Services — Fixed Scope
Microsoft 365
security assessment.
A three-week, evidence-based review of your Microsoft 365 tenant against recognised secure configuration baselines — delivered with a remediation plan your team can actually execute.
Why this assessment
Most tenants are not breached through a zero-day.
They are breached through configuration: a conditional access policy with an exclusion nobody reviewed, external sharing left at its default, a privileged account without phishing-resistant MFA, or audit logging that expired before the investigation started.
Microsoft 365 concentrates identity, email, files and collaboration into a single tenant. That makes it the highest-value control plane most organisations own — and the one most likely to have drifted since the last person configured it.
We assess the tenant as it is today, compare it to published baselines, and give you a prioritised path forward with the trade-offs stated plainly.
Engagement at a glance
- Duration
- 3 weeks, fixed scope
- Access required
- Read-only tenant and audit access
- Baselines used
- CISA SCuBA, CIS M365 Benchmark, Microsoft guidance
- Deliverables
- Findings register, remediation plan, executive readout
- Follow-on
- Optional remediation support or quarterly drift review
Scope
What we examine.
Six configuration domains, each assessed against published baselines and against how your organisation actually works.
Identity and access
Entra ID configuration review: conditional access coverage, MFA and phishing-resistant methods, legacy authentication, privileged roles, PIM, guest and app consent settings.
Exchange Online and email flow
Anti-phishing, anti-spoofing and Safe Links/Safe Attachments policy coverage, SPF, DKIM and DMARC alignment, external forwarding, transport rules and mailbox auditing.
SharePoint, OneDrive and Teams
External sharing posture, anonymous link defaults, sensitivity labels, retention, guest access in Teams, and where business data is actually leaving the tenant.
Detection and response readiness
Unified audit log and Defender alert coverage, log retention against your investigation window, and whether owners exist for the alerts your tenant already generates.
Device and endpoint policy
Intune compliance and configuration policy review, device-based conditional access, and the gap between managed, registered and unmanaged access paths.
Baseline conformance
Each finding mapped to CISA SCuBA secure configuration baselines, Microsoft's own security defaults guidance and the CIS Microsoft 365 Benchmark, so decisions are defensible.
Process
Three weeks, start to readout.
Week 1
Tenant read and evidence capture
Read-only access to configuration, policy and audit surfaces. We collect current-state evidence rather than relying on a questionnaire, and confirm which business processes depend on each setting.
Week 2
Baseline comparison and risk framing
Configuration compared against SCuBA and CIS baselines, then triaged by exploitability and business impact — not by the size of the raw finding count.
Week 3
Remediation plan and executive readout
A sequenced plan separating same-week changes from work needing change control, plus a board-level summary of residual risk and the drift controls that keep the tenant from sliding back.
Reference baselines
Standards we assess against.
Public, verifiable baselines — so findings can be reviewed independently by your team, your auditor or your insurer.
Related reading
Microsoft 365 hardening controls that hold
Our briefing on identity-first hardening and drift management across the Microsoft cloud estate.
Read the briefing →All services →Book Assessment
Navigate Risk. Build Confidence.
A focused executive session to establish where you stand across AI, cyber and business risk.
