Baseline · Monitoring · Evidence

Microsoft 365security thatstays true

Waypoint sets your Microsoft 365 security baseline, checks the live tenant against it for drift, corrects what changes, and keeps current evidence of what is actually enforced.

Direct to law, accounting, healthcare and government-contracting firms. Or under your own brand, if you are an MSP.

For MSPs
Illustrative product view. Generic system states, not client data. Waypoint works under scoped, least-privilege access reviewed quarterly, with no standing Global Admin. Every action against your tenant is written to the Microsoft Unified Audit Log, and you can ask for that log at any time.
01
Detection
02
Decision
03
Remediation
04
Evidence
05
Accountability
Operated across Microsoft 365
Entra IDConditional AccessIntunePurviewDefender for Office 365Defender for EndpointExchange OnlineSharePointOneDriveTeams

WaypointX

Set it. Hold it. Prove it.

WaypointX is a defined Microsoft 365 configuration and the discipline that holds it in place, across identity, devices, data, and email and collaboration. It runs on the Microsoft capabilities in your existing licensing. No agent to roll out, and no second console for your team: the controls stay where your IT people already work.

Three levels. Each adds responsibility, not features. If your controls are already largely in place, WaypointX can start by changing nothing and only reporting where the tenant differs from the baseline.

01

Baseline

Set the configuration: risk-based conditional access, Intune compliance and encryption across Windows, macOS, iOS and Android, DLP, sharing controls and labels, mail protection. Built against CIS and NIST CSF, documented as issued.

02

Monitor

Hold it. Automated checks compare the live tenant against the baseline. What moved is restored, or logged as an exception with an owner and a review date. An engineer reviews and reports monthly.

03

Govern

Prove it, and own it. A named security executive holds the risk register, runs the program, faces auditors and insurers, and answers to your board.

WaypointX / Control Register
Illustrative product view
ControlStatusOwnerLast checkedEvidence
Conditional AccessControlledWaypointTodayAvailable
External SharingReviewClient + WaypointAug 29Open
MFA CoverageControlledWaypointTodayAvailable
Device ComplianceControlledWaypointTodayAvailable
Risk RegisterCurrentCISOAug 28Available
Demo state · generic system data · not client records
Owner and date on every row

A tenant does not hold still.

People join and leave. Devices enroll. Someone turns on sharing for one project and it stays on afterwards. Licensing changes and new controls arrive switched off. The industry calls this drift. What it means is that the configuration you signed off six months ago has quietly stopped being the one you are running.

Meanwhile the people asking about your security have stopped accepting a description. Insurers ask what you attested to. Clients send questionnaires before they sign. Auditors ask for the artifact. The question is what is switched on right now, and who says so.

An alert is not a control.

A dashboard is not a program.

A score is not an answer.

Watch
  1. 01Detect
  2. 02Notify
  3. 03Score
  4. 04Ticket
  5. 05Wait
Answer
  1. 01Decide
  2. 02Remediate
  3. 03Verify
  4. 04Document
  5. 05Own

Companies that watch.
Companies that answer.

Monitoring produces awareness. A program requires judgment, correction, verification, evidence and an owner. Waypoint is built to finish the sequence.

The Waypoint Operating Model

From signal to answer.

Microsoft 365 records what changed and who changed it. It will not tell you whether the change was a mistake, put it back, or capture why anyone chose to live with it. Waypoint operates that span.

000102 0304 05 Microsoft 365 Baseline Decision Remediation Evidence Accountability WAYPOINT OPERATES THIS SPAN DRIFT RETURNS TO DECISION
Microsoft 365 reports the change
WaypointX compares it to the baseline and routes it
A named person owns whatever stays open

Microsoft made the floor stronger. Good.

You have probably already bought most of this.

Business Premium and E3/E5 include identity, device, data and threat controls that were licensed and never fully switched on. Waypoint starts there rather than with another vendor, another agent and another console. Fewer moving parts, and a baseline that gets upgraded as your licensing changes instead of re-architected.

We ask clients to prove it. So we go first.

We ask clients to keep current proof of their own controls. It would be strange to ask that and not publish ours. Waypoint runs the same baseline on its own tenant, and posts the state of those controls rather than describing them.

It also lists what has not been earned. Waypoint holds no SOC 2 or ISO 27001 today; both are on the roadmap and will appear when they are real. Everything we do claim links to the issuing authority.

Same baseline. Same checks. Same standard we hold you to.

