Microsoft Entra ID
Microsoft Entra roles, authentication methods, multifactor authentication (MFA) registration, Conditional Access, passkeys (FIDO2), guest users, and user and sign-in risk.
Identify security gaps across identity, devices, email, applications, collaboration, and Microsoft security controls, then receive a prioritized plan showing what to fix first.
Leadership receives a concise view of exposure, priorities, and decisions. IT receives evidence, affected controls, recommended actions, dependencies, and implementation considerations.
The control library spans more than 400 checks. Only controls relevant to your licensed services and operating context are treated as applicable. Microsoft Secure Score is treated as one posture signal, not a substitute for business context or analyst validation.
Microsoft Entra roles, authentication methods, multifactor authentication (MFA) registration, Conditional Access, passkeys (FIDO2), guest users, and user and sign-in risk.
Built-in security features for cloud mailboxes, Microsoft Defender for Office 365 where licensed, mail flow, forwarding, mailbox auditing, and email authentication.
Teams, SharePoint, OneDrive, external sharing, guest controls, link defaults, and relevant information-protection signals.
Enterprise applications, consent posture, delegated access, service principals, and high-impact permission paths.
Microsoft Intune device-management and compliance signals where licensed and in use.
Microsoft Defender XDR alerts where licensed, audit availability, log coverage, investigation readiness, and operational ownership.
Confirm the business context, tenant landscape, licenses, known constraints, and evidence plan.
Evaluate applicable controls, identify gaps, and retain the evidence needed to support conclusions.
Review high-impact observations, account for compensating controls, and resolve ambiguity.
Present the risk narrative and agree on owners, sequencing, and next decisions.
The assessment does not include implementation. This keeps assessment conclusions separate from delivery scope.
If you want help making changes, a Remediation Sprint is proposed separately with named changes, safeguards, responsibilities, and acceptance criteria.
The exact evidence plan depends on the agreed scope and licensed Microsoft services. Assessment work uses read-only collection and review. TenantShield does not need tenant access for the first conversation and does not ask you to send credentials, tokens, or tenant exports through the website.
Final scope and fixed pricing are confirmed before TenantShield requests tenant access.
Fixed scope before access. No open-ended hourly engagement.
The assessment is the proactive, tenant-wide service for identifying gaps and prioritizing remediation. TenantShield uses the audit page for evidence-led reviews prompted by a customer, insurer, board, or internal-audit request. Neither service is a financial audit, attestation, or certification.
Secure Score can identify recommended configurations. It does not validate all relevant evidence, account for every compensating control or dependency, or decide which changes matter most for your organization.
Timing is confirmed during scoping because it depends on tenant complexity, licensed services, evidence availability, and stakeholder schedules. TenantShield does not publish a universal timeline that may not apply to your environment.
They can be included when relevant to the agreed scope and licensing. TenantShield also offers focused Microsoft Entra ID, Microsoft Intune, and Conditional Access assessments.
Yes, through an optional and separately scoped Microsoft 365 hardening engagement. The assessment remains a complete standalone deliverable.
See the domains and evidence a useful review should cover.
Understand where a posture score ends and an analyst-reviewed assessment begins.
See which scope, evidence, validation, and stakeholder dependencies determine the schedule.
Understand how benchmark version, applicability, evidence, and accepted exceptions affect the result.
Prepare for a cyber insurance renewal or post-M&A assessment without overclaiming what one review proves.
Review more than 40 browser-based configuration signals with read-only permissions.
Bring your approximate user count, Microsoft 365 licensing, priorities, and deadline. No tenant access is needed for the first conversation.