Microsoft 365 Security Assessment
For most organisations, Microsoft 365 and Entra ID make up the most important security surface. A misconfiguration in Conditional Access, OAuth permissions or partner access can give an attacker far more reach than you expect. We review the entire surface — risk-based, read-only, and as an independent third party that also verifies what your vendor has configured.
The Microsoft 365 Security Assessment is an independent, in-depth review of your entire M365 environment: identity, mail, sharing, apps, Intune and logging — for organisations where cloud is the primary attack surface. You get a written report with an executive summary and a prioritised action plan. Typically 2–3 weeks from start to report — read-only, no operational impact, fixed price after a free pre-analysis. Unlike the Identity Security Review, it covers the full surface.
What the assessment covers
- Entra ID, MFA coverage, Conditional Access, PIM and RBAC
- Partner access (GDAP), users, guests and B2B collaboration
- Exchange Online, SharePoint and OneDrive — incl. sharing and forwarding
- OAuth permissions, App Registrations and Enterprise Apps
- Intune compliance, Defender and Secure Score
- Logging, audit, tenant region and data extracts
What you get
- Written report with an executive summary for leadership
- Technical findings detailed enough for your own team
- Action plan prioritised by risk and feasibility
- Typically 2–3 weeks from start to report
Out of scope
- Does not cover endpoints or on-premises infrastructure
- Not implementation or incident response
- Not a penetration test
- Unilite
- Cadpeople
- Kunde & Co
- Bitcoin Suisse
- Mercantec
- Dagrofa
- Laursens Realskole
- Zug Kommune
- Altid Vikar
- Adeo Datacenter
- A&O Kreston
- Numarics
- Geelmuyden Kiese
The assessment we received deserves a 10 out of 10 without hesitation.
80+ certifications — CISSP, CISM, CISA, ISO 27001 · More about Martin →
How it works
Free pre-analysis
We assess the scope and give you a fixed price. No obligation, no surprises.
Read-only data collection
Automated extracts via PowerShell and Graph — zero operational disruption.
Analysis & assessment
Manual specialist review with risk prioritisation and business context.
Report & plan
An executive summary for leadership, technical depth for your team — ready to act on.
Practicalities
Free and without obligation — we are given read access and assess the scope so that we can give you a fixed price.
Typically a kick-off meeting of about an hour plus setting up read access. We do the rest.
Read-only data collection — no changes to your systems and no operational disruption.
A written report with prioritised recommendations, data extracts in Excel where relevant — and a walkthrough of the results at both management and engineering level.
Frequently asked questions
How much of our own time is required?
Typically about an hour for a kick-off meeting plus setting up read-only access. We handle the rest.
Does the assessment require installing software?
No. Data collection uses automated, read-only extracts via PowerShell and Microsoft Graph.
Can the report support NIS2 or ISO 27001 work?
Yes. The report documents your controls and prioritised improvements, and several clients use it directly in compliance work such as ISAE 3000, NIS2 and ISO 27001.
What does a Microsoft 365 security assessment cost — and why isn't the price listed here?
Because no two companies — or system landscapes — are alike, and a fixed price list would be either too high for some or too vague for all. Instead, we always start with a free, no-obligation pre-analysis. After that you usually get a fixed price with no surprises — and where a fixed price isn’t possible, an estimate we stand behind and keep.
Ready to have your security verified by an independent third party?
A free, no-obligation pre-analysis. A fixed price. A concrete plan you can act on right away.
Get a free pre-analysis