SERVING BALTIMORE, MD ยท INNER HARBOR ยท FELLS POINT ยท CANTON ยท TOWSON ยท COLUMBIA

Microsoft 365 Support in Baltimore Licensed, Secured, and Actually Optimized.

Most businesses pay for Microsoft 365 twice โ€” once in licensing, again in features nobody configured. We manage, secure, and right-size 365 tenants for Baltimore businesses: identity, email security, Teams, SharePoint, and licensing.

15+
YEARS
1,000+
BUSINESSES
<30 min
RESPONSE
4.9★
GOOGLE
  • Microsoft-certified engineers, not generalists
  • Tenant security hardening & MFA rollout
  • Intune device management on every endpoint
  • Flat-rate support with a 30-minute SLA

Free · Takes 3 minutes · No sales call required

Start My Free Microsoft 365 Assessment

Response within 30 minutes, Mon-Fri. No sales pressure — ever.













What happens next: a Microsoft-certified engineer reviews your submission, emails you within 30 minutes, and schedules your 15-minute review at your convenience. Your information is never sold or shared.

Definition

What Are Managed Microsoft 365 Services?

Managed Microsoft 365 services is an ongoing program in which a Microsoft-certified provider — such as Capital Techies serving Baltimore and the greater Greater Baltimore region — deploys, secures, governs, and monitors a business’s Microsoft 365 environment for a fixed monthly fee. It is not a one-time setup. It is an operated service that keeps your M365 tenant configured correctly as Microsoft rolls out new features, threats evolve, and your organization changes.

What a complete M365 managed service includes: tenant migration and initial deployment, Entra ID identity configuration with MFA and Conditional Access, Microsoft Defender for Office 365 email security with anti-phishing and Safe Links, Intune device compliance enforcement, SharePoint and Teams governance policies, Microsoft Purview data loss prevention and sensitivity labels, third-party backup for Exchange, SharePoint, OneDrive, and Teams, ongoing Secure Score monitoring, and licensing management. For defense contractors, it includes the separate process of deploying and governing a GCC or GCC High tenant in place of commercial M365.

What managed M365 is not: it is not just keeping the lights on or resetting passwords. The Microsoft 365 platform has hundreds of configurable security and compliance settings. A default tenant out of the box has MFA turned off, SharePoint sharing set to allow anonymous links, Defender protections at minimum sensitivity, and no backup. Left unmanaged, that is exactly the configuration attackers target.

Who needs it: any Greater Baltimore organization running Microsoft 365 that does not have a dedicated Microsoft-certified engineer actively managing the tenant’s security configuration, monitoring Secure Score, and staying current with platform changes. For defense contractors, the need is even more specific: every organization handling CUI must be in GCC or GCC High, not a commercial tenant, regardless of how well that commercial tenant is otherwise configured.

Greater Baltimore context: Capital Techies delivers managed Microsoft 365 services across all Baltimore metro region of Greater Baltimore — Baltimore, Columbia, Ellicott City, Glen Burnie, Hunt Valley, Owings Mills, and Catonsville. The region’s business mix creates specific M365 requirements that a generic national provider cannot address: CMMC and GCC/GCC High for the defense contractor density around Johns Hopkins and Northrop Grumman supply chain; HIPAA-configured M365 for Johns Hopkins Hospital-affiliated practices and Peninsula health organizations; PCI-scoped SharePoint governance for Baltimore hospitality; and BEC-resistant Entra ID configurations for Columbia maritime law firms and professional services firms that move wire transfers daily.

Who We Serve

Greater Baltimore Industries With Specific Microsoft 365 Requirements

Microsoft 365 is not a single configuration problem. Each Greater Baltimore industry vertical has distinct M365 requirements driven by its compliance obligations, data types, and threat profile.

Defense / CMMC + GCC

Defense Contractors and DoD Subcontractors

Greater Baltimore has one of the densest concentrations of CMMC-obligated small businesses on the East Coast. Northrop Grumman and the federal contracting corridor — the sole designer and builder of U.S. Navy major federal programs and one of only two builders of nuclear-powered submarines — anchor a supply chain of hundreds of subcontractors, most handling CUI. All 10 of the top U.S. defense prime contractors have a presence in the region. Every firm in this supply chain that touches CUI must operate in Microsoft 365 GCC or GCC High — not commercial M365. The CMMC acquisition rule took effect November 10, 2025; Phase 2 beginning November 2026 requires C3PAO third-party certification for most CUI contracts. Capital Techies assesses GCC vs. GCC High need, manages the migration, and configures the CMMC security baseline for the Entra ID, Defender, Intune, and Purview workloads that map to the NSA at Fort Meade 800-171 controls.

