Microsoft 365 Security

Microsoft 365 Security

An independent review of how your tenant is genuinely configured — identity, access, sharing and logging — followed by the work to correct it without disrupting your staff.

The problem

Almost nobody is running the tenant they think they are

Microsoft 365 concentrates more SME risk in one place than anything else — email, documents, identity and collaboration in a single tenant reachable from anywhere.

Very few businesses configured it deliberately from scratch. It was migrated to under time pressure, extended during 2020, adjusted by whoever held admin rights at the time, and inherited by an IT provider who reasonably assumed the previous decisions were intentional.

The result is not usually one dramatic hole. It is a dozen small ones: an exclusion group from a migration that still contains active users, a departed director whose mailbox is still licensed, a sharing link from 2019 pointing at a folder of contracts, an app registration granted broad consent for a trial nobody remembers.

Individually, each is minor. Together they are the reason an account compromise turns into a data breach rather than an inconvenience.

Review at a glance

Access needed
Scoped, time-limited, read-only
Disruption
None during assessment
Duration
Typically 1–2 weeks to report
Licence stance
Use what you already own first
Deliverable
Ranked findings, business + technical
Remediation
By us, or alongside your IT provider

Scope

What a Microsoft 365 security review examines

Depth varies with your licensing and how you use the platform. We do not assess features you do not have, and we do not recommend products you do not need.

Entra ID

Tenant configuration, directory hygiene, group and licence structure, guest accounts, legacy authentication, and the app registrations that have quietly accumulated consent to your data.

Multi-factor authentication

Coverage checked against every account rather than most of them, including service accounts and break-glass access, plus resistance to prompt-bombing and token theft. Exclusions are the interesting part.

Conditional Access

Policies reviewed for what they actually enforce, not what they were intended to enforce. Overlaps, gaps, report-only policies never turned on, and the accounts excluded from all of them.

Administrator roles

How many Global Administrators exist, who holds them, whether they are used daily, and whether privileged access can be time-limited and approved instead of permanent.

Mailbox security

Forwarding and inbox rules, delegate access, shared mailbox permissions, and detection of the rule-based fraud patterns used in invoice redirection.

SharePoint

Site and library permissions, broken inheritance, sites with no owner, and whether the structure supports meaningful access control or has simply been flattened for convenience.

OneDrive

What business data sits in personal drives, what happens to it when someone leaves, and how much of it is shared outside the organisation.

Teams

Team and channel sprawl, guest membership, private channel visibility, meeting recording storage and retention, and third-party apps added by users.

External sharing

Anonymous links, their age and expiry, domain allow-lists, and which of your files are currently reachable by anyone holding a URL.

Device access

Whether unmanaged and personal devices can reach company data, what happens on those devices, and whether Intune or equivalent controls are enforced or merely configured.

Security defaults and baselines

Whether security defaults are on, whether they have been replaced by Conditional Access properly rather than partially, and how the tenant compares to a sensible baseline.

Audit logging

Whether the events that matter are recorded, how long they are retained under your licence, and whether anyone would notice a privileged role assignment at 2am.

Data loss risk

Where regulated or commercially sensitive data actually lives, who can reach it, and whether any control exists to stop it leaving. Labelling and DLP where they earn their place — not everywhere.

Backup considerations

Microsoft replicates your data; it does not back it up in the sense most businesses assume. We set out what the retention policies genuinely cover and where third-party backup is justified.

Licensing

You probably do not need every Microsoft product

A large share of the findings in a typical review are fixed by configuring something you already pay for.

Business Premium includes Conditional Access, Intune, Defender for Office 365 and Entra ID Plan 1 capability that a great many organisations hold and never switch on. Before recommending an upgrade, we establish what your current licences already permit and how much of the gap that closes.

Where a higher tier or an add-on genuinely earns its place, we will say so and explain the specific control it buys you and the risk it addresses. Where it does not, we will say that too. We take no commission on Microsoft licensing, so this recommendation costs us nothing to make honestly.

Questions we answer before recommending spend

  • What do your current licences already allow?
  • Which of those capabilities are configured, and which merely available?
  • What specific risk would an upgrade reduce?
  • Is there a configuration change that achieves the same outcome?
  • What is the annual cost against the exposure it addresses?
  • Who will administer it once it is in place?

Outcomes

What you are left with

  • A documented picture of how your tenant is configured today.
  • Findings ranked by real exposure, with the reasoning shown.
  • Administrative access reduced to named accounts with elevation.
  • MFA and Conditional Access gaps closed without locking staff out.
  • Historic sharing links reviewed, expired and brought under policy.
  • Audit logging and alerting configured for the events that matter.
  • Evidence you can put in front of an insurer or a client questionnaire.

And what it enables next

Tenant permissions in good order are also the prerequisite for any AI system that reads company files. A knowledge assistant inherits whatever access structure it is given — so an over-shared SharePoint becomes an over-sharing assistant. Getting this right first makes the AI work considerably simpler.

AI consultancy and deployment

Process

How a Microsoft 365 review runs

Assessment is non-intrusive. Nothing user-visible changes until you have seen the findings and agreed the plan.

  1. 01

    Read-only access

    A scoped, time-limited read-only role in your tenant. Nothing is changed at this stage and users notice nothing.

  2. 02

    Configuration review

    Identity, Conditional Access, roles, mailboxes, SharePoint, Teams, sharing, devices and logging, cross-checked against how you actually work.

  3. 03

    Report and prioritisation

    Findings in business language with a technical appendix, ranked by exposure and effort, including the ones we recommend you deliberately accept.

  4. 04

    Staged remediation

    Changes applied in a sequence designed to avoid disruption, with user-visible changes piloted first and communicated in advance.

FAQ

Microsoft 365 security: common questions

Is Microsoft 365 secure by default?

It is reasonably secure out of the box for a brand-new tenant, and security defaults have improved considerably. The problem is that almost no established business is running a default tenant. Years of migrations, exclusions, legacy settings and convenience decisions accumulate, and it is that accumulated drift — not Microsoft's baseline — that creates most SME exposure.

Do we need Microsoft 365 E5 to be secure?

No. A great deal can be achieved on Business Premium, which most SMEs already hold or can move to economically. E5 adds genuinely useful capability in advanced threat protection, information protection and identity governance, but it is not a prerequisite for good security, and we will not tell you it is. We start by making sure you are using what you already pay for.

Will enforcing MFA or Conditional Access disrupt our staff?

It can if it is done carelessly, which is why it rarely is done at all. We identify who is genuinely affected, pilot with a small group, communicate in advance, and keep a documented break-glass account. In practice most staff notice a single registration prompt and nothing further.

We already have a Secure Score. Is that not enough?

Secure Score is a useful signal and a poor target. It weights recommendations generically, rewards actions that may not fit your business, and says nothing about the exposure specific to your configuration — such as a five-year-old anonymous link to a folder of client files. We use it as one input, not as the assessment.

Does Microsoft back up our data?

Microsoft protects the platform and provides retention and recycle-bin features, which is not the same as a backup you control. Recoverability of a mailbox or site deleted or maliciously altered outside those retention windows is limited. Whether that gap justifies third-party backup depends on your obligations and tolerance — we set out the specifics rather than assuming you need it.

How long does a Microsoft 365 security review take?

For most SME tenants, one to two weeks from access being granted to a report in your hands. Remediation depends on findings; the high-value items are commonly completed within a further two to three weeks.

See how your tenant is really configured.

A scoping conversation is free. If your Microsoft 365 environment is already in good order, a review will establish that quickly and cheaply.