Scope & packages
Three packages by tenant size and complexity. You receive a binding fixed-price quote for your scope.
- Cyber insurance check-up (MFA status)
- Finding active accounts of former employees
- Baseline ransomware protection report
- Management summary (plain-language PDF)
- Unused and incorrectly assigned licenses
- Everything in Essentials
- Shadow IT scan & consent phishing audit
- Conditional Access & legacy auth exposure
- Detailed CIS Benchmark gap analysis
- SKU downgrade analysis (e.g., E3 to Business Premium)
- Everything in Corporate
- Multi-domain & custom routing topology
- Privileged Identity Management (PIM) review
- Graph API permissions deep dive
- Data-driven basis for your EA/CSP renewal
Technical details
Details for technical validation.
Identities (Entra ID Security)
In-depth analysis of your identity architecture against enterprise best practices. I check for MFA bypasses, token protection and active legacy authentication (SMTP, IMAP).
- Conditional Access review
- Legacy auth exposure report
- MFA & token protection status
Policies (Zero Trust Policy Review)
In-depth review of your policy set against NIS2 and Swiss FADP (revDSG) requirements. I verify sign-in risk routing, MFA number matching and device-bound policies.
- Policy gap analysis (NIS2/FADP)
- Sign-in risk & routing topology
- Device-bound policy validation
Admin (Privilege & Admin Tiering)
Analysis of standing privileges vs. PIM. I audit enterprise applications and Graph API permissions and identify consent phishing vectors.
- Enterprise applications audit
- Graph API permissions check
- Privileged access review
Endpoints (Intune & Endpoint Baseline)
Client baseline assessment against strict CIS Benchmarks. Review of MDM/MAM configurations, attack surface reduction (ASR) rules and BitLocker compliance.
- CIS Benchmark gap analysis
- ASR rules & BitLocker status report
- Prioritized remediation backlog (CSV/JSON)
Lifecycle (Identity Lifecycle Gap Analysis)
Identification of orphaned accounts and unused licenses. I uncover fully licensed accounts of former employees and misconfigured shared mailboxes.
- Inactive user report
- Stale account export
- Shared mailbox misconfiguration check
Analytics (Graph API License Analytics)
Automated analysis of actual service usage (Exchange, Teams, SharePoint). Identification of expensive licenses whose features are barely used.
- Workload usage analytics
- Underutilized license report
- Telemetry-based recommendations
Active remediation of the identified vulnerabilities is explicitly not part of this assessment sprint. The resulting backlog serves as the basis for follow-up engineering sprints or for your internal IT to work through.
Benefits for your business
The ROI for management.
Frequently asked questions
What prerequisites must be met before the sprint starts?
The sprint is strictly timeboxed. It starts (Day 1) on exactly the day your IT has fully provided the dedicated read-only access (“Global Reader” & “Security Reader” via PIM).
Do I need Global Administrator rights for the audit?
No. I work strictly according to the principle of least privilege. Read access is fully sufficient for the automated data extraction.
How is this different from Microsoft Secure Score?
Secure Score often provides generic recommendations without context. I analyze your specific configuration in detail against strict CIS Benchmarks, uncover consent phishing risks and check MDM/MAM baselines at an enterprise level.
How long does the audit take until the final deliverable?
Once the access prerequisites are met, data extraction runs in the background for 3–5 days. After it finishes, you receive the complete management summary and the engineering backlog within 24 hours.
Read more in the knowledge article: Microsoft 365 security check: 10 points to check yourself