One scoped deliverable, one fixed fee

Microsoft 365 tenant security assessment: find out what your settings are actually doing

A Microsoft 365 tenant security assessment is a read-only configuration review, not an open-ended engagement. We read your identity, sharing, email, and device settings against Microsoft's published guidance, then hand you a written findings report and a prioritized fix list you own — whether we do the fixing or your team does.

  • Fixed fee, scoped in writing
  • Senior US-based engineers
  • Read-only — we change nothing
  • The findings are yours to keep
Revenue Overview Revenue$4.2M Margin38% Orders12.4k Churn2.1% Monthly performance By segment 64%

Representative dashboard — sample data

What you receive

Six things land in your hands at the end

Every one of them is a document or a list you keep. Nothing about this engagement depends on renewing it.

A written findings report

Each area we reviewed, the setting we observed, the Microsoft guidance it was measured against, and plain-language notes on why the gap matters.

A prioritized remediation list

Findings ordered by exposure and effort, so the first afternoon of work closes the things that would hurt most — not the things that were easiest to write down.

A settings inventory

The actual configuration we read — policies, sharing defaults, role assignments, mail-flow rules — captured as evidence so a later review can measure drift against it.

A Secure Score baseline

Your current Microsoft Secure Score with the actions behind it, separated into recommendations worth acting on and ones that do not apply to how you work.

A walkthrough with the engineer

A working session with the person who ran the review, so your IT lead can ask "what happens if we change this?" and get an answer rather than a ticket.

A decision, not a dependency

Take the list in-house, hand it to your MSP, or ask us to quote the fixes as a separate scoped project. The assessment is complete either way.

How the engagement runs

Scope it, read it, hand it over

  1. 1

    Scope and agree the fee

    A free consultation establishes how many users, sites, and policies are in play and which workloads you actually run. You get one written scope and one fixed fee to approve before anything is read.

  2. 2

    Read the tenant, change nothing

    With read-only access you grant, a senior engineer works through the nine areas below, capturing the observed configuration and comparing it against Microsoft's published guidance for each control.

  3. 3

    Hand over and walk through

    You get the findings report, the settings inventory, and the prioritized fix list, plus a walkthrough session. Access is revoked at handover, and what you do next is your call.

One deliverable, deliberately narrow

Most of this site is a menu — six areas of fixed-fee Microsoft 365 consulting for small business teams you can pick from once you know what you need. This page is the opposite shape: a single scoped review with a defined start, a defined end, and one artifact at the end of it. People book it when they suspect something is wrong in the tenant but cannot yet say what, so a menu is the wrong thing to hand them.

The reason a configuration review finds so much is that Microsoft 365 tenants accumulate settings rather than decisions. A sharing default set in 2019 for one project, a conditional access policy left in report-only mode after a pilot, four people holding Global Administrator because that was the fastest way to unblock someone — none of it is a mistake at the moment it happens, and none of it announces itself later. Reading the tenant end to end is how it surfaces. The engagement model behind the fee is the ordinary one described in how our fixed-fee scoping works.

The nine areas we read

The scope is fixed so the deliverable is comparable: the same nine areas, in the same order, against the same published guidance. Where a workload is not licensed or not in use, we say so in the report rather than quietly dropping the row.

Area What we check What lands in the findings
Identity and MFA MFA coverage across users and admins, legacy authentication still permitted, password policy, break-glass account design The accounts with no second factor, named, with the enforcement path for each
Conditional access Policy inventory, exclusion groups, policies left in report-only, sign-in conditions with no matching policy A policy-by-policy map of what is covered and where sign-ins fall through
Admin-role hygiene Global Administrator count, standing versus eligible assignments, service accounts and shared mailboxes holding roles A role-by-role list with a least-privilege alternative for each assignment
External sharing and guest access Tenant and site-level sharing defaults, "Anyone" links in circulation, guest accounts and when they last signed in Every over-broad sharing surface, tied to the site or library that owns it
Email and anti-phishing Anti-phishing, anti-spam, Safe Links and Safe Attachments policies; SPF, DKIM and DMARC records; auto-forwarding rules Preset-policy gaps and DNS records that do not match the domains you actually send from
DLP and sensitivity labels Which labels are published, where they are applied in practice, DLP policies sitting in test mode instead of enforcing What is labeled, what is not, and which policies were never switched on
Device compliance Enrolled versus unmanaged devices, compliance policy coverage, operating system and disk-encryption state Devices reaching company data from outside any compliance policy
Audit logging Unified audit log status, retention window, alert policies and whether they notify a real person Whether you could reconstruct an incident today, and how far back the record goes
Microsoft Secure Score Current score, the improvement actions behind it, and which recommendations genuinely fit how your business operates A dated baseline plus the short list actually worth acting on

Each row is measured against something Microsoft publishes rather than against a private opinion. Conditional access findings reference Microsoft's Conditional Access documentation (opens in new tab); role findings against the Microsoft Entra least-privileged role guidance (opens in new tab); sharing findings against the SharePoint external sharing overview (opens in new tab); logging findings against the Microsoft Purview auditing documentation (opens in new tab); and the score baseline comes straight from Microsoft Secure Score (opens in new tab). Where guidance and your business reality disagree, the report says which recommendation we would skip and why.