Healthcare / HIPAA

Healthcare Organizations

Johns Hopkins Medicine — Maryland’s largest health system with roughly 35,000 employees and 12 hospitals — paid $2.175 million to HHS OCR in 2019 after underreporting a breach and lacking a Business Associate Agreement. That settlement established the enforcement posture OCR brings to Maryland health organizations. Microsoft 365 can be HIPAA-configured, but the BAA alone does not make an environment compliant. Capital Techies configures access controls, encryption, audit logging, SharePoint DLP policies, and email security for Greater Baltimore physician practices, clinics, behavioral health providers, and medical billing contractors — with audit-ready documentation for OCR’s active enforcement initiative targeting failure to conduct adequate risk analyses.

Hospitality / PCI DSS

Baltimore Hospitality and Tourism

Baltimore welcomed 14 million-plus visitors in 2024, generating $2.6 billion in direct visitor spending. Hotels, resorts, and restaurant groups across the oceanfront strip and the Inner Harbor operate Microsoft 365 environments alongside property management systems and payment processing infrastructure. SharePoint external sharing misconfiguration, guest account sprawl, and email-borne malware targeting front desk staff are the most common M365 risks in this vertical. Capital Techies locks down SharePoint sharing policies, enforces Intune device compliance on front-office workstations, configures Defender Safe Attachments and Safe Links, and maintains the documented M365 security posture that PCI DSS v4.0.1 assessors and cyber insurance underwriters require.

Professional Services / BEC

Law Firms and Professional Services

Columbia’s downtown and the Inner Harbor law firms, accounting practices, and maritime services companies process large wire transfers on predictable schedules — making them the highest-frequency business email compromise targets in the region. BEC ranked among the costliest crime categories in the FBI’s 2024 IC3 report, with $16.6 billion in total losses nationally. Capital Techies configures DMARC enforcement to prevent domain spoofing, deploys Defender for Office 365 anti-phishing policies tuned to impersonation attack patterns, enforces Conditional Access to lock M365 access to compliant devices, and maintains SharePoint permissions to prevent unauthorized client file access. ABA Formal Opinion 483 makes breach monitoring an ethical obligation for attorneys — M365 audit logging and anomaly alerting is part of that posture.

Port and Logistics

Port, Freight, and Supply Chain

The Baltimore-Washington technology corridor processed 3.5 million research programs in FY2024 and operates through a dense network of freight forwarders, customs brokers, logistics IT providers, and terminal operators. These businesses share documents, access partner portals, and exchange data across Microsoft 365 environments with varying levels of security maturity. Guest access sprawl, Teams external collaboration risks, and SharePoint integrations with port partner systems create data exposure vectors that standard M365 configurations leave unaddressed. Capital Techies governs external collaboration settings, enforces guest access review cycles, and ensures that supply chain document libraries are not accessible beyond their intended audience.

Financial Services

Financial Services and Insurance

Baltimore financial services firms — including the region’s major employers65 environments handling customer financial data under Gramm-Leach-Bliley Act obligations. Capital Techies configures Purview Data Loss Prevention policies to detect and block sharing of financial account data, enforces Conditional Access to restrict M365 access to managed devices, deploys Defender for Office 365 Plan 2 with automated investigation and response for faster threat containment, and maintains audit logging at the detail level that GLBA security program documentation requires.

What Is Actually Happening in Greater Baltimore

Four Ways an Unconfigured Microsoft 365 Tenant Puts Greater Baltimore Businesses at Risk

These are not hypotheticals. They are the attack patterns Capital Techies encounters inside Greater Baltimore M365 tenants — documented threat scenarios drawn from real breach patterns and compliance obligations active in the region right now.

The Account That Was Open for Months

A Baltimore professional services firm had multi-factor authentication configured as optional for users. A single employee’s credentials were harvested in a phishing campaign. The attacker logged into the firm’s Microsoft 365 tenant from overseas, set up mail-forwarding rules to monitor incoming wire transfer requests, and waited. By the time the fraud was discovered, three client payments had been redirected. Business email compromise was among the costliest crime categories in the FBI’s 2024 IC3 report, which logged $16.6 billion in total losses nationally across 859,532 complaints. Enforcing MFA across every M365 user account would have made those stolen credentials worthless.

Root cause: MFA not enforced. Fix: Entra ID Conditional Access with MFA required for all users. Time to implement with Capital Techies: under a week. Source: FBI IC3 2024 Annual Report (ic3.gov).

