Service

Microsoft 365 Security Assessment

An independent, evidence-based view of your Microsoft 365 risk in two to three weeks.

Duration2–3 weeksInvestmentTypically $7,500–$15,000

The problem

Most Microsoft 365 tenants grew fast and were never reviewed end to end. Legacy sign-in methods, permanent global admins, permissive app consent and weak email protections are common — and they are exactly what phishing kits and business email compromise crews look for.

Who it's for

50–2,000 seat organizations on Microsoft 365 without a dedicated Microsoft security engineer.

What's included

  • Baseline against CISA SCuBA, CIS Microsoft 365 and Microsoft's Zero Trust Assessment
  • Identity review: Conditional Access, MFA coverage, admin roles, legacy authentication
  • Email security: Defender for Office 365 policies, SPF/DKIM/DMARC, external forwarding
  • Collaboration: external sharing, Teams external access, guest governance
  • App consent and OAuth application review
  • Logging and audit readiness

Frequently asked questions

What access do you need?

Read-only roles such as Global Reader and Security Reader. Some free assessment tools need a one-time admin consent, which your administrator grants.

Do you fix things too?

The assessment is diagnostic. Most clients continue with our Entra ID Hardening Sprint or a monthly retainer to implement the roadmap.

How is this different from Secure Score?

Secure Score is a useful input. We validate it, add checks it doesn't cover, and turn the results into a prioritized plan tied to business risk.