Microsoft 365 Security Posture: Assess, Harden and Hold
We measure what your Microsoft 365 and Entra tenant allows today, agree where it should be, and close the gap in stages you approve.
Measured, agreed, hardened, then held
In short: We assess your Microsoft 365 and Entra tenant against recognised baselines, agree a target state with you, harden it in a risk-ordered sequence and then watch for drift. Right for organisations whose tenant has grown for years without a formal security review, or who need evidence for Cyber Essentials, ISO 27001 or a client questionnaire.
Many Microsoft 365 tenants were set up before today's secure defaults existed. Nothing was done wrong at the time. The defaults moved on, the tenant stayed where it was, and that gap is where identity attacks find their way in.
Who this is for
The problem
Microsoft's Digital Defense Report 2025 found that more than 97% of identity attacks are password attacks, and a tenant with gaps in MFA or legacy authentication still switched on is exposed to exactly those. The gaps rarely come from one decision. They come from years of sensible exceptions, a supplier's admin account nobody removed, and defaults that changed on Microsoft's side after the tenant was built, so nobody can say with confidence what the tenant allows today.
What we would do
If your tenant has run for more than a couple of years without a structured review, start with an assessment against a recognised baseline and fix identity first: MFA for everyone, legacy authentication blocked, and fewer standing administrators. Those are the controls assessors and insurers ask about first.
- If you are a very small organisation on Microsoft's security defaults with no exceptions, you may not need this yet: security defaults already require MFA and block legacy authentication.
- If you already run Conditional Access with a named owner, regular reviews and change control, drift monitoring on its own may be all you need rather than a full assessment.
- If the immediate driver is certification, start with our Cyber Essentials service, which covers the tenant controls and the wider scope.
When we are not the answer: If you want a score pushed up as fast as possible regardless of what it breaks, we are the wrong provider. We stage every change and wait for your approval, which is slower than switching everything on at once and far less likely to lock your finance team out on a Monday.
We start by measuring. We use EtherInsights, our posture tooling, together with Microsoft's open-source Zero Trust Assessment, the open-source Maester test framework and the CIS Microsoft 365 Foundations Benchmark. The assessment reads your configuration and changes nothing, and the result is a plain picture of what your tenant allows today across identity, devices, network and data.
More on how we deliver our Microsoft 365 security posture service
Then we agree a target state with you, write a plan ordered by risk, and harden in stages. Conditional Access runs in report-only mode first, two emergency access accounts are in place before any policy goes live, and every change goes through a change request you approve. After that we watch for drift, so the next well-meant exception does not quietly undo the work.
Posture assessment and drift tracking are delivered with EtherInsights from our partner EfficientEther, which keeps each finding on a timeline rather than in a one-off report.
Systech is founder-led by Ryan Mangan, a Microsoft MVP for Azure Virtual Desktop and Windows 365, a Chartered Fellow of the BCS (FBCS) and author of Packt's two-edition Mastering Azure Virtual Desktop.
Posture is one layer. Firewalls, endpoint detection, email security and backup are covered on our managed security services page, which sets out how the layers fit together.
Everything you need, managed for you
What is a Microsoft 365 security posture review?
It is a structured answer to one question: what does your Microsoft 365 and Entra tenant actually allow today, and how far is that from where it should be? Posture is the sum of the settings rather than any one product: who can sign in, from where, with what proof, who holds administrative power, and which applications can reach your data.
Microsoft describes its own Secure Score as a measurement of an organisation's security posture, and it is a useful map. Microsoft is also clear that it is not an absolute measure of how likely you are to be breached, and that not every recommendation fits every environment. So we treat it as one input, not the target.
Which baselines do we assess against?
Several, because each one sees something the others miss:
- Microsoft's Zero Trust Assessment: an open-source, read-only PowerShell module from Microsoft that checks the tenant across the Identity, Devices, Network and Data pillars
- Maester: an open-source PowerShell test framework, released under the MIT licence, running tests drawn from CIS, CISA's SCuBA baselines and EIDSCA
- The CIS Microsoft 365 Foundations Benchmark, currently version 7.0.0, the community-agreed configuration baseline for Microsoft 365
- EtherInsights, our posture tooling, which tracks findings over time and sets them alongside licensing, so we can see what you already pay for and have not switched on
None of these is a compliance certification, and passing every test is not the same as being secure. They are openly published, well-maintained measures, which means you can rerun them yourself and check our work.
What usually changes, and in what order?
Identity first, because that is where most attacks start. Microsoft states that MFA can block over 99.2% of identity-based attacks, which makes it the highest-value control in almost any tenant.
