A written findings report
Each area we reviewed, the setting we observed, the Microsoft guidance it was measured against, and plain-language notes on why the gap matters.
One scoped deliverable, one fixed fee
A Microsoft 365 tenant security assessment is a read-only configuration review, not an open-ended engagement. We read your identity, sharing, email, and device settings against Microsoft's published guidance, then hand you a written findings report and a prioritized fix list you own — whether we do the fixing or your team does.
Representative dashboard — sample data
What you receive
Every one of them is a document or a list you keep. Nothing about this engagement depends on renewing it.
Each area we reviewed, the setting we observed, the Microsoft guidance it was measured against, and plain-language notes on why the gap matters.
Findings ordered by exposure and effort, so the first afternoon of work closes the things that would hurt most — not the things that were easiest to write down.
The actual configuration we read — policies, sharing defaults, role assignments, mail-flow rules — captured as evidence so a later review can measure drift against it.
Your current Microsoft Secure Score with the actions behind it, separated into recommendations worth acting on and ones that do not apply to how you work.
A working session with the person who ran the review, so your IT lead can ask "what happens if we change this?" and get an answer rather than a ticket.
Take the list in-house, hand it to your MSP, or ask us to quote the fixes as a separate scoped project. The assessment is complete either way.
How the engagement runs
A free consultation establishes how many users, sites, and policies are in play and which workloads you actually run. You get one written scope and one fixed fee to approve before anything is read.
With read-only access you grant, a senior engineer works through the nine areas below, capturing the observed configuration and comparing it against Microsoft's published guidance for each control.
You get the findings report, the settings inventory, and the prioritized fix list, plus a walkthrough session. Access is revoked at handover, and what you do next is your call.
Most of this site is a menu — six areas of fixed-fee Microsoft 365 consulting for small business teams you can pick from once you know what you need. This page is the opposite shape: a single scoped review with a defined start, a defined end, and one artifact at the end of it. People book it when they suspect something is wrong in the tenant but cannot yet say what, so a menu is the wrong thing to hand them.
The reason a configuration review finds so much is that Microsoft 365 tenants accumulate settings rather than decisions. A sharing default set in 2019 for one project, a conditional access policy left in report-only mode after a pilot, four people holding Global Administrator because that was the fastest way to unblock someone — none of it is a mistake at the moment it happens, and none of it announces itself later. Reading the tenant end to end is how it surfaces. The engagement model behind the fee is the ordinary one described in how our fixed-fee scoping works.
The scope is fixed so the deliverable is comparable: the same nine areas, in the same order, against the same published guidance. Where a workload is not licensed or not in use, we say so in the report rather than quietly dropping the row.
| Area | What we check | What lands in the findings |
|---|---|---|
| Identity and MFA | MFA coverage across users and admins, legacy authentication still permitted, password policy, break-glass account design | The accounts with no second factor, named, with the enforcement path for each |
| Conditional access | Policy inventory, exclusion groups, policies left in report-only, sign-in conditions with no matching policy | A policy-by-policy map of what is covered and where sign-ins fall through |
| Admin-role hygiene | Global Administrator count, standing versus eligible assignments, service accounts and shared mailboxes holding roles | A role-by-role list with a least-privilege alternative for each assignment |
| External sharing and guest access | Tenant and site-level sharing defaults, "Anyone" links in circulation, guest accounts and when they last signed in | Every over-broad sharing surface, tied to the site or library that owns it |
| Email and anti-phishing | Anti-phishing, anti-spam, Safe Links and Safe Attachments policies; SPF, DKIM and DMARC records; auto-forwarding rules | Preset-policy gaps and DNS records that do not match the domains you actually send from |
| DLP and sensitivity labels | Which labels are published, where they are applied in practice, DLP policies sitting in test mode instead of enforcing | What is labeled, what is not, and which policies were never switched on |
| Device compliance | Enrolled versus unmanaged devices, compliance policy coverage, operating system and disk-encryption state | Devices reaching company data from outside any compliance policy |
| Audit logging | Unified audit log status, retention window, alert policies and whether they notify a real person | Whether you could reconstruct an incident today, and how far back the record goes |
| Microsoft Secure Score | Current score, the improvement actions behind it, and which recommendations genuinely fit how your business operates | A dated baseline plus the short list actually worth acting on |
Each row is measured against something Microsoft publishes rather than against a private opinion. Conditional access findings reference Microsoft's Conditional Access documentation (opens in new tab); role findings against the Microsoft Entra least-privileged role guidance (opens in new tab); sharing findings against the SharePoint external sharing overview (opens in new tab); logging findings against the Microsoft Purview auditing documentation (opens in new tab); and the score baseline comes straight from Microsoft Secure Score (opens in new tab). Where guidance and your business reality disagree, the report says which recommendation we would skip and why.
