Core service · Microsoft 365 Security Assessment

Microsoft 365 Security Assessment

Identify security gaps across identity, devices, email, applications, collaboration, and Microsoft security controls, then receive a prioritized plan showing what to fix first.

From $3,500
The outcome

One risk story. Two useful levels of detail.

Leadership receives a concise view of exposure, priorities, and decisions. IT receives evidence, affected controls, recommended actions, dependencies, and implementation considerations.

  • Executive risk narrative and posture summary
  • Technical findings with supporting evidence
  • Prioritized action register
  • Stakeholder readout and question session
ILLUSTRATIVE DELIVERABLE

Decision-ready assessment

What matters nowImmediate
What depends on policyPlanned
What can be acceptedDocumented
What needs validationAssigned
Scope

More than Microsoft Secure Score—and no padded checklist.

The control library spans more than 400 checks. Only controls relevant to your licensed services and operating context are treated as applicable. Microsoft Secure Score is treated as one posture signal, not a substitute for business context or analyst validation.

Microsoft Entra ID

Microsoft Entra roles, authentication methods, multifactor authentication (MFA) registration, Conditional Access, passkeys (FIDO2), guest users, and user and sign-in risk.

Exchange Online

Built-in security features for cloud mailboxes, Microsoft Defender for Office 365 where licensed, mail flow, forwarding, mailbox auditing, and email authentication.

Collaboration & data

Teams, SharePoint, OneDrive, external sharing, guest controls, link defaults, and relevant information-protection signals.

Applications

Enterprise applications, consent posture, delegated access, service principals, and high-impact permission paths.

Devices

Microsoft Intune device-management and compliance signals where licensed and in use.

Detection & audit

Microsoft Defender XDR alerts where licensed, audit availability, log coverage, investigation readiness, and operational ownership.

Engagement flow

Controlled access. Visible reasoning. Practical handoff.

01

Scope

Confirm the business context, tenant landscape, licenses, known constraints, and evidence plan.

02

Assess

Evaluate applicable controls, identify gaps, and retain the evidence needed to support conclusions.

03

Validate

Review high-impact observations, account for compensating controls, and resolve ambiguity.

04

Read out

Present the risk narrative and agree on owners, sequencing, and next decisions.

Included

An assessment your team can use.

  • Applicable controls selected from a 400+ Microsoft 365 control library
  • Analyst validation of material findings
  • Executive and technical report
  • Prioritized action register
  • Stakeholder readout

Important boundary

The assessment does not include implementation. This keeps assessment conclusions separate from delivery scope.

If you want help making changes, a Remediation Sprint is proposed separately with named changes, safeguards, responsibilities, and acceptance criteria.

Learn about Remediation Sprints →

Good fit

When the Security Assessment makes sense.

  • Your IT team owns Microsoft 365 but lacks time for an independent deep review.
  • Leadership wants a defensible view of risk and investment priorities.
  • You are preparing for a customer review, insurance renewal, board discussion, audit, or major Microsoft 365 change.
  • You need an action plan before asking a provider to implement changes.
Not a compliance certification: The assessment may map observations to common security practices, but it does not certify compliance, guarantee security, or replace legal, audit, or penetration-testing work.
Evidence collection

Read-only access, defined before work begins.

The exact evidence plan depends on the agreed scope and licensed Microsoft services. Assessment work uses read-only collection and review. TenantShield does not need tenant access for the first conversation and does not ask you to send credentials, tokens, or tenant exports through the website.

Review permissions and data-handling boundaries

Examples of evidence reviewed

  • Privileged and directory role assignments
  • Authentication-method and MFA registration signals
  • Conditional Access policy configuration and coverage
  • Enterprise application permissions and consent posture
  • Exchange, collaboration, device, and security settings in scope
  • Supporting operational procedures where configuration alone is insufficient
Fictional example finding

See the evidence, impact, action, and owner together.

IDENTITY · PRIVILEGED ACCESS

Privileged authentication coverage is inconsistent

High
Evidence
Illustrative role, authentication-method, and Conditional Access review found privileged identities outside the strongest policy coverage.
Business impact
A compromised administrator could provide broad access to Microsoft 365 data and security controls.
Recommended action
Require phishing-resistant authentication for privileged access while preserving and testing controlled emergency access.
Effort and ownership
Moderate · Identity lead · Validate in report-only mode before enforcement.
Pricing

From $3,500

Final scope and fixed pricing are confirmed before TenantShield requests tenant access.

  • Microsoft 365 security control review
  • Analyst validation
  • Executive security summary
  • Technical findings register
  • Prioritized remediation roadmap
  • Stakeholder findings readout

Fixed scope before access. No open-ended hourly engagement.

FAQ

Microsoft 365 assessment questions.

How is this different from a Microsoft 365 security audit?

The assessment is the proactive, tenant-wide service for identifying gaps and prioritizing remediation. TenantShield uses the audit page for evidence-led reviews prompted by a customer, insurer, board, or internal-audit request. Neither service is a financial audit, attestation, or certification.

Why is Microsoft Secure Score not enough?

Secure Score can identify recommended configurations. It does not validate all relevant evidence, account for every compensating control or dependency, or decide which changes matter most for your organization.

How long does the assessment take?

Timing is confirmed during scoping because it depends on tenant complexity, licensed services, evidence availability, and stakeholder schedules. TenantShield does not publish a universal timeline that may not apply to your environment.

Does the assessment include Microsoft Entra ID and Microsoft Intune?

They can be included when relevant to the agreed scope and licensing. TenantShield also offers focused Microsoft Entra ID, Microsoft Intune, and Conditional Access assessments.

Can TenantShield help implement the recommendations?

Yes, through an optional and separately scoped Microsoft 365 hardening engagement. The assessment remains a complete standalone deliverable.

Related resources

Evaluate the approach before you contact us.

Assessment checklist

See the domains and evidence a useful review should cover.

Read the checklist

Secure Score comparison

Understand where a posture score ends and an analyst-reviewed assessment begins.

Compare the approaches

Assessment timeline

See which scope, evidence, validation, and stakeholder dependencies determine the schedule.

Plan the timeline

CIS benchmark guide

Understand how benchmark version, applicability, evidence, and accepted exceptions affect the result.

Review the CIS guide

Free security checker

Review more than 40 browser-based configuration signals with read-only permissions.

Run free security checker

Get a clear scope before access or implementation.

Bring your approximate user count, Microsoft 365 licensing, priorities, and deadline. No tenant access is needed for the first conversation.