Cybersecurity · Microsoft 365 · Active Directory

See your risks.
Prioritize the right actions.

An independent, pragmatic assessment of your Microsoft environment that turns security gaps into a clear, achievable roadmap aligned with your operations.

14+years in IT
Independentsenior external perspective
Actionablepriorities and owners
FR / ENbilingual delivery

01 — Scope

Two environments.
One attack surface.

The final scope is tailored to your architecture, priorities and existing controls. Both tracks can be delivered together or separately.

01Assessment

Microsoft 365 assessment

A structured review of identities, access, data sharing and detection controls to reduce the most likely risks.

  • Entra ID, MFA and Conditional Access
  • Privileged roles, PIM and emergency accounts
  • Enterprise applications, OAuth and consent
  • Exchange Online, anti-phishing and email authentication
  • SharePoint, OneDrive and external sharing
  • Microsoft Defender, logging and incident readiness
Explore the Microsoft 365 assessment
Guides for this serviceSMTP AUTH Basic retirement in Microsoft 365: migrate printers, apps and alerts to OAuthMicrosoft 365: why OneDrive and SharePoint are not a backupDeploy passkeys with Microsoft Entra ID without locking out usersSecuring Copilot agents and MCP servers in the enterprise: a practical guideMicrosoft Defender Advanced Hunting: 10 useful KQL queries for IT administrators
02Assessment

Active Directory assessment

An analysis of domain security posture, attack paths and legacy dependencies that may expose privileged accounts.

  • Privileged groups, Tier 0 and delegation
  • Stale accounts, service accounts and gMSA
  • Kerberos, NTLM, LDAP, SMB and legacy protocols
  • GPOs, domain controllers and operational hygiene
  • AD CS and attack paths, when present
  • Defender for Identity coverage and detection capability
Explore the Active Directory assessment
Guides for this serviceSecure Active Directory Certificate Services: detect ESC1, ESC4, ESC6 and ESC8Stale MDE devices: cleanup with PowerShell and the APIMigrate Microsoft Defender for Identity to v3.x sensors: a practical guideSMB hardening with Windows 11 24H2 and Windows Server 2025: a deployment guideKerberos and RC4 in 2026: audit Active Directory and migrate to AES without outagesActive Directory security assessment: 10 checks to prioritize

Please note: this is a posture and configuration assessment. Penetration testing or breach simulation is included only when explicitly defined in the engagement.

02 — Method

A rigorous approach,
without disrupting operations.

The analysis combines observed configurations, business context and Microsoft-recommended practices. Findings are validated before presentation.

  1. 01

    Scoping

    Objectives, context, boundaries and required access are confirmed before any collection.

  2. 02

    Controlled collection

    Temporary, read-only access is preferred, with targeted collection of relevant configurations.

  3. 03

    Risk analysis

    Findings are validated, contextualized and ranked by impact and exploitability.

  4. 04

    Readout

    Results presentation, prioritized roadmap and technical discussion with your teams.

03 — Deliverables

More than a score.
A path forward.

Each recommendation is grounded in your technical reality so the team can decide, plan and act.

01

Executive summary

A clear view of the current posture and the risks that require a management decision.

02

Technical report

Documented findings, evidence, impact, recommendations and configuration references.

03

Remediation roadmap

Actions ranked by priority, complexity and dependencies to guide the next 30, 60 and 90 days.

04

Findings workshop

A session with technical teams and decision-makers to validate the next steps.

04 — Confidentiality

Your data stays
under control.

Least privilege guides every access request.

Temporary and read-only access is preferred whenever possible.

Exports are limited to what is necessary, and their handling is agreed during scoping.

A confidentiality agreement can govern the engagement.

Next step

Want to know where
to act first?

Briefly describe your environment and what prompted the assessment. I’ll reply with the first useful questions to define a relevant scope.

Request an exploratory call