Password and access resets
Routine account unlocks, password resets, and permission requests belong with regular support, not a scoped review.
Independent IT security review
Day-to-day IT support and an independent configuration review answer different questions with different evidence. Buying the wrong one wastes the budget and leaves the real question unanswered.
Day-to-day IT support exists to keep people working: a locked-out account, a printer that will not connect, a laptop that needs rebuilding. It is judged by how fast the ticket closes.
Routine account unlocks, password resets, and permission requests belong with regular support, not a scoped review.
Device setup, network drops, and application errors are day-to-day support work with its own queue and priorities.
Support is judged by response time and ticket closure, not by the depth of reasoning behind a configuration decision.
An independent review exists to answer a defined question with evidence: does current configuration match intent, and where does it not. It is judged by whether the decision record holds up.
The engagement starts from a specific decision-an inherited tenant, a rollout, a finding backlog-not a general health check.
Observations are tied to policy definitions, role assignments, and business context instead of a ticket count.
The deliverable is a set of findings, options, and owners a decision-maker can act on, not a closed ticket.
Treating support like assurance-or a review like a support contract-creates the wrong expectations on both sides.
It does not carry a support queue, reset passwords, or provide same-day technical assistance for unrelated issues.
A help desk ticket does not produce an independent decision record, and closing it does not confirm a control now behaves as intended.
A review can surface support-process gaps-like a joiner-mover-leaver breakdown-that the help desk then has to live with day to day.
The right service depends on what needs to be true afterward, not on which provider is already on retainer.
A closed ticket satisfies a user. A decision record with rationale satisfies a leadership question.
Support ownership usually sits with whoever holds the contract. Review ownership should sit with a named, accountable reviewer.
A ticket ends when the symptom stops. A review ends with a decision record and, if authorized, a separate remediation plan.
Next step
Start with the trigger, decision, and known boundaries. Do not send passwords, recovery codes, or tenant exports.