What this is not

Read the limits before you book

This is a configuration review, not a penetration test: nothing is attacked, exploited, or stress-tested. It is not a compliance audit, and it produces no certification, attestation, or formal opinion of any kind — we do not issue CMMC, HIPAA, or SOC findings, and the report should not be presented as one. It is not a monitoring service; it describes the tenant on the days we read it. And it changes nothing: your tenant, your admin accounts, and every decision about whether and when to remediate stay with you. If your auditors or your insurer need evidence, the findings are useful input for that conversation, not a substitute for the assessor who owns it.

Scope, timeline, and the fee

Pricing is scoped rather than listed because the honest driver is tenant size and sprawl: fifteen SharePoint sites and two conditional access policies is not the same review as two hundred sites and a decade of guest accounts. The table below is the whole commercial shape of the engagement.

Stage What happens Timeline Fee
Free consultation A senior engineer confirms which workloads you run, how big the tenant is, and whether an assessment is the right first step at all Before scoping No charge
The assessment Read-only review of the nine areas, the settings inventory, the written findings report, the prioritized remediation list, and the walkthrough session Inside our usual 2–4 week delivery window Fixed fee — scoped after your free consultation
Remediation (optional) You work the list in-house or hand it to your MSP; if you would rather we did it, the fixes are quoted as a separate project you approve on its own merits Depends on the list Fixed fee — scoped after your free consultation

Everything the assessment produces belongs to you the moment it is delivered, including the settings inventory a future engineer would need to repeat the review without us.

Who books this, and what usually follows

The common fit is a 20–500-person company where one IT generalist owns the whole tenant, or where an outsourced provider set it up years ago and nobody has read the configuration since. The trigger is usually external: a cyber-insurance questionnaire nobody can answer confidently, a customer security review, a near-miss with a phishing email, or a new leader asking who has administrator rights.

What follows depends on what the report finds. Sharing and permission findings tend to lead into SharePoint intranet and document management consulting, because sprawl is a structure problem before it is a settings problem. Identity, network, and infrastructure findings often point toward Azure migration and cost optimization work. And if an AI rollout is what prompted the question in the first place, the narrower content-governance angle is covered in our article on Copilot data governance essentials and delivered as the first phase of Microsoft 365 Copilot rollout consulting — a readiness review aimed at one question, where this assessment is aimed at the whole tenant.

FAQ

Questions people ask before booking a review

Nine configuration areas: identity and MFA, conditional access, admin-role hygiene, external sharing and guest access, email and anti-phishing settings, DLP and sensitivity labels, device compliance, audit logging, and your Microsoft Secure Score baseline. Each is compared against Microsoft's published guidance, and every finding is written down with the setting we observed.

Not during the assessment. The review is read-only: we look, we document, and we hand you a prioritized fix list. Remediation is a separate decision you make and a separate scope you approve. Your tenant, your admin accounts, and every configuration change remain under your control throughout.

Neither. It is a configuration review measured against Microsoft's published guidance for Microsoft 365. We do not attack your systems, and we do not issue certifications, attestations, or formal compliance opinions. If your auditors need evidence, the findings report is useful input for them — not a substitute for them.

One fixed fee, scoped after your free consultation, because an honest number depends on how many users, sites, and policies live in the tenant. Delivery falls inside our usual two-to-four-week window, and you approve the written scope, the fee, and the timeline before any review begins.

Read-only administrative access, granted by you, to the Microsoft 365 admin center, Entra ID, Exchange, SharePoint, Purview, and Intune where you use them. We work from your own audit and configuration data, and access is revoked at handover. No agents, no third-party tooling installed in the tenant.

Book a free consultation

Get more from the Microsoft tools you already pay for

Tell us what you’re trying to fix — a report, an approval process, an intranet, a Copilot rollout. We scope it as a fixed-fee project, you approve, and a senior engineer delivers in 2–4 weeks.

  • Fixed-fee scope agreed before any work starts
  • Senior, US-based Microsoft engineers — no handoffs
  • Typical 2–4 week delivery
  • 30 days of post-delivery hypercare included

The fastest way to reach us is the form — tell us the task and we’ll reply within one business day.

All fields are required.

We reply within one business day. No newsletters, no drip campaigns.

Book a Free Consultation