Microsoft 365 Security Posture: Assess, Harden and Hold
We measure what your Microsoft 365 and Entra tenant allows today, agree where it should be, and close the gap in stages you approve.
Checked 4 October 2026. Built from the full service page.
In short: We assess your Microsoft 365 and Entra tenant against recognised baselines, agree a target state with you, harden it in a risk-ordered sequence and then watch for drift. Right for organisations whose tenant has grown for years without a formal security review, or who need evidence for Cyber Essentials, ISO 27001 or a client questionnaire.
Who this is for
The problem
Microsoft's Digital Defense Report 2025 found that more than 97% of identity attacks are password attacks, and a tenant with gaps in MFA or legacy authentication still switched on is exposed to exactly those.
What we would do
If your tenant has run for more than a couple of years without a structured review, start with an assessment against a recognised baseline and fix identity first: MFA for everyone, legacy authentication blocked, and fewer standing administrators. Those are the controls assessors and insurers ask about first.
- If you are a very small organisation on Microsoft's security defaults with no exceptions, you may not need this yet: security defaults already require MFA and block legacy authentication.
- If you already run Conditional Access with a named owner, regular reviews and change control, drift monitoring on its own may be all you need rather than a full assessment.
- If the immediate driver is certification, start with our Cyber Essentials service, which covers the tenant controls and the wider scope.
When we are not the answer: If you want a score pushed up as fast as possible regardless of what it breaks, we are the wrong provider. We stage every change and wait for your approval, which is slower than switching everything on at once and far less likely to lock your finance team out on a Monday.
What is included
- Assessment against Microsoft's Zero Trust Assessment, Maester tests and the CIS Microsoft 365 Foundations Benchmark
- A target state agreed with you, not imposed from a checklist
- A risk-ordered remediation plan, with identity first
- Conditional Access staged in report-only mode before anything enforces
- Two emergency access accounts in place before any policy goes live
- Every change approved by you through a change request
- Ongoing drift monitoring, so later changes do not undo the work
- Evidence for Cyber Essentials, ISO 27001 and client security questionnaires
What the last 12 months looked like
What it costs
Scoped and quoted against your estate rather than sold from a rate card. We price what you already run, including the parts that are working and do not need replacing, and the quote itemises what is included so it can be compared line by line with anyone else’s. Managed IT support starts at £40 per user, per month if that is the wider question.
Three questions people ask
Will the assessment change anything in our tenant?
No. The assessment stage reads configuration and reports on it. Microsoft's Zero Trust Assessment is read-only by design, and the other tests we run read settings rather than change them.
Is a high Microsoft Secure Score the same as being secure?
No, and Microsoft says as much. Secure Score measures posture against Microsoft's own recommendations, but Microsoft is clear that it is not an absolute measure of how likely you are to be breached, and not every recommendation fits every organisation.
What if a new policy locks someone out?
That is what the sequencing is for. Policies run in report-only mode first, so a would-be lockout shows up in a log rather than on a Monday morning.
Tell us what you need
A short call to talk through how your IT works today, what your team handles, and what you need from a provider. We will tell you plainly how we would approach it.
Prefer to talk now? Call us on +44 (0)1482 770583.