The CUI That Was Never Supposed to Be There

A Hunt Valley defense subcontractor supporting Northrop Grumman supply chain had been storing Controlled Unclassified Information in a standard commercial Microsoft 365 Business Standard tenant for three years. When a prime contractor asked for documentation of their GCC environment as part of a DFARS 252.204-7012 review, the subcontractor had none. Commercial M365 does not meet the FedRAMP Moderate standard required for CUI under DFARS. The firm faced a choice: spend months migrating to GCC under deadline pressure, or lose the contract. Under the CMMC acquisition rule effective November 10, 2025, this situation is no longer hypothetical — it is a compliance violation with False Claims Act exposure attached.

Root cause: wrong M365 environment for the data handled. Fix: GCC or GCC High tenant migration. Source: DFARS 252.204-7012; DoD CMMC Program Rule (32 CFR Part 170).

The SharePoint Link That Was Public

A Ellicott City medical billing contractor shared a SharePoint folder with a referring practice using Microsoft 365’s default sharing setting: “Anyone with the link.” The link was forwarded, the folder was indexed, and protected health information covering over 1,200 patients was accessible without authentication for six weeks before discovery. The default SharePoint sharing configuration in a new Microsoft 365 tenant allows anonymous link sharing. That default has caused HIPAA breaches at healthcare organizations across the country. HHS OCR’s enforcement initiative launched in October 2024 specifically targets inadequate risk analyses — sharing configuration is exactly the kind of technical control OCR looks for.

Root cause: SharePoint external sharing left at default “Anyone with the link” setting. Fix: tenant-level sharing policy lockdown plus DLP policies via Microsoft Purview. Source: HHS OCR; HIPAA Security Rule 45 CFR 164.312.

The Ransomware That Encrypted OneDrive

A Columbia law firm’s desktop was encrypted by ransomware deployed through a malicious email attachment. Because the firm’s desktops were syncing with OneDrive, the ransomware propagated the encryption to the cloud copies of every document the infected user had access to. The firm had no third-party Microsoft 365 backup. Microsoft’s built-in version history was partially helpful, but several document libraries exceeded the default retention window. Recovery took 11 days and required significant manual reconstruction of client files. Microsoft’s shared responsibility model does not cover ransomware-driven cloud file encryption. Ransomware appeared in 88% of SMB breaches per Verizon DBIR 2025.

Root cause: no independent M365 backup and default Defender configuration. Fix: third-party M365 backup plus Defender for Office 365 with Safe Attachments. Source: Verizon DBIR 2025; Microsoft shared responsibility documentation.

The Numbers

Microsoft 365 Security by the Numbers: What Greater Baltimore Businesses Face

Every figure below is attributable to a primary source. Use them to make the case for a proper M365 deployment — or to explain why the default configuration is not acceptable.

$10.22M
Average cost of a US data breach in 2025 — an all-time high for the US, up 9% year over year, and the highest in the world for the 15th consecutive year
Source: IBM Cost of a Data Breach Report 2025
$16.6B
Total cybercrime losses reported to the FBI in 2024 across 859,532 complaints — business email compromise through M365 accounts among the costliest categories
Source: FBI IC3 2024 Annual Report (ic3.gov)
88%
Share of SMB breaches involving ransomware per Verizon DBIR 2025 — cloud file sync means ransomware now reaches SharePoint and OneDrive, not just local drives
Source: Verizon Data Breach Investigations Report 2025
44%
Share of all breaches in which ransomware appeared in 2025 — up from 32% the prior year, now the most common action type across all breach categories
Source: Verizon Data Breach Investigations Report 2025
$1.53M
Average ransomware recovery cost in 2025, excluding any ransom payment — M365 backup is the single most effective control for reducing this number
Source: Sophos State of Ransomware 2025
GCC / GCC High
Required M365 environment for Greater Baltimore defense contractors handling CUI under DFARS 252.204-7012 — commercial M365 is not compliant, regardless of configuration
Source: DoD CMMC Program Rule (32 CFR Part 170); DFARS 252.204-7012

What We Do

Microsoft 365 Services for Greater Baltimore: What Each Workload Covers

Each service below addresses a specific gap in how most Greater Baltimore businesses are running Microsoft 365 today. Here is what each one does, what it prevents, and what happens to organizations that skip it.

Microsoft 365 Migration

M365 Migration and Tenant Deployment

Complete migration from Google Workspace, on-premises Exchange, hosted email, or another M365 tenant — including mailbox migration, calendar and contacts, SharePoint and Teams buildout, and DNS cutover. We stage data migration in the background and minimize cutover downtime to under an hour. Post-cutover, we configure the tenant’s security baseline before the first user logs in, so the environment is never running at default settings.

