Skip to content

Microsoft 365 security assessment

Find out how secure your Microsoft 365 tenant is, from evidence.

Tenants grow one project at a time, and few people can say how secure theirs is overall. In two to three weeks we review identity, devices, email, data and the Microsoft security tools you own, and give you a ranked plan to fix what matters.

Empty open-plan office at dusk, with windows looking over a river city.

What we examine

  • Entra ID: Conditional Access, MFA methods, legacy authentication, privileged roles and break-glass accounts
  • App registrations, enterprise apps and consented permissions
  • Microsoft Defender XDR coverage and configuration across endpoints, email, identity and cloud apps
  • Intune compliance, configuration and update policies
  • Exchange Online protection, mail flow rules and forwarding
  • SharePoint, OneDrive and Teams sharing and guest access
  • Purview labels, DLP, retention and audit
  • Licences against the controls in use
Sample layout of an Infrastructure Review report: a ranked findings table with priority markers, and behind it a page with an architecture diagram and a numbered sequence of actions.
Sample layout.

What you receive

  • Findings ranked by risk, each with the evidence and the fix
  • An Essential Eight mapping for the controls Microsoft 365 provides
  • A remediation plan, sequenced and sized
  • Licence findings: gaps and waste
  • A one-page summary for leadership

What we need from you

  • Global Reader and Security Reader access to the tenant
  • About two hours of your team's time across a kick-off and the readout

How it runs

  1. Scoping: the tenant, the questions and who needs the answer.
  2. Review: configuration, logs and settings examined with read-only access.
  3. Readout: findings and the plan walked through with your team.

Questions buyers ask

Will you change anything in our tenant?

No. The review uses read-only roles. Fixes happen afterwards, through your change process.

How is this different from Secure Score?

Secure Score lists Microsoft's recommendations. The assessment tests what matters for your organisation, explains the risk in context and turns it into a plan.

What happens next?

North Ark can deliver the fixes as projects, such as identity, Defender or Purview, and then keep the tenant in shape under Managed Microsoft 365 and security.

Does it cover the Essential Eight?

It maps the Microsoft 365 controls to the Essential Eight. For a full maturity assessment across all systems, the Essential Eight assessment is the right choice.

Can we use the results with another provider?

Yes. The findings and plan are yours.

Start a conversation

Get an evidence-based view of your tenant.

Tell us what prompted the question.

Talk to an Engineer