Transparent methodology

A repeatable control review with human judgment where it matters.

TenantShield combines a structured Microsoft 365 control library, collected evidence, analyst validation, and business context to produce priorities—not just check results.

Five stages

From environment context to owned action.

01 · SCOPE

Establish applicability

Confirm licenses, enabled services, tenant relationships, business requirements, known exceptions, and assessment boundaries.

02 · EVIDENCE

Evaluate controls

Collect and review the configuration and operational evidence available for each applicable control.

03 · VALIDATE

Resolve context

Check material observations against compensating controls, dependencies, stakeholder intent, and evidence quality.

04 · PRIORITIZE

Rank real work

Consider likely impact, exposure, exploitability, breadth, business dependency, change risk, and effort.

05 · COMMUNICATE

Build the action register

Connect each priority to evidence, an accountable owner, recommended action, dependency, and validation step.

Control domains

Coverage follows the Microsoft 365 services in use.

The library contains more than 400 controls, but a larger raw count is not the objective. Applicability and evidence quality are recorded so excluded controls do not distort the result.

Identity

Microsoft Entra authentication, Conditional Access, privileged roles, guest users, and user and sign-in risk.

Messaging

Exchange Online, built-in security features for cloud mailboxes, Microsoft Defender for Office 365 where licensed, mail flow, auditing, forwarding, and email authentication.

Collaboration

Microsoft Teams, SharePoint Online, OneDrive, sharing, guest users, and governance settings.

Applications

Consent, permissions, enterprise applications, and service principals.

Devices

Microsoft Intune device management, configuration, and compliance signals where applicable.

Data protection

Relevant Microsoft Purview retention, sensitivity labeling, and data loss prevention controls where licensed.

Audit & detection

Microsoft Defender XDR alerts where licensed, audit availability, logging, and investigation readiness.

Operations

Ownership, exception handling, access lifecycle, change control, and evidence of review.

Risk rating

Severity is not based on a failed setting alone.

A recommendation is prioritized using the evidence available at the time of review and the organization’s context.

FactorQuestion
ImpactWhat could happen to identities, data, operations, customers, or regulatory obligations?
ExposureHow broadly is the condition exposed, and which users, administrators, data, or workloads are affected?
LikelihoodHow plausible is misuse or failure given current controls and common attack paths?
CompensationDo other technical or operational controls materially reduce the risk?
Change riskWhat user impact, dependency, or service disruption could remediation create?
Evidence confidenceIs the conclusion supported directly, partially, or dependent on stakeholder confirmation?
Microsoft-aligned language

Product names follow current Microsoft documentation.

TenantShield uses Microsoft’s current names for the services and signals being evaluated. Microsoft Secure Score is referenced as a Microsoft posture measurement; it is not relabeled as a TenantShield grade.

What it is

A configuration and control assessment.

  • Point-in-time evidence review
  • Structured control coverage
  • Analyst validation
  • Contextual prioritization
  • Decision and action support
What it is not

Clear limits matter.

  • Not a penetration test
  • Not continuous threat monitoring
  • Not a legal opinion
  • Not a compliance certification
  • Not a guarantee against compromise

See the methodology in a practical deliverable.

The sample report shows how evidence, context, priority, and action are connected.