Covers: Exchange Online mailbox migration, SharePoint site and document library setup, Teams structure and governance, OneDrive configuration, DNS and MX record cutover, user onboarding.

Without it: migrations handled without a security-first configuration step deliver a tenant that is live, functional, and fully exposed — MFA off, sharing wide open, Defender at minimum sensitivity.

Microsoft Entra ID

Identity and Access Management (MFA + Conditional Access)

Entra ID (formerly Azure Active Directory) controls who can sign into your Microsoft 365 environment and from where. We enforce multi-factor authentication for every user, configure Conditional Access policies that block logins from unrecognized devices and high-risk sign-in locations, and apply Privileged Identity Management for administrator accounts. This is zero trust identity: no login is trusted by default. For defense contractors, Entra ID Conditional Access maps directly to the NSA at Fort Meade 800-171 access control requirements under CMMC Level 2.

Prevents: account takeover via stolen credentials, login from unauthorized devices, admin privilege abuse, credential stuffing attacks.

Without it: a phished or reused password opens your entire M365 environment — mail, files, Teams, and every connected application. Missing MFA documentation is the most common reason cyber insurance claims are denied.

Microsoft Defender for Office 365

Email Security and Anti-Phishing

Defender for Office 365 Plan 1 and Plan 2 deliver Safe Attachments (detonating suspicious files in a sandboxed environment before delivery), Safe Links (real-time URL scanning at click time), anti-phishing policies, and spoof intelligence. We configure DMARC, DKIM, and SPF records so attackers cannot impersonate your domain when emailing your clients. DMARC enforcement is a CMMC Level 2 requirement and a growing expectation from cyber insurance underwriters. For Greater Baltimore maritime law firms and professional services companies, domain spoofing prevention is a direct defense against the business email compromise that cost $16.6 billion in FBI-reported losses in 2024.

Prevents: phishing credential harvesting, malicious attachment delivery, domain spoofing for BEC, zero-day email exploits.

Without it: M365’s default anti-spam filtering blocks obvious junk but misses sophisticated phishing campaigns built specifically to impersonate known senders and evade signature-based filters.

Microsoft Intune

Device Management and Compliance Enforcement

Microsoft Intune enforces device compliance policies — encryption, screen lock, OS patch level, and approved application installation — before a device is allowed to connect to Microsoft 365. Conditional Access policies tied to Intune block non-compliant or unmanaged devices from accessing Exchange, SharePoint, and Teams. For healthcare organizations, device management is part of the HIPAA Security Rule’s workstation use and workstation security controls. For defense contractors, it supports the NSA at Fort Meade 800-171 control 3.1.18 (control the connection of mobile devices) under CMMC Level 2.

Prevents: unpatched device access, personal device data leakage, lost device exposure, non-compliant endpoint access to regulated data.

Without it: a personal phone running an outdated OS with no encryption and no remote-wipe capability has the same access to your Exchange mailbox and SharePoint files as a managed corporate laptop.

Microsoft Purview

Data Governance and Compliance (DLP, Sensitivity Labels, eDiscovery)

Microsoft Purview provides data loss prevention policies that detect and block sharing of regulated data — PHI patterns for HIPAA, CUI markers for defense contractors, PAN data for PCI scope. Sensitivity labels classify documents and enforce encryption and access restrictions throughout their lifecycle, whether the file is in SharePoint, emailed, or saved to a USB drive. eDiscovery and retention policies support litigation holds and regulatory record-keeping requirements. For defense contractors, Purview sensitivity labels configured to mark CUI documents support the NSA at Fort Meade 800-171 control 3.13.16 under CMMC Level 2.

Prevents: accidental PHI sharing via SharePoint, CUI exfiltration via email, litigation hold failures, uncontrolled document access by former employees.

Without it: any user can email a SharePoint folder containing patient records to a personal Gmail address, and the system will complete the action without warning or logging.

SharePoint and Teams Governance

SharePoint and Teams Governance

Left unmanaged, Microsoft 365 tenants accumulate hundreds of Teams channels, SharePoint sites, and guest accounts created ad hoc by users without guardrails. We implement governance policies: Teams creation controls, lifecycle management with automated expiration and review, guest access policies with regular review cycles, external sharing settings locked to the minimum necessary, and sensitivity labels applied to Teams and SharePoint sites to enforce data handling rules. For Baltimore hospitality businesses, SharePoint external sharing policies keep payment-adjacent document libraries out of reach of anonymous link sharing.

