Identity and authentication
Review MFA methods, passkeys, registration and account recovery. Assess Conditional Access policy coverage or security defaults, depending on your environment.
Montréal · Remote delivery · FR / EN
Understand who can access your Microsoft 365 environment, with which privileges and protections. An independent review that turns accumulated configurations into practical security decisions.
01 — Why assess?
For businesses and IT teams that need an actionable picture, not another report sitting in a document pile.
02 — Technical scope
Checks are tailored to the components present and agreed scope. Exclusions and visibility limitations are documented.
Review MFA methods, passkeys, registration and account recovery. Assess Conditional Access policy coverage or security defaults, depending on your environment.
Inventory sensitive roles, permanent assignments, emergency accounts and their monitoring. Assess PIM where available, along with separation between everyday and administrative accounts.
Review enterprise applications, OAuth permissions and granted consent. Identify excessive access or applications without an accountable owner while considering integrations that remain in use.
Analyze Exchange Online protections, forwarding rules and available anti-phishing controls. Review SPF, DKIM and DMARC in the context of the services authorized to send your email.
Review SharePoint and OneDrive settings, including external sharing, anonymous links and guest access. The assessment targets agreed configurations and metadata, not systematic reading of files or mailboxes.
Assess Microsoft Defender coverage, accessible logs and the ability to trace suspicious activity. Visibility gaps are distinguished from configuration issues and licensing limitations.
You do not need to purchase a new licence to request an assessment. Available checks and recommendations do depend on your subscriptions: Conditional Access, PIM and Defender capabilities are not included in every plan. Prerequisites are confirmed before the engagement.
03 — Method
A security score is an indicator, not a complete diagnosis. Findings are checked against your actual usage, licensing and operational constraints. Recommendations distinguish immediate improvements from changes that require a pilot, an additional capability or a management decision.
Confirm objectives, included components, exclusions, access, constraints and scheduling before collecting any data.
Collect agreed configurations and evidence with temporary, read-only access where possible. Validate tooling and collection windows with your team.
Cross-check results, document limitations and rank findings by impact, exposure, dependencies and remediation effort.
Present results to IT owners and decision-makers. Define actions, proposed owners and validation criteria.
04 — Deliverables
A report you can act on and a conversation to make it useful. The roadmap proposes sequencing; it does not promise complete remediation within 90 days.
A clear summary of priority risks, assessment limitations and decisions to make.
Findings with relevant evidence, impact, recommendations and validation criteria. Checks not performed are identified.
A sequence aligned with your capacity: immediate actions, pilots and work to organize over 30, 60 and 90 days.
A discussion to understand results, review dependencies and agree on next steps.
05 — Sample deliverable
Entirely fictional, illustrative example. It describes no client, real incident or guaranteed outcome.
06 — Access and confidentiality
Prepare approximate user and tenant counts, licensing information, key integrations and existing controls. Required read access is defined during scoping; a collection process carried out by your team can be preferred.
Access is individually attributable where possible, limited to the engagement and revoked at closure. Privilege exceptions are justified before use.
Transfer, storage, retention and deletion of exports are agreed before collection. A confidentiality agreement can govern exchanges.
Collection does not include production changes or active exploitation by default. Intrusive actions or remediation require separate authorization.
07 — FAQ
No. Access is scoped to individual checks, using read roles and time-limited access where possible. Any check requiring additional privileges is explained and can be performed by your team. Never send passwords through the contact form.
Yes, the scope can match your subscription. The report separates misconfigurations, unavailable controls and improvements that would require additional licensing, without treating an upgrade as automatically necessary.
Collection primarily targets agreed configurations, permissions and logs. Content access is not systematic; any specific need must be justified and authorized within the scope.
Hybrid dependencies are identified, but an in-depth domain review belongs to the Active Directory assessment. Both services can be coordinated under a clearly defined shared scope.
Work can be performed remotely when access and your organization's policies allow it. Timing is agreed after scoping, based on size, complexity and availability of data and stakeholders; no universal turnaround is promised.
The assessment provides findings and a roadmap. Implementation, pilots and post-remediation validation can be scoped as separate support. No production changes are made without explicit authorization.
No. This is a point-in-time posture and configuration assessment, not a guarantee that no compromise exists. Active exploitation, incident response and compliance attestation are not included by default.
08 — Explore further
These technical guides illustrate my approach. They do not replace a review of your environment.
Next step
Briefly describe your environment and what prompted the assessment. Do not send passwords, sensitive exports or confidential data through the form.