0%

Preparing the page

Microsoft 365 Security Assessment: What It Covers and What You Should Get

What a Microsoft 365 security assessment covers, from identity and devices to data and email, how long it takes, and what deliverables you should expect.

Joseph

Joseph · Cloud Consulting

· Updated · 4 min read

Share
Placeholder illustration

"Are we secure in Microsoft 365?" is a hard question to answer from the inside. Settings accumulate over years, admins change, and licences include features nobody has turned on. A Microsoft 365 security assessment gives you an objective answer and a plan.

This guide explains what an assessment should cover, how it is run and what you should receive at the end.

What is a Microsoft 365 security assessment?

It is a structured review of your Microsoft 365 tenant's security configuration and operations. It compares current settings with Microsoft and industry best practice, considers your licences and business risks, and identifies the gaps that matter most.

Six assessment steps

What does a Microsoft 365 security assessment cover?

Sample roadmap graphic
AreaWhat is reviewed
IdentityMFA coverage and methods, Conditional Access, admin roles, PIM, guest access, app consent
DevicesIntune enrolment, compliance policies, encryption, update status, Defender onboarding
Email and collaborationAnti-phishing, Safe Links/Attachments, SPF/DKIM/DMARC, external forwarding, Teams settings
DataSharing settings, sensitivity labels, DLP, retention, oversharing in SharePoint/OneDrive
Threat protectionDefender XDR configuration, alert handling, incident response readiness
Logging and monitoringAudit logging, log retention, SIEM integration, alerting
LicensingWhat you pay for vs what is configured
OperationsWho monitors, response times, documentation, change control

How is an assessment run?

  1. Kick-off: agree scope, stakeholders and business priorities, and grant read-only access.
  2. Automated data collection: export configuration, Secure Score, sign-in and audit data.
  3. Manual review: expert analysis of policies, exceptions and real-world usage.
  4. Interviews: IT, security and business owners on processes and pain points.
  5. Risk analysis: rank findings by likelihood and impact.
  6. Roadmap and readout: present findings, quick wins and a phased, costed plan.

What deliverables should you expect?

  • Executive summary with overall posture and top risks in business language
  • Detailed findings, each with evidence, risk rating and remediation steps
  • Licence utilisation analysis showing unused paid capabilities
  • Quick wins that can be fixed in days
  • Phased, costed roadmap for identity, devices, threat protection and data
  • Optional compliance mapping to frameworks relevant to your industry

Is Microsoft Secure Score enough?

Secure Score is a valuable starting point. It measures configuration against Microsoft's recommendations and suggests improvements. However, it does not capture business context, exceptions that weaken policies, operational gaps such as who responds to alerts, or whether controls are actually enforced for every user. Use it as input, not the conclusion.

Use it as input, not the conclusion.

What are the most common findings?

In tenants we assess, the same issues appear frequently:

  • MFA enforced, but with exclusions that quietly grew
  • Legacy authentication still allowed
  • Too many permanent Global Administrators
  • No device compliance requirement in Conditional Access
  • External sharing set to "anyone" across SharePoint
  • E5 or Business Premium features paid for but not configured
  • No one monitoring Defender alerts after hours

How Crozaint approaches assessments

The Start phase of Crozaint's Digital Workplace & Security engagement is a 2–4 week discovery and estate assessment covering Microsoft 365, identity controls, device compliance and data governance gaps. The deliverable is a costed rollout roadmap, so you know exactly what it takes to close each gap.

Only after the assessment do you choose how to proceed: Crozaint-managed operations or self-run. Both models are reversible, and you retain ownership of your tenant and licences throughout. Crozaint brings 10+ years of managed services experience.

Common mistakes to avoid

  • Treating Secure Score as the whole assessment
  • Assessing configuration but not operations
  • Receiving a 200-finding report with no prioritisation
  • Not involving business owners in data and sharing decisions
  • Running an assessment and never acting on the roadmap

Conclusion

A good Microsoft 365 security assessment tells you what is really enforced, what you already own and what to fix first. The roadmap is the real value.

Ready for an honest view of your tenant? Book a 30-minute discovery call and scope your assessment with Crozaint.

Frequently Asked Questions

How long does a Microsoft 365 security assessment take?

A thorough assessment typically takes two to four weeks, depending on tenant size, complexity and the number of stakeholders. This includes data collection, expert review, interviews and a final readout with a prioritised roadmap. Crozaint's assessment phase runs 2–4 weeks.

What access is needed for an assessment?

Most assessments require read-only administrative access, such as Global Reader and Security Reader roles, which allow configuration and reports to be reviewed without making changes. Access is granted for the assessment period and removed afterwards. No changes are made to the tenant during assessment.

What is a good Microsoft Secure Score?

There is no universal target, because scores depend on licences and business decisions. Rather than chasing a number, focus on high-impact recommendations such as MFA, blocking legacy authentication, admin protection and device compliance. Track the trend over time alongside your own risk priorities.

Will an assessment disrupt users?

No. A security assessment is read-only and does not change settings or affect users. Any remediation is planned separately, tested in report-only or audit modes where possible, and rolled out in phases with communication to minimise disruption.

What happens after the assessment?

You receive findings and a costed roadmap. You can remediate with your own team, engage a partner to deploy the changes, or combine both. With Crozaint, you choose between managed operations or a full handover after deployment, and both options are reversible.

Joseph

Written by

Joseph

Cloud Consulting · 15 articles

Joseph has spent fifteen years at the operating end of infrastructure — from data-centre and network operations to multi-cloud consulting across AWS, Azure and GCP. He turns unreadable cloud bills into decisions teams can act on, and he knows the automation underneath them — Terraform, Ansible, Kubernetes — well enough to make the savings stick.

Nidhish JoyReviewed for technical accuracy by Nidhish Joy, Co-founder & CEO.

After the reading

Reading About Digital Workplace & Security Is the Easy Part.Doing It in Your Estate Is Ours.

Thirty minutes with the people who wrote this. We look at your setup, say what we would fix first and leave you with a plan, whether or not you go further with us.

  • A look at your estate, not a demo
  • What we would fix first, and why
  • A plan you keep, whether or not you hire us
Joseph

Talk to Joseph

Wrote this article · Cloud Consulting

Thirty minutes on your estate. Joseph looks at what you have and tells you what we would do first.

Book 30 Minutes

No deck, no pitch, no commitment.