Prevents: data sprawl, orphaned guest access, accidental public document exposure, compliance scope creep from unmanaged Teams.

Without it: three years of ungoverned Teams growth leaves you with 200 channels, 40 guest users from vendors who left two years ago, and no visibility into which SharePoint sites are sharing what with whom.

Third-Party M365 Backup

Microsoft 365 Backup

Microsoft’s built-in retention covers platform failures but does not protect against ransomware-driven cloud file encryption, accidental deletion beyond the recycle bin window, or malicious insider deletion. We deploy independent, immutable third-party backup covering Exchange Online, SharePoint, OneDrive, and Teams — with configurable retention up to seven years for healthcare and legal compliance requirements. Recovery is granular: a single email, a document version, or an entire mailbox, restored in minutes from a clean, attacker-inaccessible copy. For Maryland-regulated healthcare providers, documented backup and recovery procedures are part of the HIPAA Security Rule’s contingency plan standard.

Prevents: permanent data loss from ransomware, accidental deletion beyond Microsoft’s retention window, insider threat data deletion, compliance retention failures.

Without it: Microsoft’s own service agreement recommends third-party backup. When ransomware encrypts OneDrive-synced files and version history is exhausted, the answer is “data is gone” — not “restored in an hour.”

Microsoft 365 GCC and GCC High

GCC and GCC High for Defense Contractors

Commercial Microsoft 365 plans do not meet DFARS 252.204-7012 requirements for Controlled Unclassified Information. GCC (FedRAMP Moderate authorized) is the minimum environment for most DoD CUI and satisfies DFARS baseline requirements. GCC High (FedRAMP High authorized) is required for ITAR-controlled technical data and certain sensitive CUI categories. We assess which environment your program data requires, manage GCC/GCC High tenant provisioning and eligibility documentation, migrate mailboxes and SharePoint content from your commercial tenant, configure the security baseline, and maintain the environment to CMMC Level 2 standards. Greater Baltimore defense contractors tied to the HII the federal contracting corridor supply chain, Johns Hopkins programs, and JBLE should assess GCC/GCC High need today — not when a prime contractor asks for proof.

Prevents: DFARS violation for CUI in a non-compliant environment, False Claims Act exposure, contract ineligibility.

Without it: storing CUI in a commercial M365 tenant is a DFARS violation regardless of how many other security controls are in place. The environment itself must be FedRAMP Moderate authorized at minimum.

Microsoft 365 Plan Comparison

Choosing the Right Microsoft 365 Plan for Your Greater Baltimore Business

The plan you are on determines which security tools you have access to. Most Greater Baltimore businesses are on a plan that is either under-equipped for their threat profile or their compliance obligations — and do not know it.

