Services — Fixed Scope

Microsoft 365
security assessment.

A three-week, evidence-based review of your Microsoft 365 tenant against recognised secure configuration baselines — delivered with a remediation plan your team can actually execute.

Why this assessment

Most tenants are not breached through a zero-day.

They are breached through configuration: a conditional access policy with an exclusion nobody reviewed, external sharing left at its default, a privileged account without phishing-resistant MFA, or audit logging that expired before the investigation started.

Microsoft 365 concentrates identity, email, files and collaboration into a single tenant. That makes it the highest-value control plane most organisations own — and the one most likely to have drifted since the last person configured it.

We assess the tenant as it is today, compare it to published baselines, and give you a prioritised path forward with the trade-offs stated plainly.

Engagement at a glance

Duration
3 weeks, fixed scope
Access required
Read-only tenant and audit access
Baselines used
CISA SCuBA, CIS M365 Benchmark, Microsoft guidance
Deliverables
Findings register, remediation plan, executive readout
Follow-on
Optional remediation support or quarterly drift review

Scope

What we examine.

Six configuration domains, each assessed against published baselines and against how your organisation actually works.

Identity and access

Entra ID configuration review: conditional access coverage, MFA and phishing-resistant methods, legacy authentication, privileged roles, PIM, guest and app consent settings.

Exchange Online and email flow

Anti-phishing, anti-spoofing and Safe Links/Safe Attachments policy coverage, SPF, DKIM and DMARC alignment, external forwarding, transport rules and mailbox auditing.

SharePoint, OneDrive and Teams

External sharing posture, anonymous link defaults, sensitivity labels, retention, guest access in Teams, and where business data is actually leaving the tenant.

Detection and response readiness

Unified audit log and Defender alert coverage, log retention against your investigation window, and whether owners exist for the alerts your tenant already generates.

Device and endpoint policy

Intune compliance and configuration policy review, device-based conditional access, and the gap between managed, registered and unmanaged access paths.

Baseline conformance

Each finding mapped to CISA SCuBA secure configuration baselines, Microsoft's own security defaults guidance and the CIS Microsoft 365 Benchmark, so decisions are defensible.

Process

Three weeks, start to readout.

Week 1

Tenant read and evidence capture

Read-only access to configuration, policy and audit surfaces. We collect current-state evidence rather than relying on a questionnaire, and confirm which business processes depend on each setting.

Week 2

Baseline comparison and risk framing

Configuration compared against SCuBA and CIS baselines, then triaged by exploitability and business impact — not by the size of the raw finding count.

Week 3

Remediation plan and executive readout

A sequenced plan separating same-week changes from work needing change control, plus a board-level summary of residual risk and the drift controls that keep the tenant from sliding back.

Reference baselines

Standards we assess against.

Public, verifiable baselines — so findings can be reviewed independently by your team, your auditor or your insurer.

Related reading

Microsoft 365 hardening controls that hold

Our briefing on identity-first hardening and drift management across the Microsoft cloud estate.

Read the briefing →All services →

Book Assessment

Navigate Risk. Build Confidence.

A focused executive session to establish where you stand across AI, cyber and business risk.