Microsoft 365 Security Assessment

Know exactly where your tenant stands, and what to fix first.

A senior security engineer assesses your Microsoft 365 tenant against CIS and CISA baselines, correlates the findings into real attack paths, and hands you a prioritised fix list. Not a 200-checkbox dump.

Read-only, no agents, no changes CIS and CISA SCuBA baselines Expert-led, not a tool run Days, not weeks
A printed Falconer Microsoft 365 assessment report, FS-ASM-0231, on a desk with its findings pages beside it
Why now

You are probably here because…

Almost nobody assesses a tenant for fun. One of these usually forces the question.

Regulation
A NIS2 or ISO 27001 deadline needs evidence

The auditor wants proof of technical measures, not intentions.

Insurance
The renewal questionnaire asks about MFA and email security

You need to answer with findings, not guesses.

Sales
A customer sent a security questionnaire

And you are not certain the honest answers look good.

Change
A migration or new tenant just went live

Defaults shipped it working, nobody hardened it.

The scare
A phishing email got uncomfortably far

It was caught late, and now leadership is asking what else is open.

Suspicion
You inherited the tenant and trust nothing

Years of admins, exceptions, and “temporary” settings nobody documented.

41%

of organisations have effectively enforced MFA across Microsoft 365. The rest have gaps they mostly do not know about.

CoreView · State of Microsoft 365, 2025
99.9%

of compromised accounts did not have MFA in effect. The single most common finding is also the most exploited one.

Microsoft · identity security research
Scope

What we actually assess

Four surfaces, specific enough to be checkable. Endpoints, Intune, and Azure infrastructure are separate assessments, so this one stays deep instead of wide.

Identity & Entra

01/04
  • MFA coverage gaps, user by user
  • Conditional Access mapping: holes, conflicts, legacy-auth exceptions
  • Privileged-role inventory and break-glass exposure
  • Guest and dormant accounts
  • OAuth app and service-principal consent hygiene

Email & Defender for Office 365

02/04
  • DMARC, SPF, and DKIM posture
  • Anti-phishing and impersonation protection depth
  • Safe Links and Safe Attachments configuration
  • Mailbox forwarding and transport-rule exceptions

Collaboration & data

03/04
  • Oversharing and “anyone” links
  • External guest exposure
  • DLP policy gaps
  • Sensitivity-label enforcement

Posture & licensing

04/04
  • Secure Score, pulled and correlated, not just reported
  • Tenant defaults that signal maturity
  • Licensing gaps: security features you own but have not turned on
The difference

Attack paths, not checklists

Free tools print pass/fail lists; a technical buyer can run one this afternoon. What they do not do is connect the findings. Our assessors build detections and respond to incidents for a living, and they read your tenant the way an attacker would.

Checklist: pass
Conditional Access requires MFA for all users

Every scanner scores this green. On paper, you are covered.

Checklist: low
Legacy authentication allowed for 3 “service” mailboxes

Flagged as minor. Old protocols, small blast radius, easy to ignore.

Our finding: critical
Password spray → mailbox takeover, no MFA challenge ever fired

Legacy auth never triggers MFA, so the “pass” above is hollow. This pairing is attack path #1 in the report.

A whiteboard diagram: MFA required, legacy auth on, no MFA prompt, password spray, mailbox takeover. Circled: path 1.
On the board

A checklist scores settings one at a time. We score the paths between them, and that is what you pay a human for.

This is attack path #1 from a real assessment, drawn the way we work it: two findings a scanner rates green and low, ending in a mailbox nobody would notice was gone.

The deliverable

One report, written for three readers

The report is the product, so here is what it looks like: board-ready, remediation-ready, and auditor-ready, in one document.

For the board

Executive summary

Overall risk, what it means for the business, and the decisions that need making, in two pages a CFO reads without a translator.

  • Overall risk rating with rationale
  • Top attack paths in plain language
  • Prioritised next steps with effort estimates
For IT

Technical findings

Every finding remediation-ready: what we checked, what we expected, what we found, and exactly how to fix it.

  • Severity and affected objects per finding
  • Expected vs actual configuration
  • The fix: portal steps or PowerShell, per finding
For the auditor

Compliance mapping

Findings mapped to control references, so the same document doubles as audit and insurance evidence.

  • CIS M365 Benchmark and CISA SCuBA references
  • NIS2, ISO 27001, GDPR, Cyber Essentials mapping
  • Evidence your auditor can cite directly
Includes a 1:1 readout call. We walk the findings with you, answer questions, and agree what happens first. The report never lands as a PDF in the dark.
A Falconer security engineer reviewing tenant data at a desk in a quiet office
Method & safety

Safe enough to run on a Tuesday morning

The quiet fear with any assessment is access and breakage. Here is exactly how it works.

