework: 12 dimensions, scored against written rules, not an AI guess.

Access is read-only, using Microsoft’s own admin and audit tooling. Every finding is scored against the 12 MITB dimensions and tied to evidence in your tenant. Every fix is mapped to a license you already own, wherever one exists. Nothing in your environment is changed. Your data stays yours and never becomes a marketing story. You keep the report.

What we check

Twelve areas, in plain English

The same 12 dimensions MITB scores. Named here the way a managing partner or an IT director would describe them.

Identity

Accounts one password away from a breach. MFA on privileged roles, legacy authentication, Conditional Access.

Devices

Laptops that are unpatched, unencrypted, or missing endpoint protection.

Data exposure

Files shared with everyone, anonymous links, and sensitivity labels that were never turned on. This is what Copilot will read.

Email

Forwarding rules, SPF, DKIM, DMARC, and whether anti-phishing policy is actually tuned.

Cloud apps

The AI and other apps already granted access to mail and files, named. App consent that does not require a review.

Defender

Whether Microsoft Defender is covering the devices you already pay for, and whether alerts are being worked.

Vulnerabilities

Known-exploited issues still sitting on the estate, and whether critical patches are inside your own SLA.

Backup and recovery

Whether Exchange, SharePoint, and OneDrive can actually be restored, and when that was last proven.

Endpoints

Intune enrollment, compliance policy, and whether an unmanaged device can still reach company apps.

Access

Global Admin count, guest sprawl, and access reviews that were scheduled and never run.

Compliance evidence

Audit-log retention and the artifacts a cyber-insurance questionnaire or an auditor will ask for.

Awareness

Whether people have been trained, and whether the acceptable-use policy was acknowledged or just filed.

What you get

A report you can act on without a new license

The deliverables

  • A written report that opens with a same-budget 30-day plan.
  • Named findings, each backed by evidence from your tenant.
  • Each finding tied to the control already in your Microsoft license, when one exists.
  • An inventory of AI apps with access to your data.
  • A readout call to walk through the order of work.
  • The report is yours whether or not we work together after.

Two to three weeks

  • A 30-minute call. Fit, scope, and what “read-only” will mean in your tenant.
  • Read-only access. Typically a Global Reader role, or the narrowest role that can see the evidence. We change nothing.
  • The review. A senior Microsoft security lead checks each finding against the evidence. The scoring framework is the checklist.
  • The readout. You get the report and the call. Then you decide what happens next.
Price

From $4,500. The workshop is optional.

Fixed fee. No hourly surprise at the end. A senior Microsoft security lead runs every review, from the first call to the readout.

The Pulse Check

From $4,500

Read-only tenant review

Twelve dimensions, the 30-day plan, the AI-app inventory, and the readout. Two to three weeks. You keep the report.

Optional add-on

$2,500

Leadership workshop

A working session to walk your team through the fixes. Not required to get the report.

If you sign a retainer within 30 days of the readout, the full fee is credited toward it. A retainer is ongoing monitoring plus a quarterly re-score, from $4,500 a month (see the retainer tiers). It is a separate decision. The Pulse Check stands on its own.

Who it’s for

50 to 500 seats, and the firms around them

Microsoft 365 firms

Law, healthcare, finance, and professional services, mostly on Microsoft 365. A managing partner, a firm administrator, a COO, or an IT director who is about to turn Copilot on, renew cyber insurance, or answer an audit finding. Built for that size of firm, including practices in Georgia. The review itself is remote.

Larger enterprises

A Copilot rollout stalling on oversharing, a board asking about AI risk, or a tenant merge. The practical first step is a Pulse Check scoped to one business unit or subsidiary. Not a software sale.

MSPs

You can white-label the Pulse Check under your own brand and resell it to the tenants you already manage. Wholesale or revenue-share terms are set with us on the call. There is no published partner rate on this page.

Who runs it

Jaras Funderburg

Founder of Mindpod Technologies. 20+ years in Microsoft infrastructure and security.

A senior Microsoft security lead runs each review. Jaras leads the Pulse Check for Mindpod, from the first call through the readout.

Mindpod Technologies is in Atlanta.

What this is not

Not a certification

Not a penetration test, not a compliance certification, and not a substitute for your auditor, your insurer, or your counsel. Findings are evidence from your tenant and a recommended order of work.

Not legal advice

ABA Formal Opinion 512, issued in July 2024, does not ban AI. It says the duties you already have still apply when you use generative AI: competence, confidentiality, supervision, and fees. This review is designed to support that work for a law firm. Your ethics counsel decides compliance.

FAQ

Before you send the form

What does read-only mean?

We look. We do not change the tenant. Access is a read-only role, for example Global Reader, or the narrowest role that can see the evidence we need. No remediation scripts, no policy edits, no mailbox changes.

What access do you need, and for how long?

After the 30-minute call, you grant read-only access for the review window, typically the two to three weeks of the engagement. You revoke it when the readout is done. You choose the account and the role.

What happens to our data?

The report is yours. We do not sell tenant data and we do not publish your findings. With your permission, lessons about the method can improve MITB. Your files are not the training set, and they are not a case study unless you later agree to one in writing.

How is MITB used in the review?

MITB is the method. Its 12 dimensions are the checklist, and each one is scored against written rules. A senior Microsoft security lead applies it to your tenant, with read-only access through Microsoft’s own admin and audit tooling, and checks every finding against the evidence before it goes in your report.

Will you tell us we are compliant?

No. We will tell you what the evidence shows and which control you may already own. Compliance, insurance, and ethics conclusions belong to your counsel, your auditor, and your carrier.

What if we do the review and do not hire you after?

You keep the report and the 30-day plan. The Pulse Check fee covers the review. A retainer, if you want one, is a separate signature. The credit of that fee applies only if that retainer is signed within 30 days of the readout.

Can our MSP resell this?

Yes. White-label means the review can go out under your brand. The commercial terms are a conversation with us, not a rate card on this page.

What if the form does not send?

The page confirms only after the message is accepted for delivery. If sending fails, it stays on the form and shows an error, with a link to email info@mindpodtech.com. You can also call 800-301-9873 or book the 30-minute call.

Request

Tell us what prompted it

The form emails info@mindpodtech.com. Reply-to is the work address you enter, so the answer comes back to you. You will see a confirmation only if the message was accepted. If it was not, the form stays here and the email link is the fallback.

Prefer to talk first? Pick a time on our calendar. The form is here if you would rather write.

Mindpod Technologies
8735 Dunwoody Place #5088
Atlanta, GA 30350
info@mindpodtech.com
800-301-9873

Required fields are marked. We use this only to reply about the Pulse Check. This form does not add you to a mailing list.