Skip to content
Ventric
Foundation

What is a Microsoft 365 security assessment, and do you need one?

A straight answer to what gets checked, what you should expect to receive, and the signs that your tenant is overdue a look.

Dan KennedyCo-founderPublished 7 min read

A Microsoft 365 security assessment is a structured review of your Microsoft 365 environment against sensible security practice, producing a prioritised list of what is wrong and what to do about it. It is a configuration review, not a hacking exercise, and for most small businesses it is the single most useful piece of security work available to them.

The reason it is useful is unglamorous. Almost all of the security problems we find in SME tenants are not clever attacks. They are settings nobody ever changed.

The short answer

If you have been using Microsoft 365 for more than a couple of years, have had staff join and leave, and nobody in the business could confidently tell you who currently holds administrator rights, then yes, you need one. That describes the large majority of businesses we look at.

What an assessment actually looks at

A proper assessment covers the areas where things realistically go wrong, in roughly this order of importance.

Identity and access

Who can sign in, from where, and what happens if their password is stolen. This is where the majority of real-world compromise happens, so it is where an assessment should spend most of its attention.

  • Is multi-factor authentication enforced for everyone, including the accounts that are inconvenient?
  • How many accounts hold global administrator rights, and does each one still need it?
  • Are there any accounts belonging to people who have left?
  • Are there shared logins that multiple people use?
  • Are legacy authentication protocols still enabled, which would let an attacker bypass multi-factor entirely?

Email

Business email compromise is the most common serious incident at this size of company, and it usually leaves fingerprints in the mailbox configuration.

  • Forwarding rules sending mail to external addresses, which is a classic sign of an existing compromise
  • Whether SPF, DKIM and DMARC are configured, which affects both spoofing of your domain and your own deliverability
  • Mailbox delegation and who can send as whom
  • Whether audit logging is switched on, because without it you cannot reconstruct what happened after an incident

Files and sharing

  • Anything shared publicly with "anyone with the link", which is often a document somebody shared five years ago and forgot
  • External guests with ongoing access to SharePoint sites or Teams
  • Whether permissions follow roles or have been granted person by person until nobody can explain them

Devices and data recovery

  • Whether company data sits on personal devices with no way to remove it
  • Disk encryption on laptops
  • What your actual recovery position is if a mailbox or site is deleted or encrypted, and whether that has ever been tested

Licensing

Not security exactly, but it belongs in the same review, because the answer is frequently that you are already paying for controls you have not enabled. It is common to find a business on a licence tier that includes conditional access or device management, using neither.

What you should get at the end

This is the part worth being fussy about, because the market is full of automated scans dressed up as consultancy. A useful assessment gives you:

  • Findings specific to your tenant, with evidence. "Four accounts hold global administrator rights and two belong to former staff" is a finding. "Implement least privilege" is a slogan.
  • Priorities that distinguish urgent from untidy. A missing multi-factor policy and an inconsistent file naming convention should not appear in the same list at the same weight.
  • Business context. What the risk actually means: the likelihood, and what it would cost you in downtime, money or reputation.
  • A route to fix it, including which items you could reasonably do yourselves.
  • Honesty about limits. Anything the assessor could not verify should be stated as unverified rather than assumed fine.

If what you receive is a score out of a hundred and a generic remediation checklist, you have bought a report rather than an assessment.

Signs your tenant is overdue a look

  • Nobody can list who has administrator access without going to check
  • Microsoft 365 was set up by someone who no longer works with the business
  • Staff have joined and left and you are not certain every account was disabled
  • People share documents by making links available to anyone
  • You are being asked security questions by a customer, an insurer or a tender process
  • You are considering Copilot, which will surface anything the permissions allow it to surface
  • You have never tested whether you could actually restore a deleted mailbox

That last point about Copilot is worth dwelling on. AI assistants are extremely effective at finding documents people should not have been able to reach. Turning one on before reviewing permissions is how a quiet configuration problem becomes a visible one.

Assessment, audit or penetration test?

The terms get used loosely, and the distinction that matters is what is being examined.

  • Security assessment or audit. In practice these mean the same thing: a review of how your environment is configured. This is what almost every SME needs.
  • Penetration test. A skilled attempt to break in. Genuinely valuable, considerably more expensive, and largely wasted if you have not done the configuration work first. A penetration tester will find the missing multi-factor authentication and charge you a lot more to tell you about it.
  • Compliance audit. Assessment against a specific standard such as Cyber Essentials or ISO 27001. Useful when you need the certificate, and narrower than a general review.

Sensible order: assessment, fix what it finds, then certification or penetration testing if you need them.

What it will not tell you

An assessment reviews configuration at a point in time. It will not tell you whether you have already been compromised in a way that left no configuration trace, it will not cover systems outside Microsoft 365, and it does not stay true. Tenants drift as people join, leave and change roles, which is why this is worth repeating periodically rather than treating as a one-off.

It is also not a substitute for the boring habits: keeping devices patched, having a way to remove access quickly when someone leaves, and making sure the people in your business can recognise a convincing phishing email.

Questions about this topic

How long does a Microsoft 365 security assessment take?

Gathering the configuration data is quick, often a day or two, because most of it can be read directly from the tenant. The time goes into interpreting it against how your business actually works, and into the conversation about priorities afterwards. For a business of ten to fifty people, expect the whole thing to run over a week or two rather than months.

Will an assessment disrupt our users?

No. It is a read-only review. Nothing changes during the assessment itself, and any remediation is planned and agreed separately so you can decide what to do and when.

Do we need one if we already have an IT provider?

It is often more useful in that situation, not less. An independent review that is not carried out by the people who built the environment gives you a second opinion, and it tends to surface the things that have been quietly accepted as normal.

Need a clearer picture of your Microsoft 365 setup?

A free Microsoft 365 assessment is usually the most useful first step: an evidence-led look at security, governance and licensing, with clear priorities.