Cloud Security · Service 05

Microsoft 365 Security

Tenant configuration review, Conditional Access hardening, Entra ID privilege audit. The cloud platform most UK businesses run on, secured properly.

Why this matters

A baseline is not a security configuration.

Microsoft 365 is where most UK businesses now operate: email, files, identity, collaboration. It is also a primary target for credential theft and business email compromise. Attackers don't need to compromise your network if they can simply authenticate to your tenant with credentials obtained through a phishing email or a data breach.

Microsoft enables a baseline of protection on new tenants, and that baseline is worth having. It is not the same as a configuration built around how your organisation actually works, and it is not sufficient on its own for most businesses. The security features exist in the platform, but most of them require deliberate configuration. Gaps are common, not from negligence, but from never having had an independent review.

We close those gaps. Audit, recommendations, and implementation alongside your team or handed over for them to action.

Audit coverage

What we examine in your tenant.

01

Identity and access

The most important layer. We audit multi-factor authentication enforcement including the gaps most administrators overlook: break-glass accounts, service accounts, and legacy authentication paths that bypass multi-factor authentication entirely. Conditional Access policy design, sign-in risk configuration, and privileged role assignments in Entra ID.

Multi-factor authentication gapsConditional Access designPrivileged role review
02

Email security

Microsoft Defender for Office 365 configuration, anti-phishing policies, Safe Links and Safe Attachments tuning, DomainKeys Identified Mail, Domain-based Message Authentication, and Sender Policy Framework alignment, mailbox auditing, and the tenant-level settings most administrators never touch but that have meaningful security impact.

Anti-phishing configurationEmail authentication alignmentMailbox audit logging
03

Data protection

SharePoint and OneDrive external sharing policies, sensitivity labels, data loss prevention rules, retention configuration, and external sharing exposure. Most organisations are sharing more data than they realise. We identify what's accessible to whom and whether that reflects your actual intent.

External sharing exposureData loss prevention gapsSensitivity label coverage
04

Endpoint and device security

Microsoft Intune device compliance policies, Conditional Access tied to device state, Microsoft Defender for Endpoint configuration, attack surface reduction rules, and whether your device security posture actually matches what your Conditional Access policies assume about it.

Device compliance policiesDefender for Endpoint tuningAttack surface reduction
05

Audit and detection

What is logged, where it goes, how long it's retained, who reviews it, and whether the current configuration would actually detect a compromise before significant damage occurred. Unified audit log configuration, sign-in log retention, and whether alerts are reaching someone with the context and authority to act on them.

Unified audit log coverageAlert routing and responseLog retention periods
Common findings

What we find most often.

Common issues identified during Microsoft 365 reviews.

01

Legacy authentication not blocked

Older protocols that don't support multi-factor authentication provide a route in for anyone with valid credentials. Blocking them is one of the highest-value single changes in any tenant.

02

Global admin accounts used for daily work

A phishing email landing in a global admin's inbox is a full tenant compromise. Admin accounts must be separate from day-to-day accounts and used only for administration.

03

Conditional Access exclusions that bypass protection

A single excluded user or application left over from a test months ago is an open door. We audit every exclusion in every policy.

04

SharePoint sharing set to anyone with a link

Where that setting is enabled or selected as the default, shared links provide access without authentication and can be forwarded beyond the intended recipient. Tenants are often found with years of content in this state.

05

Defender alerts with no one reading them

Endpoint protection firing alerts into a shared mailbox that nobody monitors provides the appearance of detection without the substance of it.

06

Multi-factor authentication registration unprotected

An attacker with a stolen password may be able to register their own authentication method where registration is not adequately protected through Conditional Access, trusted onboarding locations or Temporary Access Pass controls. That turns multi-factor authentication into the attacker's tool rather than yours.

What you receive

Scored, ranked, and actionable.

A full tenant audit report scored against the Microsoft Secure Score baseline and our own hardening checklist. Each finding is ranked by three dimensions: how much it reduces your real risk, how much effort it takes to implement, and whether users will notice the change.

The result is a prioritised remediation plan with the quick wins on top. We can implement the changes alongside your team, or document them clearly enough for your team or provider to action independently.

Typical engagement runs 5 to 10 working days, end to end, depending on tenant complexity. Pure audit, audit with remediation, and ongoing managed review arrangements are all available.

Book a tenant review

Useful reading

Before or after a Microsoft 365 security review, these posts are worth reading.