Security Assessment
Microsoft 365 Security Assessment
A fixed-scope, fixed-price review of your Microsoft 365 tenant: sign-in security, admin access, email protection, devices, sharing and backup, with a prioritised remediation roadmap.
- MFA coverage and Conditional Access review
- Admin roles and privileged access
- Legacy authentication and risky sign-ins
A fixed-scope review of your tenant, with a fix list
Overview
Most Microsoft 365 tenants were set up to get people working, not to be secure. Multi-factor authentication is partly enforced, old sign-in methods are still allowed, too many people are global admins and nobody has looked at external sharing since the tenant was created.
The Microsoft 365 Security Assessment checks all of it against Microsoft's own security baselines and tells you, in priority order, what to fix. It is read-only: we change nothing during the assessment, and you keep the report whether or not you ask us to do the remediation.
What is included
Everything in the engagement, in writing.
- MFA coverage and Conditional Access review
- Admin roles and privileged access
- Legacy authentication and risky sign-ins
- Exchange Online protection, SPF, DKIM and DMARC
- Microsoft Secure Score review
- Intune device compliance
- SharePoint, OneDrive and Teams external sharing
- Licence review and backup coverage
- Prioritised remediation roadmap and debrief
What you get out of it
Outcomes you can hold us to.
- 01A clear picture of how exposed your tenant is
- 02A prioritised fix list your team or ours can work through
- 03Evidence for insurers, auditors and client questionnaires
What happens during the assessment
1. Kick-off: a short call to agree scope and grant temporary read-only access.
2. Review: we collect configuration, sign-in and Secure Score data and check each area against Microsoft's recommended baselines.
3. Report: findings rated by risk, each with the business impact and the exact fix.
4. Debrief: we walk you through the results and the remediation roadmap. If you want us to do the work, we quote it at a fixed price.
FAQ
Frequently asked questions
What is a Microsoft 365 security assessment?
It is a structured review of how your Microsoft 365 tenant is configured: sign-in security, MFA and Conditional Access, admin roles, email protection (SPF, DKIM, DMARC), devices, external sharing and backup. You receive a risk-rated list of findings and a prioritised plan to fix them.
Do you need admin access to our tenant?
We need temporary read-only access, such as the Global Reader role, for the duration of the review. We make no changes during the assessment and the access can be removed as soon as it finishes.
How long does it take?
For most small and mid-sized tenants the review and report are completed within one to two weeks of access being granted.
How much does it cost?
The assessment is a fixed price based on the size of your tenant, agreed before we start. Any remediation work is quoted separately, and you are free to do it yourselves using the report.

Ready to move on Microsoft 365 Security Assessment?
We will scope it against your actual environment, not a generic package, and give you a fixed price before any work starts.