Read-only, always

We change nothing. No settings touched, no agents installed, no user impact, no downtime.

Access you control

Scoped, delegated read access via GDAP that you grant and can revoke the moment we are done.

Tooling for coverage

Automated collection across Microsoft Graph and Exchange, checked against the CIS M365 Benchmark and CISA SCuBA baselines.

Humans for judgment

A senior engineer reads the results, correlates them into attack paths, and prioritises. The checklist is the start, not the deliverable.

Days, not weeks

Collection is hours, analysis is days. You get findings while they are still true.

Your data stays yours

Evidence is handled under GDPR, stored in the EU, and deleted on the schedule we agree.

After the report

From findings to fixed

An assessment that only names problems is a stress generator. Three honest ways forward, and the report stands alone whichever you pick.

Fix it yourselves
Every finding ships with the fix

Portal steps or PowerShell, per finding. Many clients remediate in-house with the report alone, and that is a fine outcome for us.

We fix it
Quick-hit remediation

A scoped engagement that closes the top findings, then hands the tenant back hardened.

We keep it fixed
Ongoing management and monitoring

M365 Security Management keeps posture from drifting back. If the assessment shows you need eyes on the tenant, that is MDR and Sentinel. Explore MDR and Managed Sentinel.

How it starts

Free snapshot → full assessment → fixed

The ladder is explicit so nobody feels sold to twice.

1
Free security review

A conversation and a light posture snapshot. Enough to tell whether a full assessment is worth your money, and we will say if it is not.

Free · 30 min
2
Full M365 security assessment

The complete engagement on this page: four surfaces, attack-path analysis, the three-reader report, and the readout call. Priced on users and complexity, quoted before we start, no surprises.

Fixed fee · by tenant size
3
Remediation, or ongoing management

Fix it yourselves with the report, have us close the top findings, or move to managed services. No obligation baked into the assessment.

Optional

Assessments are one-time engagements. No retainer, no auto-renew, no lock-in.

FAQ

The questions assessment buyers ask

Is it safe? Do you make any changes to our tenant?

No changes, ever. The assessment is read-only: no agents installed, no settings modified, no user impact, no downtime. Users never notice it happened.

What access do you need, and can we revoke it?

Scoped, delegated read access granted via GDAP. You grant it at the start, and you can revoke it yourself the moment the engagement ends, without asking us.

How long does it take?

Days, not weeks. Automated collection runs in hours; expert analysis and report writing take a few days after that. You get the exact date at scoping.

Is this just a Secure Score printout or an automated tool run?

No, and that is the point. Tooling gives us coverage; the value is a senior engineer correlating the results into attack paths: which combinations of settings an attacker would actually chain together, in priority order. A free scanner cannot make that judgment.

What exactly do we get?

One report written for three readers: an executive summary for the board, remediation-ready technical findings with the fix per finding, and compliance mapping to control references. Plus a 1:1 readout call to walk the findings.

Do you map findings to NIS2 or ISO 27001?

Yes. Technical baselines are the CIS Microsoft 365 Foundations Benchmark and CISA SCuBA; every finding also maps to NIS2, ISO 27001, GDPR, and Cyber Essentials references where relevant, so the report doubles as audit evidence.

Will this satisfy our cyber-insurance or auditor?

The report is written to be handed over: control references, evidence, and status per finding. Auditors and insurers accept documented third-party assessments; yours will tell you if they need anything further, and the compliance mapping makes that conversation short.

Do you fix the findings, or just report them?

Your choice. Every finding includes the fix, so your team can remediate in-house. If you want help, we offer scoped quick-hit remediation, ongoing M365 Security Management, or managed detection if the assessment shows you need monitoring. The report stands alone either way.

What does it cost, and how is it different from the free review?

The free review is a 30-minute conversation with a light posture snapshot: honest advice on whether a full assessment is worth it. The full assessment is a fixed-fee engagement priced on tenant size and complexity, quoted before we start.

Do we need E5 licensing for the fixes you recommend?

Usually not. Most findings are misconfigurations of features you already license, and the report flags any fix that would genuinely require a licensing step up, with the cheaper alternative alongside it. Unused-license findings often fund the gaps.

Contact

Tell us what you’re dealing with

A Microsoft security specialist reads every message and replies, usually within one business day. Whether you need monitoring, help with a specific tool, or just have a question, start here.

New to this? Ask about a free Microsoft security review as a starting point.

What we can help with
  • Managed detection and response
  • Microsoft Sentinel engineering
  • Identity and email security
  • A free Microsoft security review
1You send a message
2A specialist replies within a business day
3We set up a call to scope what you need

"*" indicates required fields

This field is for validation purposes and should be left unchanged.