Plan Best For Security Features Included Compliance Fit Greater Baltimore Notes
Microsoft 365 Business Basic
~$6/user/mo
Organizations with very limited budgets needing email, Teams, and browser-based Office apps only — no desktop Office installed Exchange Online, Teams, SharePoint, OneDrive; no Defender add-on included; basic anti-spam only; no Intune; Entra ID Free tier only Minimum viable for small businesses with no regulated data; not suitable for HIPAA, CMMC, or PCI-scoped environments without significant add-ons Unsuitable for Greater Baltimore defense contractors (no GCC option), healthcare practices, or any organization processing regulated data without adding compliance tools separately. Most firms outgrow this immediately.
Microsoft 365 Business Standard
~$12.50/user/mo
Organizations needing full desktop Office apps, Teams, and SharePoint with moderate collaboration needs and no heavy compliance requirements Desktop Office apps, Exchange, Teams, SharePoint, OneDrive; basic Exchange Online Protection; no Defender for Office 365 Plan 1 included; no Intune; Entra ID Free tier Better for general business use but still lacks the security controls required by HIPAA, CMMC, PCI DSS v4.0.1, or cyber insurance underwriters without add-ons Common plan for Baltimore hospitality and professional services firms — and commonly the one that has MFA turned off and SharePoint sharing at default “anyone with a link.” A starting point, not a finished security posture.
Microsoft 365 Business Premium
~$26/user/mo
Recommended for most SMBs
Small and mid-sized businesses needing enterprise-grade security tools, device management, and identity protection without moving to E-series licensing Everything in Business Standard PLUS: Microsoft Defender for Business (EDR), Defender for Office 365 Plan 1 (Safe Attachments, Safe Links, anti-phishing), Microsoft Intune device management, Entra ID Plan 1 (Conditional Access, MFA enforcement, Privileged Identity Management), Azure Information Protection Plan 1, Microsoft Purview basic DLP Meets cyber insurance MFA and EDR requirements; supports HIPAA technical safeguards with proper configuration; supports most CMMC Level 1 and Level 2 security controls (in GCC for defense contractors) The right plan for most Greater Baltimore businesses with 10 to 300 users. The security tools included in this plan are frequently not configured — Capital Techies activates and governs them. For defense contractors, Business Premium is available in GCC but NOT GCC High.
Microsoft 365 E3
~$36/user/mo
Enterprise
Organizations with more than 300 users, complex compliance requirements, advanced eDiscovery needs, or requiring full Microsoft Purview compliance capabilities Full desktop apps, Exchange, Teams, SharePoint, OneDrive, Intune, Entra ID Plan 1, Windows E3 (OS deployment, BitLocker), advanced compliance tools including Purview eDiscovery, audit logs, retention policies, information barriers Strong compliance foundation for HIPAA, MODPA, and regulated data environments; Purview eDiscovery supports legal hold obligations for Greater Baltimore law firms; does not include Defender for Office 365 Plan 2 (requires add-on) Appropriate for Greater Baltimore mid-market organizations including healthcare groups, financial services firms, and larger professional services companies. Available in GCC and GCC High for defense contractors.
Microsoft 365 E5
~$57/user/mo
Enterprise Security
Organizations requiring the full Microsoft security stack: advanced threat protection, insider risk management, full Purview compliance suite, and Microsoft Sentinel SIEM integration Everything in E3 PLUS: Defender for Office 365 Plan 2 (automated investigation and response, threat explorer, attack simulation), Defender for Identity, Microsoft Sentinel integration-ready, Insider Risk Management, Communication Compliance, full Purview compliance suite, Entra ID Plan 2 (Identity Protection, Privileged Identity Management) The most complete compliance and security platform Microsoft offers; supports CMMC Level 2 and Level 3 control requirements, advanced HIPAA controls, PCI DSS scope management, and MODPA data governance; available in GCC High for the most sensitive defense programs Appropriate for Greater Baltimore organizations with the most demanding security and compliance requirements: prime defense contractors with multiple program types, large health systems, and organizations that have experienced incidents and are rebuilding their security posture. GCC High availability makes E5 the platform for ITAR-controlled environments.
Microsoft 365 GCC / GCC High
Pricing varies; requires eligibility
Defense Required
U.S. federal, state, and local government entities AND their contractors handling Controlled Unclassified Information under DFARS 252.204-7012 — required, not optional GCC: FedRAMP Moderate authorized; meets DFARS CUI baseline. GCC High: FedRAMP High authorized; meets ITAR/EAR and export-controlled CUI requirements. Data stored in U.S. data centers; GCC High staffed exclusively by screened U.S. citizens GCC: minimum required environment for DFARS 252.204-7012 CUI compliance; supports CMMC Level 2 with proper configuration. GCC High: required for ITAR-controlled technical data, certain SAP programs, and CUI categories above FedRAMP Moderate. Neither GCC nor GCC High = CMMC certification; they are the required platform, not the complete solution Every Greater Baltimore defense subcontractor handling CUI that is currently on a commercial M365 tenant is in a DFARS violation. The CMMC acquisition rule (effective November 10, 2025) and Phase 2 C3PAO certification requirements beginning November 2026 make this urgent. Capital Techies manages GCC and GCC High eligibility, tenant provisioning, mailbox migration, and CMMC security baseline configuration.

Free Microsoft 365 Assessment

Find Out Exactly Where Your M365 Tenant Is Exposed — In 15 Minutes

A Microsoft-certified engineer reviews your tenant’s security configuration against the attacks hitting Greater Baltimore businesses and the compliance requirements that apply to your industry. You get a written summary either way.

  • 15-minute call with a Microsoft-certified engineer, not a salesperson
  • Secure Score review and written gap summary for your tenant
  • GCC / GCC High assessment for defense contractors with CUI obligations
  • Compliance snapshot for CMMC, HIPAA, PCI DSS, or cyber insurance requirements
  • Licensing review — confirm you are on the right plan for your needs
  • Zero obligation. If you are well configured, we will tell you that too.

Start My Free Assessment

Client Feedback

What Our Clients Say

Real reviews from Capital Techies clients on Google.

