Entra ID
Tenant configuration, directory hygiene, group and licence structure, guest accounts, legacy authentication, and the app registrations that have quietly accumulated consent to your data.
Microsoft 365 Security
An independent review of how your tenant is genuinely configured — identity, access, sharing and logging — followed by the work to correct it without disrupting your staff.
The problem
Microsoft 365 concentrates more SME risk in one place than anything else — email, documents, identity and collaboration in a single tenant reachable from anywhere.
Very few businesses configured it deliberately from scratch. It was migrated to under time pressure, extended during 2020, adjusted by whoever held admin rights at the time, and inherited by an IT provider who reasonably assumed the previous decisions were intentional.
The result is not usually one dramatic hole. It is a dozen small ones: an exclusion group from a migration that still contains active users, a departed director whose mailbox is still licensed, a sharing link from 2019 pointing at a folder of contracts, an app registration granted broad consent for a trial nobody remembers.
Individually, each is minor. Together they are the reason an account compromise turns into a data breach rather than an inconvenience.
Review at a glance
Scope
Depth varies with your licensing and how you use the platform. We do not assess features you do not have, and we do not recommend products you do not need.
Tenant configuration, directory hygiene, group and licence structure, guest accounts, legacy authentication, and the app registrations that have quietly accumulated consent to your data.
Coverage checked against every account rather than most of them, including service accounts and break-glass access, plus resistance to prompt-bombing and token theft. Exclusions are the interesting part.
Policies reviewed for what they actually enforce, not what they were intended to enforce. Overlaps, gaps, report-only policies never turned on, and the accounts excluded from all of them.
How many Global Administrators exist, who holds them, whether they are used daily, and whether privileged access can be time-limited and approved instead of permanent.
Forwarding and inbox rules, delegate access, shared mailbox permissions, and detection of the rule-based fraud patterns used in invoice redirection.
Site and library permissions, broken inheritance, sites with no owner, and whether the structure supports meaningful access control or has simply been flattened for convenience.
What business data sits in personal drives, what happens to it when someone leaves, and how much of it is shared outside the organisation.
Team and channel sprawl, guest membership, private channel visibility, meeting recording storage and retention, and third-party apps added by users.
Anonymous links, their age and expiry, domain allow-lists, and which of your files are currently reachable by anyone holding a URL.
Whether unmanaged and personal devices can reach company data, what happens on those devices, and whether Intune or equivalent controls are enforced or merely configured.
Whether security defaults are on, whether they have been replaced by Conditional Access properly rather than partially, and how the tenant compares to a sensible baseline.
Whether the events that matter are recorded, how long they are retained under your licence, and whether anyone would notice a privileged role assignment at 2am.
Where regulated or commercially sensitive data actually lives, who can reach it, and whether any control exists to stop it leaving. Labelling and DLP where they earn their place — not everywhere.
Microsoft replicates your data; it does not back it up in the sense most businesses assume. We set out what the retention policies genuinely cover and where third-party backup is justified.
Licensing
A large share of the findings in a typical review are fixed by configuring something you already pay for.
Business Premium includes Conditional Access, Intune, Defender for Office 365 and Entra ID Plan 1 capability that a great many organisations hold and never switch on. Before recommending an upgrade, we establish what your current licences already permit and how much of the gap that closes.
Where a higher tier or an add-on genuinely earns its place, we will say so and explain the specific control it buys you and the risk it addresses. Where it does not, we will say that too. We take no commission on Microsoft licensing, so this recommendation costs us nothing to make honestly.
Outcomes
Tenant permissions in good order are also the prerequisite for any AI system that reads company files. A knowledge assistant inherits whatever access structure it is given — so an over-shared SharePoint becomes an over-sharing assistant. Getting this right first makes the AI work considerably simpler.
Process
Assessment is non-intrusive. Nothing user-visible changes until you have seen the findings and agreed the plan.
A scoped, time-limited read-only role in your tenant. Nothing is changed at this stage and users notice nothing.
Identity, Conditional Access, roles, mailboxes, SharePoint, Teams, sharing, devices and logging, cross-checked against how you actually work.
Findings in business language with a technical appendix, ranked by exposure and effort, including the ones we recommend you deliberately accept.
Changes applied in a sequence designed to avoid disruption, with user-visible changes piloted first and communicated in advance.
FAQ
It is reasonably secure out of the box for a brand-new tenant, and security defaults have improved considerably. The problem is that almost no established business is running a default tenant. Years of migrations, exclusions, legacy settings and convenience decisions accumulate, and it is that accumulated drift — not Microsoft's baseline — that creates most SME exposure.
No. A great deal can be achieved on Business Premium, which most SMEs already hold or can move to economically. E5 adds genuinely useful capability in advanced threat protection, information protection and identity governance, but it is not a prerequisite for good security, and we will not tell you it is. We start by making sure you are using what you already pay for.
It can if it is done carelessly, which is why it rarely is done at all. We identify who is genuinely affected, pilot with a small group, communicate in advance, and keep a documented break-glass account. In practice most staff notice a single registration prompt and nothing further.
Secure Score is a useful signal and a poor target. It weights recommendations generically, rewards actions that may not fit your business, and says nothing about the exposure specific to your configuration — such as a five-year-old anonymous link to a folder of client files. We use it as one input, not as the assessment.
Microsoft protects the platform and provides retention and recycle-bin features, which is not the same as a backup you control. Recoverability of a mailbox or site deleted or maliciously altered outside those retention windows is limited. Whether that gap justifies third-party backup depends on your obligations and tolerance — we set out the specifics rather than assuming you need it.
For most SME tenants, one to two weeks from access being granted to a report in your hands. Remediation depends on findings; the high-value items are commonly completed within a further two to three weeks.
A scoping conversation is free. If your Microsoft 365 environment is already in good order, a review will establish that quickly and cheaply.