Waypoint Security Posture
Illustrative
Microsoft 365 ControlsCurrent
MonitoringActive
Control EvidenceAvailable
Operational StatusPublished live
CertificationsRoadmap published
Structure shown. Live values resolve from the Trust Center.
View current posture

One platform. Two commercial paths.

The product is the same in both. What changes is whose name is on the invoice and whose relationship the client belongs to.

For Organizations

Operate with evidence.

A client questionnaire is holding up a signature. An insurer wants to know what you attested to. An auditor wants the artifact, not the policy. Waypoint gets the tenant right, keeps it right, and keeps the proof current, so those requests stop being fire drills.

Typical fitRegulated SMB + mid-market
SectorsLegal · CPA · Health · GovCon
Starts withA read of your tenant
For MSPs

Extend the practice without building it.

Building this practice in-house means specialist hiring, engineering time, monitoring, reporting and permanent maintenance. WaypointX is the same operating model at wholesale, under your brand, standardized across every tenant you run. Waypoint operates the security layer. The client stays yours.

EconomicsWholesale per tenant
DeliveryYour brand, Waypoint operated
You keepThe client relationship

Some decisions should have a name attached to them.

WaypointX reports the technical state of a tenant. It cannot supply the judgment that state requires: which exceptions are acceptable and for how long, how risk gets described to a board, what an auditor is given, which vendor dependency is a real problem.

That is what the Govern tier buys. Not consulting hours. A named executive who owns the risk register, runs the program on a cadence, and sits opposite the auditor and the insurer.

Software can report risk. It cannot accept it.

Decision LogIllustrative
Accept residual risk · legacy shared mailboxCISORev 12 Sep
Exception granted · external sharing, one siteCISORev 30 Sep
Control tightened · admin center accessWaypointClosed
Escalated to board · vendor dependencyCISORev 04 Oct
Insurance attestation reviewed against tenantCISOAnnual

Structure shown. Entries are generic, not client records.

Published Pricing

Know the economics before the sales call.

Published so the economics are settled before anyone spends a meeting on them. Per Microsoft 365 tenant. Baseline is a one-time fee. Monitor and Govern are monthly.

01

WaypointX Baseline

$7,500
Per tenant / one time
For

The tenant configured correctly and documented as issued. A starting position, not a finished program: this level does not watch what happens next.

Includes · risk-based conditional access, Intune device compliance and encryption, DLP and sharing controls, mail protection, configuration record
02

WaypointX Monitor

Recommended operating tier
$1,500
Per tenant / month
For

Where the configuration has to stay correct after week one, and the proof has to be current whenever somebody asks for it.

Adds · continuous baseline checks, drift correction, exception log, monthly human review and report
03

WaypointX Govern

$2,250
Per tenant / month · Commercial
$5,000 / month · GCC High
For

Where somebody has to sign. A named executive answering to a board, an auditor, a regulator or a major client.

Adds · fractional CISO, risk register ownership, board briefings, audit and insurer liaison, escalation authority

These are direct rates. MSPs buy at wholesale through the partner program and set their own client pricing.

Waypoint Research

A security company should have a position.

Notes on where this market is wrong, and why controls fail in practice rather than in theory. Claims in these notes are cited to primary sources. Where a source could not be verified, the claim was cut rather than softened.

01

An alert is not a control.

The CategoryResearch note
02

CMMC's schedule moved. Your DFARS clauses did not.

Defense BaseResearch note
03

Your insurance application is a security control.

The UnderwriterResearch note
04

Your help desk is an authentication system.

Service DeskResearch note

We publish what we can defend.

Read Waypoint Research
Where the pressure comes from

The question is not whether you have a framework. It is whether you can produce the evidence.

Cyber Insurance
What did you attest to?
Application → tenant
Customer Diligence
Can you prove it now?
Questionnaire → evidence
CMMC / DFARS
What does the contract require?
Clause → control
Audit
Where is the evidence?
Request → artifact
Board
Who owns the decision?
Risk → name

Five parties, five different questions, one underlying requirement: show what is actually true, and show it now. Proof should not begin when the questionnaire arrives.

Start with the environment

See what your Microsoft tenant can prove.

An engineer reads the tenant before anyone sells you anything: where your controls stand against the baseline, which gaps matter first, where proof is missing, and what we would do in the first thirty days. If you are in reasonable shape, we will tell you that.

Read the tenant
Set it
Hold it
Prove it
Own it