FAQ

Microsoft 365 Baltimore and Greater Baltimore: Questions Business Owners Actually Ask

How much does Microsoft 365 cost for a business in Baltimore?
Microsoft 365 licensing for businesses ranges from $6 per user per month for Business Basic to $57 per user per month for E5, depending on the security features, compliance tools, and device management included. For most Baltimore small and mid-sized businesses, Business Premium at around $26 per user per month is the right starting point because it includes Microsoft Defender for Office 365, Intune device management, and Entra ID Conditional Access — the controls cyber insurers and compliance auditors now require. Defense contractors handling Controlled Unclassified Information cannot use commercial M365 plans at all and must instead deploy Microsoft 365 GCC or GCC High, which carry a separate pricing structure and eligibility process. Capital Techies helps Greater Baltimore businesses select the right plan, negotiate volume licensing, and avoid paying for features they will not use.
Does commercial Microsoft 365 meet CMMC or DFARS requirements for defense contractors?
No. Commercial Microsoft 365 plans — including Business Basic, Business Standard, Business Premium, E3, and E5 — do not meet the data residency and access control requirements of DFARS 252.204-7012 for Controlled Unclassified Information. DoD guidance requires that systems handling CUI be hosted in a FedRAMP Moderate-authorized environment at a minimum, which corresponds to Microsoft 365 GCC. For programs involving more sensitive CUI categories, GCC High (FedRAMP High authorized) is required. Storing CUI in a commercial M365 tenant is a DFARS violation that creates False Claims Act exposure. Greater Baltimore defense contractors tied to Northrop Grumman supply chain, Johns Hopkins programs, and other DoD contracts must assess which data they handle and migrate to the appropriate sovereign cloud environment. Capital Techies manages GCC and GCC High deployments and can guide contractors through the eligibility and migration process.
What is the difference between Microsoft 365 GCC and GCC High?
Microsoft 365 Government Community Cloud (GCC) is a FedRAMP Moderate-authorized environment designed for U.S. federal, state, and local government entities and their contractors. It meets the baseline requirements of DFARS 252.204-7012 for most Controlled Unclassified Information. GCC High is a FedRAMP High-authorized environment that additionally meets the requirements of International Traffic in Arms Regulations (ITAR) and Export Administration Regulations (EAR) — it is required for contractors handling export-controlled technical data, certain Special Access Programs, or CUI categories that exceed the FedRAMP Moderate baseline. GCC High data is isolated to U.S. data centers staffed entirely by screened U.S. citizens. Most Greater Baltimore defense subcontractors handling standard CUI under the NSA at Fort Meade 800-171 will qualify for GCC; those supporting ITAR-controlled programs or certain intelligence community contracts typically need GCC High. Getting the classification wrong in either direction creates compliance risk — Capital Techies assesses your program data and recommends the correct environment before migration begins.
Is Microsoft 365 backed up?
Not by default in a way that protects your business from data loss. Microsoft’s shared responsibility model covers platform uptime and infrastructure, but it does not protect against accidental deletion, ransomware encryption of cloud files via OneDrive sync, malicious insider deletion, or retention policy misconfiguration that permanently removes email. Items deleted from Exchange Online, SharePoint, and OneDrive can be recovered within limited retention windows — typically 30 to 93 days depending on configuration — but after that, the data is gone. Ransomware that encrypts SharePoint and OneDrive content via synced drives is a documented attack vector. Capital Techies deploys third-party Microsoft 365 backup solutions that create independent, immutable copies of Exchange, SharePoint, OneDrive, and Teams data — so recovery after an incident is measured in hours, not in “it is gone.” For Greater Baltimore healthcare organizations, documented backup procedures are part of the HIPAA Security Rule contingency plan standard.
What is Microsoft Entra ID and why does my Greater Baltimore business need it?
Microsoft Entra ID (formerly Azure Active Directory) is the identity and access management platform that controls who can sign into your Microsoft 365 environment and from where. Without a properly configured Entra ID deployment, your users can sign in from any device in any country with just a username and password — a stolen credential opens the door completely. Entra ID enables multi-factor authentication, Conditional Access policies that block logins from unrecognized devices or high-risk sign-in locations, and Privileged Identity Management for administrator accounts. For Greater Baltimore defense contractors, Entra ID Conditional Access is mapped to multiple the NSA at Fort Meade 800-171 access control requirements under CMMC Level 2. For healthcare organizations, it supports the HIPAA technical safeguard for access controls. For any business, it is the single most effective control for preventing account takeover — and missing MFA documentation is the most common reason cyber insurance claims are denied.
What Microsoft 365 security features should my Baltimore business actually be using?