This is a configuration review, not a penetration test: nothing is attacked, exploited, or stress-tested. It is not a compliance audit, and it produces no certification, attestation, or formal opinion of any kind — we do not issue CMMC, HIPAA, or SOC findings, and the report should not be presented as one. It is not a monitoring service; it describes the tenant on the days we read it. And it changes nothing: your tenant, your admin accounts, and every decision about whether and when to remediate stay with you. If your auditors or your insurer need evidence, the findings are useful input for that conversation, not a substitute for the assessor who owns it.
Pricing is scoped rather than listed because the honest driver is tenant size and sprawl: fifteen SharePoint sites and two conditional access policies is not the same review as two hundred sites and a decade of guest accounts. The table below is the whole commercial shape of the engagement.
| Stage | What happens | Timeline | Fee |
|---|---|---|---|
| Free consultation | A senior engineer confirms which workloads you run, how big the tenant is, and whether an assessment is the right first step at all | Before scoping | No charge |
| The assessment | Read-only review of the nine areas, the settings inventory, the written findings report, the prioritized remediation list, and the walkthrough session | Inside our usual 2–4 week delivery window | Fixed fee — scoped after your free consultation |
| Remediation (optional) | You work the list in-house or hand it to your MSP; if you would rather we did it, the fixes are quoted as a separate project you approve on its own merits | Depends on the list | Fixed fee — scoped after your free consultation |
Everything the assessment produces belongs to you the moment it is delivered, including the settings inventory a future engineer would need to repeat the review without us.
The common fit is a 20–500-person company where one IT generalist owns the whole tenant, or where an outsourced provider set it up years ago and nobody has read the configuration since. The trigger is usually external: a cyber-insurance questionnaire nobody can answer confidently, a customer security review, a near-miss with a phishing email, or a new leader asking who has administrator rights.
What follows depends on what the report finds. Sharing and permission findings tend to lead into SharePoint intranet and document management consulting, because sprawl is a structure problem before it is a settings problem. Identity, network, and infrastructure findings often point toward Azure migration and cost optimization work. And if an AI rollout is what prompted the question in the first place, the narrower content-governance angle is covered in our article on Copilot data governance essentials and delivered as the first phase of Microsoft 365 Copilot rollout consulting — a readiness review aimed at one question, where this assessment is aimed at the whole tenant.
Related services
Sharing and permission findings are usually a structure problem. Intranets and document management built so access is auditable by design.
A governed Copilot rollout that starts with readiness and permission cleanup, then pilots and adoption training on a fixed fee.
When findings point past the tenant to the servers and subscriptions behind it: migration, cost optimization, and architecture review.
FAQ
Nine configuration areas: identity and MFA, conditional access, admin-role hygiene, external sharing and guest access, email and anti-phishing settings, DLP and sensitivity labels, device compliance, audit logging, and your Microsoft Secure Score baseline. Each is compared against Microsoft's published guidance, and every finding is written down with the setting we observed.
Not during the assessment. The review is read-only: we look, we document, and we hand you a prioritized fix list. Remediation is a separate decision you make and a separate scope you approve. Your tenant, your admin accounts, and every configuration change remain under your control throughout.
Neither. It is a configuration review measured against Microsoft's published guidance for Microsoft 365. We do not attack your systems, and we do not issue certifications, attestations, or formal compliance opinions. If your auditors need evidence, the findings report is useful input for them — not a substitute for them.
One fixed fee, scoped after your free consultation, because an honest number depends on how many users, sites, and policies live in the tenant. Delivery falls inside our usual two-to-four-week window, and you approve the written scope, the fee, and the timeline before any review begins.
Read-only administrative access, granted by you, to the Microsoft 365 admin center, Entra ID, Exchange, SharePoint, Purview, and Intune where you use them. We work from your own audit and configuration data, and access is revoked at handover. No agents, no third-party tooling installed in the tenant.
Book a free consultation
Tell us what you’re trying to fix — a report, an approval process, an intranet, a Copilot rollout. We scope it as a fixed-fee project, you approve, and a senior engineer delivers in 2–4 weeks.
The fastest way to reach us is the form — tell us the task and we’ll reply within one business day.