Security assessments

Know what to fix in your tenant

A configuration review that gives your team a written record of the gaps, why they matter, and which changes to make first.

What you receive

An executive summary
A summary of the risks identified in the agreed scope, for the people approving the remediation work.
Prioritized configuration findings
The setting or control reviewed, the gap identified, its security impact, and the recommended change. Findings are ranked by risk so your team can distinguish urgent work from longer-term improvements.
A remediation roadmap
Recommended actions organized by risk and effort, with licensing and user impact considered when setting priorities.

What we inspect

Choose a Microsoft 365, Entra, Purview, or Google Workspace review. The checks depend on the services you use and the scope we agree with you.

  • Authentication and access: MFA, Conditional Access, administrator privileges, guests, and emergency access.
  • Email protection: phishing controls, forwarding, and mail authentication settings.
  • Data sharing: external access, sensitivity labels, and data loss prevention controls.
  • Monitoring: audit visibility, security alerts, and relevant benchmark alignment.

Illustrative finding • not client data

External sharing is broader than the business requires

Observation
A SharePoint site containing internal project files permits Anyone links. The team only needs to share with named external collaborators.
Why it matters
An Anyone link can be forwarded beyond the intended recipient. Access does not require the recipient to sign in.
Recommended action
Review existing links with the site owner, restrict sharing to the required recipients, and test external collaboration before applying the change more broadly.
How priority is decided
Consider the sensitivity of the files, existing links, and business impact. Record those details before assigning the finding a risk level.
Microsoft guidance on sharing links

Before the assessment starts

Tell us your tenant size, services, licensing, and the questions you need answered. We use that information to agree on scope and access. Implementation can be scoped separately after you review the findings.

Ask about an assessmentView all services