Security

Microsoft 365 security assessment

A read of your Microsoft 365 tenant as it really is, covering sign-in rules, administrator accounts, app permissions and device health, with findings ranked by what an attacker would reach for first.

Code on a dark screen, reflected in glass

The situation

The licences are bought, the features are there, and nobody is certain which of them are actually switched on.

Who it is for

Any organisation running Microsoft 365, especially before an audit, after an incident, or before adopting new security tools.

What people worry about

The dangerous gaps are the quiet ones. A protection that has been switched off raises no alarm; it is simply not there. That is why an assessment reads the settings themselves rather than waiting for something to go wrong.

What you get

Included in the engagement

  • Your sign-in and access rules, including ones that exist but are not enforcing anything
  • Who holds administrator power, and who holds it permanently
  • Apps with standing access to your data, the kind a password reset does not remove
  • Devices that are not enrolled or not meeting your standard

What it means

Ranked by what an attacker would reach for first
Read-only we look at your settings and change nothing

How it runs

What happens, in order

  1. 01

    Connect

    You grant read-only access, which takes minutes.

  2. 02

    Read

    We read your settings as they actually are, not as the documentation says they should be.

  3. 03

    Rank

    Findings are ordered by what an attacker would use first, so the top of the list is where to start.

  4. 04

    Walk through

    An engineer takes you through the findings and what to fix first.

Talk to an engineer, not a form

The first conversation is about your estate, not our product.