Cybersecurity · Microsoft 365 · Active Directory
See your risks.
Prioritize the right actions.
An independent, pragmatic assessment of your Microsoft environment that turns security gaps into a clear, achievable roadmap aligned with your operations.
14+years in IT
Independentsenior external perspective
Actionablepriorities and owners
FR / ENbilingual delivery
01 — Scope
Two environments.
One attack surface.
The final scope is tailored to your architecture, priorities and existing controls. Both tracks can be delivered together or separately.
01Assessment
Microsoft 365 assessment
A structured review of identities, access, data sharing and detection controls to reduce the most likely risks.
- Entra ID, MFA and Conditional Access
- Privileged roles, PIM and emergency accounts
- Enterprise applications, OAuth and consent
- Exchange Online, anti-phishing and email authentication
- SharePoint, OneDrive and external sharing
- Microsoft Defender, logging and incident readiness
Explore the Microsoft 365 assessment →02Assessment
Active Directory assessment
An analysis of domain security posture, attack paths and legacy dependencies that may expose privileged accounts.
- Privileged groups, Tier 0 and delegation
- Stale accounts, service accounts and gMSA
- Kerberos, NTLM, LDAP, SMB and legacy protocols
- GPOs, domain controllers and operational hygiene
- AD CS and attack paths, when present
- Defender for Identity coverage and detection capability
Explore the Active Directory assessment →Please note: this is a posture and configuration assessment. Penetration testing or breach simulation is included only when explicitly defined in the engagement.
02 — Method
A rigorous approach,
without disrupting operations.
The analysis combines observed configurations, business context and Microsoft-recommended practices. Findings are validated before presentation.
- 01
Scoping
Objectives, context, boundaries and required access are confirmed before any collection.
- 02
Controlled collection
Temporary, read-only access is preferred, with targeted collection of relevant configurations.
- 03
Risk analysis
Findings are validated, contextualized and ranked by impact and exploitability.
- 04
Readout
Results presentation, prioritized roadmap and technical discussion with your teams.
03 — Deliverables
More than a score.
A path forward.
Each recommendation is grounded in your technical reality so the team can decide, plan and act.
01Executive summary
A clear view of the current posture and the risks that require a management decision.
02Technical report
Documented findings, evidence, impact, recommendations and configuration references.
03Remediation roadmap
Actions ranked by priority, complexity and dependencies to guide the next 30, 60 and 90 days.
04Findings workshop
A session with technical teams and decision-makers to validate the next steps.
04 — Confidentiality
Your data stays
under control.
Least privilege guides every access request.
Temporary and read-only access is preferred whenever possible.
Exports are limited to what is necessary, and their handling is agreed during scoping.
A confidentiality agreement can govern the engagement.
Next step
Want to know where
to act first?
Briefly describe your environment and what prompted the assessment. I’ll reply with the first useful questions to define a relevant scope.
Request an exploratory call→