The gap between what most Greater Baltimore businesses have deployed and what Microsoft 365 includes in their existing license is significant. At minimum, every business should have multi-factor authentication enforced for all users (not just admins), Conditional Access policies restricting login to compliant devices, Microsoft Defender for Office 365 with anti-phishing and Safe Links policies active, and SharePoint external sharing locked down from the default of “anyone with a link.” Business Premium subscribers also have Intune for device compliance enforcement and Microsoft Defender for Business for endpoint detection and response — both frequently left unconfigured. Capital Techies conducts a Microsoft 365 Secure Score review for every new Greater Baltimore client and closes the gap between what the tenant has paid for and what it actually has running.
How long does a Microsoft 365 migration take for a Greater Baltimore business?
A straightforward Microsoft 365 migration for a business of 25 to 100 users — moving from Google Workspace, a local Exchange server, or another email host — typically takes two to four weeks from kickoff to cutover, including mailbox migration, DNS reconfiguration, Teams and SharePoint setup, and user onboarding. More complex migrations involving a GCC or GCC High tenant, hybrid Exchange environments, or large SharePoint document library migrations can extend to six to twelve weeks. The cutover itself, if planned correctly, takes less than an hour of user-visible downtime. Capital Techies handles migrations across all seven Greater Baltimore cities with minimal business disruption: we stage data migration in the background, do a final sync close to cutover, and provide same-day support on the day users switch over.
Does Microsoft 365 Business Premium meet HIPAA requirements for Greater Baltimore healthcare practices?
Microsoft 365 Business Premium can be configured to support HIPAA compliance, but the licensing alone does not make an environment HIPAA-compliant. Microsoft signs a Business Associate Agreement for eligible Microsoft 365 plans, which is a required element of HIPAA compliance. Beyond the BAA, the environment must be properly configured: access controls and MFA must be enforced, audit logging must be enabled, email encryption must be active for PHI transmissions, and Data Loss Prevention policies in Microsoft Purview must be configured to detect and block unintended PHI sharing. HHS OCR’s active enforcement initiative launched in October 2024 specifically targets failure to conduct adequate risk analyses — which means having M365 running is not enough; you need documented evidence that the security configuration meets the HIPAA Security Rule. Capital Techies configures and documents M365 HIPAA safeguards for Greater Baltimore physician practices, Johns Hopkins Hospital-affiliated providers, and independent clinics across the Peninsula and the Baltimore metro region.
What is Microsoft Purview and do Greater Baltimore businesses need it?
Microsoft Purview is the compliance and data governance platform built into Microsoft 365, covering Data Loss Prevention, sensitivity labels, eDiscovery, audit logs, retention policies, and information barriers. For Greater Baltimore defense contractors, Purview sensitivity labels can be configured to mark and protect CUI-tagged documents throughout their lifecycle — a CMMC Level 2 requirement. For healthcare organizations, Purview Data Loss Prevention policies can detect and block email or SharePoint sharing of content that matches PHI patterns. For professional services firms subject to litigation holds, Purview eDiscovery and retention policies satisfy legal hold obligations. Business Premium includes a subset of Purview; full capabilities require E3 or E5 licensing or add-on compliance plans. Capital Techies assesses which Purview features are required for your compliance obligations and configures them correctly from day one.
Why is Microsoft 365 the number one breach entry point and what can Greater Baltimore businesses do about it?
Microsoft 365 is the world’s most widely used productivity platform and therefore the most heavily targeted by attackers. Business email compromise — where attackers gain access to a Microsoft 365 mailbox and monitor it for wire transfer opportunities or impersonate the account to redirect payments — was among the costliest crime categories in the FBI’s 2024 IC3 report, which logged $16.6 billion in total losses nationally. Ransomware appeared in 44% of all breaches and 88% of SMB breaches per Verizon’s 2025 DBIR. The most common M365 attack vectors are credential phishing, password spraying against accounts without MFA, and abusing default SharePoint sharing settings to exfiltrate data. The fix is not switching platforms — it is locking down the one you have. Enforcing MFA, deploying Conditional Access, enabling Defender for Office 365 anti-phishing, and restricting external sharing closes the most common entry points. Capital Techies performs M365 security hardening assessments for Baltimore and Greater Baltimore businesses and closes these gaps in days, not months.

How Exposed Is Your Business Right Now?

Get your free Cyber Risk Score in under 3 minutes. We check for exposed credentials, email spoofing gaps, dark web leaks, and unpatched systems. You get a letter grade and a plain-English report. No sales call required.

Get Your Free Cyber Risk Score →

Free · Takes 3 minutes · No sales call required