Establish applicability
Confirm licenses, enabled services, tenant relationships, business requirements, known exceptions, and assessment boundaries.
TenantShield combines a structured Microsoft 365 control library, collected evidence, analyst validation, and business context to produce priorities—not just check results.
Confirm licenses, enabled services, tenant relationships, business requirements, known exceptions, and assessment boundaries.
Collect and review the configuration and operational evidence available for each applicable control.
Check material observations against compensating controls, dependencies, stakeholder intent, and evidence quality.
Consider likely impact, exposure, exploitability, breadth, business dependency, change risk, and effort.
Connect each priority to evidence, an accountable owner, recommended action, dependency, and validation step.
The library contains more than 400 controls, but a larger raw count is not the objective. Applicability and evidence quality are recorded so excluded controls do not distort the result.
Microsoft Entra authentication, Conditional Access, privileged roles, guest users, and user and sign-in risk.
Exchange Online, built-in security features for cloud mailboxes, Microsoft Defender for Office 365 where licensed, mail flow, auditing, forwarding, and email authentication.
Microsoft Teams, SharePoint Online, OneDrive, sharing, guest users, and governance settings.
Consent, permissions, enterprise applications, and service principals.
Microsoft Intune device management, configuration, and compliance signals where applicable.
Relevant Microsoft Purview retention, sensitivity labeling, and data loss prevention controls where licensed.
Microsoft Defender XDR alerts where licensed, audit availability, logging, and investigation readiness.
Ownership, exception handling, access lifecycle, change control, and evidence of review.
A recommendation is prioritized using the evidence available at the time of review and the organization’s context.
| Factor | Question |
|---|---|
| Impact | What could happen to identities, data, operations, customers, or regulatory obligations? |
| Exposure | How broadly is the condition exposed, and which users, administrators, data, or workloads are affected? |
| Likelihood | How plausible is misuse or failure given current controls and common attack paths? |
| Compensation | Do other technical or operational controls materially reduce the risk? |
| Change risk | What user impact, dependency, or service disruption could remediation create? |
| Evidence confidence | Is the conclusion supported directly, partially, or dependent on stakeholder confirmation? |
TenantShield uses Microsoft’s current names for the services and signals being evaluated. Microsoft Secure Score is referenced as a Microsoft posture measurement; it is not relabeled as a TenantShield grade.
The sample report shows how evidence, context, priority, and action are connected.