The outcomes we typically agree with customers:
- MFA for everyone, using phishing-resistant methods such as passkeys, FIDO2 security keys or Windows Hello for Business where possible
- Legacy authentication blocked, because Microsoft notes that most compromising sign-in attempts come from it and it does not support MFA
- Global Administrators reduced to fewer than five people, with just-in-time access in place of standing roles
- User consent to applications limited to verified publishers, so a convincing permission prompt cannot hand over mail and files
SMS and voice codes are better than nothing, but Microsoft describes them as prone to remote phishing attacks, so we move people off them where the device estate allows. Everything after identity, from device compliance to sharing and data protection, is ordered by risk in the plan you approve.
How do you harden a tenant without locking people out?
By sequencing and by evidence. Conditional Access policies start in report-only mode, which records who a policy would have affected without enforcing it. We review that record with you, resolve the exceptions it reveals, and only then switch the policy on.
Before any policy goes live:
- Two cloud-only emergency access accounts exist, as Microsoft recommends, kept out of the policies that could lock out everyone else
- Each change is raised as a change request and approved by you before it is scheduled
- Each change carries a written rollback step, so a problem can be reversed rather than worked around
Nobody can honestly promise zero risk of disruption on a live tenant. What this sequence does is make surprises rare, small and recoverable.
Why does posture drift, and how do we stop it?
Because a tenant is a living system. A new starter needs an exception, a supplier needs temporary admin access, Microsoft changes a default, and a year later the tenant has moved without anyone deciding it should. That is not carelessness: it is what happens when a tenant is busy doing its job.
Drift monitoring reruns the same baselines on a schedule and flags anything that has moved away from the agreed target state. When something changes, we tell you what changed, whether it matters and what we recommend, and nothing is reverted without your approval.
What evidence does this give us for Cyber Essentials and ISO 27001?
Cyber Essentials Requirements for IT Infrastructure v3.3, from April 2026, says authentication to cloud services must always use MFA, and cloud services cannot be excluded from scope. Your Microsoft 365 tenant is in scope whether or not anybody listed it.
The assessment output, the approved change requests and the drift reports together form a dated record of what was configured, when and why. That is the evidence an ISO 27001 auditor or a client security questionnaire asks for. It supports certification but cannot guarantee a pass, because that decision belongs to the assessor or auditor. We are ISO 27001 and ISO 9001 certified and hold Cyber Essentials ourselves, so we know what they look for.
Is this a one-off project or an ongoing service?
Either. Some organisations want the assessment, the plan and the hardening as a defined project, then run the tenant themselves. Others keep us on for drift monitoring, so the posture holds as people, suppliers and Microsoft's defaults change.
We scope each engagement first and then quote it, itemised, so you can see what each part covers and compare it line by line with anyone else's.
Questions we hear a lot
Will the assessment change anything in our tenant?
No. The assessment stage reads configuration and reports on it. Microsoft's Zero Trust Assessment is read-only by design, and the other tests we run read settings rather than change them. We agree the read access they need with you first, and nothing changes until you have seen the plan and approved each change request.
Is a high Microsoft Secure Score the same as being secure?
No, and Microsoft says as much. Secure Score measures posture against Microsoft's own recommendations, but Microsoft is clear that it is not an absolute measure of how likely you are to be breached, and not every recommendation fits every organisation. We use it as one input alongside CIS and Zero Trust baselines, and prioritise by real risk rather than by points.
What if a new policy locks someone out?
That is what the sequencing is for. Policies run in report-only mode first, so a would-be lockout shows up in a log rather than on a Monday morning. Two emergency access accounts sit outside the policies that could lock everyone out, and each change has a rollback step agreed in advance. The risk on a live tenant is never zero, but it becomes small and recoverable.
Does this depend on which Microsoft licences we have?
Partly. Some controls, such as Conditional Access and just-in-time administrator access, depend on your licence tier. The assessment shows what your current licences already include and which of those features are switched off. Where a control needs a licence you do not have, the plan says so and sets out the alternative, so you can decide whether the upgrade is worth it.
Will this get us through Cyber Essentials?
It closes the tenant gaps that most often cause problems, such as cloud services without MFA, and gives you dated evidence of the controls. It cannot guarantee a pass, because certification is the assessor's decision and Cyber Essentials covers more than your tenant: devices, firewalls, patching and malware protection all count. If certification is the goal, our Cyber Essentials service covers the full scope.
Our Microsoft 365 security posture service is delivered UK-wide from our office in Brough, East Yorkshire, with on-site support across the county where it helps. We work with businesses in Harrogate, Huddersfield, Scarborough, Bradford, Hull and Leeds and 6 more Yorkshire towns and cities, and remotely with clients right across the UK.
Tell us what you need
A short call to talk through how your IT works today, what your team handles, and what you need from a provider. We will tell you plainly how we would approach it.
