Montréal · Remote delivery · FR / EN

Microsoft 365 and Entra ID security assessment
Identities, access and data.

Understand who can access your Microsoft 365 environment, with which privileges and protections. An independent review that turns accumulated configurations into practical security decisions.

01 — Why assess?

Is your Microsoft 365 environment actually well protected?

For businesses and IT teams that need an actionable picture, not another report sitting in a document pile.

02 — Technical scope

What gets reviewed.

Checks are tailored to the components present and agreed scope. Exclusions and visibility limitations are documented.

01

Identity and authentication

Review MFA methods, passkeys, registration and account recovery. Assess Conditional Access policy coverage or security defaults, depending on your environment.

02

Privileges and emergency access

Inventory sensitive roles, permanent assignments, emergency accounts and their monitoring. Assess PIM where available, along with separation between everyday and administrative accounts.

03

Applications and consent

Review enterprise applications, OAuth permissions and granted consent. Identify excessive access or applications without an accountable owner while considering integrations that remain in use.

04

Email and impersonation

Analyze Exchange Online protections, forwarding rules and available anti-phishing controls. Review SPF, DKIM and DMARC in the context of the services authorized to send your email.

05

Sharing and data exposure

Review SharePoint and OneDrive settings, including external sharing, anonymous links and guest access. The assessment targets agreed configurations and metadata, not systematic reading of files or mailboxes.

06

Detection and investigation

Assess Microsoft Defender coverage, accessible logs and the ability to trace suspicious activity. Visibility gaps are distinguished from configuration issues and licensing limitations.

You do not need to purchase a new licence to request an assessment. Available checks and recommendations do depend on your subscriptions: Conditional Access, PIM and Defender capabilities are not included in every plan. Prerequisites are confirmed before the engagement.

03 — Method

Validated findings.
Practical priorities.

A security score is an indicator, not a complete diagnosis. Findings are checked against your actual usage, licensing and operational constraints. Recommendations distinguish immediate improvements from changes that require a pilot, an additional capability or a management decision.

  1. 01

    Scoping

    Confirm objectives, included components, exclusions, access, constraints and scheduling before collecting any data.

  2. 02

    Controlled collection

    Collect agreed configurations and evidence with temporary, read-only access where possible. Validate tooling and collection windows with your team.

  3. 03

    Analysis and prioritization

    Cross-check results, document limitations and rank findings by impact, exposure, dependencies and remediation effort.

  4. 04

    Readout and next steps

    Present results to IT owners and decision-makers. Define actions, proposed owners and validation criteria.

04 — Deliverables

What you receive.

A report you can act on and a conversation to make it useful. The roadmap proposes sequencing; it does not promise complete remediation within 90 days.

01

Executive summary

A clear summary of priority risks, assessment limitations and decisions to make.

02

Technical report

Findings with relevant evidence, impact, recommendations and validation criteria. Checks not performed are identified.

03

Remediation roadmap

A sequence aligned with your capacity: immediate actions, pilots and work to organize over 30, 60 and 90 days.

04

Findings workshop

A discussion to understand results, review dependencies and agree on next steps.

05 — Sample deliverable

A finding, from evidence to action.

Entirely fictional, illustrative example. It describes no client, real incident or guaranteed outcome.

An enterprise application with access it no longer needs

Evidence to validate
In this fictional example, the inventory reveals an old integration with tenant-wide Mail.Read application permission, no identified owner and no documented current business need.
Potential impact
If the application's credentials are compromised, application access may expose email beyond the original requirement. Effective scope and additional controls must be verified before drawing a conclusion.
Recommendation
Assign an owner, confirm dependencies and reduce permissions to actual requirements. If the integration is abandoned, schedule its disablement and subsequent access removal after validation with the responsible teams.
Post-remediation validation
Verify remaining access, test retained integrations and document removal of unnecessary permissions. Assign an owner and a review date to remaining applications.

06 — Access and confidentiality

Collect what matters.
Respect your operations.

Prepare approximate user and tenant counts, licensing information, key integrations and existing controls. Required read access is defined during scoping; a collection process carried out by your team can be preferred.

Access is individually attributable where possible, limited to the engagement and revoked at closure. Privilege exceptions are justified before use.

Transfer, storage, retention and deletion of exports are agreed before collection. A confidentiality agreement can govern exchanges.

Collection does not include production changes or active exploitation by default. Intrusive actions or remediation require separate authorization.

07 — FAQ

Before we begin.

Does the assessment require permanent Global Administrator access?

No. Access is scoped to individual checks, using read roles and time-limited access where possible. Any check requiring additional privileges is explained and can be performed by your team. Never send passwords through the contact form.

Is this useful with Microsoft 365 Business Premium or without E5?

Yes, the scope can match your subscription. The report separates misconfigurations, unavailable controls and improvements that would require additional licensing, without treating an upgrade as automatically necessary.

Will you read our email and documents?

Collection primarily targets agreed configurations, permissions and logs. Content access is not systematic; any specific need must be justified and authorized within the scope.

Is our on-premises Active Directory included?

Hybrid dependencies are identified, but an in-depth domain review belongs to the Active Directory assessment. Both services can be coordinated under a clearly defined shared scope.

Can the engagement be remote, and how long does it take?

Work can be performed remotely when access and your organization's policies allow it. Timing is agreed after scoping, based on size, complexity and availability of data and stakeholders; no universal turnaround is promised.

Are fixes included?

The assessment provides findings and a roadmap. Implementation, pilots and post-remediation validation can be scoped as separate support. No production changes are made without explicit authorization.

Is this a penetration test or certification?

No. This is a point-in-time posture and configuration assessment, not a guarantee that no compromise exists. Active exploitation, incident response and compliance attestation are not included by default.

08 — Explore further

The topics, in practice.

These technical guides illustrate my approach. They do not replace a review of your environment.

Guides for this serviceSMTP AUTH Basic retirement in Microsoft 365: migrate printers, apps and alerts to OAuthMicrosoft 365: why OneDrive and SharePoint are not a backupDeploy passkeys with Microsoft Entra ID without locking out usersSecuring Copilot agents and MCP servers in the enterprise: a practical guideMicrosoft Defender Advanced Hunting: 10 useful KQL queries for IT administrators

Next step

Let's define a useful scope.

Briefly describe your environment and what prompted the assessment. Do not send passwords, sensitive exports or confidential data through the form.

Request a conversation