// MICROSOFT 365 SECURITY REVIEW · HANS STUDY · ONTARIO, CANADA
Microsoft 365 security review
A tenant that's accumulated two years of guest accounts, a conditional access policy nobody has revisited since it was set up, and legacy authentication left on for one app that supposedly needed it. This review reads the tenant as it stands today and hands back what to fix, in order.
What it covers
Entra ID conditional access and MFA coverage, legacy authentication, guest and external user access, admin role assignment and privileged account hygiene, mail flow rules and anti-phishing configuration, Defender for Office 365 settings where licensed, SharePoint and OneDrive external sharing defaults, and audit logging and retention.
What you receive
- A findings report ranked by consequence, covering identity, mail, and admin configuration
- A prioritized list of changes, separating what's safe to apply immediately from what needs a change window
- A short conditional access baseline to configure against going forward
Questions
What does a Microsoft 365 security review check?
Entra ID conditional access and MFA coverage, legacy authentication, guest and external user access, admin role assignment, mail flow rules and anti-phishing configuration, Defender for Office 365 settings where licensed, SharePoint and OneDrive external sharing defaults, and audit logging and retention.
What do I get back from the review?
A findings report ranked by consequence, covering identity, mail, and admin configuration. It comes with a prioritized list of changes, separating what's safe to apply immediately from what needs a change window, and a short conditional access baseline.
Does it cover guest accounts and external sharing?
Yes. Guest and external user access, SharePoint and OneDrive external sharing defaults, and privileged account hygiene are all in scope.
Can the review be done remotely?
Yes. It's delivered remotely, or through the DHD, a remote access device shipped to site.
Does it cover SPF, DKIM, and DMARC?
Mail flow rules and anti-phishing configuration are in scope. Moving a domain's SPF, DKIM, and DMARC to quarantine is a separate service, email domain hardening.
How is the review priced?
Bring a rough user count to a scoping call, which confirms the scope for your tenant. A written quote comes before any work starts.
Book a scoping call
Bring a rough user count and a short call confirms the scope for your tenant.
Delivered remotely, or through the DHD, a remote access device shipped to site.