"Are we secure in Microsoft 365?" is a hard question to answer from the inside. Settings accumulate over years, admins change, and licences include features nobody has turned on. A Microsoft 365 security assessment gives you an objective answer and a plan.
This guide explains what an assessment should cover, how it is run and what you should receive at the end.
What is a Microsoft 365 security assessment?
It is a structured review of your Microsoft 365 tenant's security configuration and operations. It compares current settings with Microsoft and industry best practice, considers your licences and business risks, and identifies the gaps that matter most.
Microsoft 365 security assessment process
Illustration in progress
What does a Microsoft 365 security assessment cover?
Prioritised Microsoft 365 security roadmap
Illustration in progress
| Area | What is reviewed |
|---|---|
| Identity | MFA coverage and methods, Conditional Access, admin roles, PIM, guest access, app consent |
| Devices | Intune enrolment, compliance policies, encryption, update status, Defender onboarding |
| Email and collaboration | Anti-phishing, Safe Links/Attachments, SPF/DKIM/DMARC, external forwarding, Teams settings |
| Data | Sharing settings, sensitivity labels, DLP, retention, oversharing in SharePoint/OneDrive |
| Threat protection | Defender XDR configuration, alert handling, incident response readiness |
| Logging and monitoring | Audit logging, log retention, SIEM integration, alerting |
| Licensing | What you pay for vs what is configured |
| Operations | Who monitors, response times, documentation, change control |
How is an assessment run?
- Kick-off: agree scope, stakeholders and business priorities, and grant read-only access.
- Automated data collection: export configuration, Secure Score, sign-in and audit data.
- Manual review: expert analysis of policies, exceptions and real-world usage.
- Interviews: IT, security and business owners on processes and pain points.
- Risk analysis: rank findings by likelihood and impact.
- Roadmap and readout: present findings, quick wins and a phased, costed plan.
What deliverables should you expect?
- Executive summary with overall posture and top risks in business language
- Detailed findings, each with evidence, risk rating and remediation steps
- Licence utilisation analysis showing unused paid capabilities
- Quick wins that can be fixed in days
- Phased, costed roadmap for identity, devices, threat protection and data
- Optional compliance mapping to frameworks relevant to your industry
Is Microsoft Secure Score enough?
Secure Score is a valuable starting point. It measures configuration against Microsoft's recommendations and suggests improvements. However, it does not capture business context, exceptions that weaken policies, operational gaps such as who responds to alerts, or whether controls are actually enforced for every user. Use it as input, not the conclusion.
Use it as input, not the conclusion.
What are the most common findings?
In tenants we assess, the same issues appear frequently:
- MFA enforced, but with exclusions that quietly grew
- Legacy authentication still allowed
- Too many permanent Global Administrators
- No device compliance requirement in Conditional Access
- External sharing set to "anyone" across SharePoint
- E5 or Business Premium features paid for but not configured
- No one monitoring Defender alerts after hours
How Crozaint approaches assessments
The Start phase of Crozaint's Digital Workplace & Security engagement is a 2–4 week discovery and estate assessment covering Microsoft 365, identity controls, device compliance and data governance gaps. The deliverable is a costed rollout roadmap, so you know exactly what it takes to close each gap.
Only after the assessment do you choose how to proceed: Crozaint-managed operations or self-run. Both models are reversible, and you retain ownership of your tenant and licences throughout. Crozaint brings 10+ years of managed services experience.
Common mistakes to avoid
- Treating Secure Score as the whole assessment
- Assessing configuration but not operations
- Receiving a 200-finding report with no prioritisation
- Not involving business owners in data and sharing decisions
- Running an assessment and never acting on the roadmap
Conclusion
A good Microsoft 365 security assessment tells you what is really enforced, what you already own and what to fix first. The roadmap is the real value.
Ready for an honest view of your tenant? Book a 30-minute discovery call and scope your assessment with Crozaint.

