Starting engagement

Microsoft 365 Security and Cost Review

A senior administrator goes through your tenant, writes down what is actually configured, and ranks what needs attention. Scope and price are agreed before anyone touches your environment.

The review answers one question: what is actually configured in your Microsoft 365 tenant right now. Not what was intended when it was set up, and not what the last person to touch it says is there. What the tenant reports today.

It exists because the same conversation keeps happening. A business with somewhere between ten and seventy-five people is running on Microsoft 365, nobody in the building is a senior Microsoft 365 administrator, and the honest answer to "who has admin rights" is that nobody is certain. That is not negligence. It is what happens when the tenant is five years old and everyone has been busy.

,

What gets examined

The same twelve areas every time, so the report can be compared against itself when you run it again in a year.

  • Global administrators and privileged roles. Who holds administrative rights, whether those accounts belong to people who still work there, and whether admin work is being done from everyday accounts.
  • Active, inactive and former employee accounts. Every account, when it last signed in, and which ones belong to people who have left. This is where the report usually starts earning its keep.
  • MFA and Conditional Access. Not whether multi-factor authentication exists, but whether it is actually enforced, for whom, and what the exclusions are. Policies that apply to nobody are common.
  • Mailbox forwarding and inbox rules. Forwarding to outside addresses, and the quiet inbox rules that move messages to a folder nobody reads. Both are standard signs of a compromised mailbox.
  • Shared mailboxes, aliases and distribution groups. What exists, who can reach each one, and whether an address the business relies on is really a person's private mailbox.
  • Third party and OAuth application access. Which applications have been granted access to your data, by whom, and with what permissions. Consent granted once in 2021 is still consent today.
  • SPF, DKIM and DMARC. Whether your domain authenticates properly, whether anything can send as you, and what your published policy actually instructs receivers to do.
  • Microsoft licence allocation. What you are paying for against who works there, including licences assigned to departed staff and higher tier licences on people who do not use the features.
  • SharePoint, OneDrive and Teams external sharing. What has been shared outside the business, how much of it is still live, and whether anonymous links have accumulated.
  • Intune, Defender and device management. Which devices are enrolled and managed, which are simply signing in, and what the business could actually do if a laptop went missing tonight.
  • Retention and recovery configuration. What happens to a deleted mailbox or file, and for how long. Most owners assume Microsoft keeps everything forever. It does not.
  • Administrative ownership and documentation. Whether the business, rather than a person or a former supplier, holds the tenant, the domain and the recovery details, and whether any of it is written down.
,

What you receive

A written report you can hand to somebody else, not a slide deck and not a portal login.

Findings ranked by priority

Every finding is classified critical, high, medium or informational, with the reasoning attached. Critical means it should be dealt with this week. Informational means it is worth knowing and does not need a decision.

Immediate actions

The short list of things that should change now, separated out so they do not get lost behind the longer term work. If anything urgent appears while the review is still running, you hear about it then rather than at the end.

A remediation roadmap

The rest of the work in a sensible order, with the dependencies made clear. Some of it is an hour. Some of it needs a conversation with your team about how people actually work before it can be safely changed.

A conversation about the findings

We go through the report together. This is where the "why is that a problem" questions get answered, and where you tell us which of the recommendations do not fit how the business runs.

An implementation proposal, if you want one

Optional and priced separately after the review, because pricing remediation before seeing the tenant is guesswork.

,

How the engagement runs

  1. A short conversation first

    What prompted the question, roughly how many people use Microsoft 365, and whether anything specific has already gone wrong. Fifteen minutes is usually enough.

  2. Scope and price agreed in writing

    Fixed scope and price agreed before access. You know what is included and what it costs before anyone signs in to anything.

  3. Read access arranged

    You create the account, you control it, and you can remove it when the review is delivered.

  4. The review itself

    The twelve areas above, working through the tenant and writing down what is there. Anything urgent is reported the day it is found.

  5. Findings delivered and discussed

    The written report, then a conversation about it. You keep the report either way.

  6. Your decision on what happens next

    Fix it yourself, hand it to your existing IT people, or ask us for a remediation proposal. All three are normal.

,

Who this is for

  • Businesses of roughly ten to seventy-five people running on Microsoft 365.
  • No senior Microsoft 365 administrator inside the business.
  • A tenant that has been running for a few years and has changed hands at least once.
  • Somebody has asked a question you cannot currently answer, such as who has admin rights.
  • You are filling in a security questionnaire and want to know the real answers first.

When this is not the right fit

  • You need a penetration test or a formal compliance audit signed by an assessor.
  • You want a twenty-four hour help desk, a security operations centre or managed detection and response.
  • You are on Google Workspace rather than Microsoft 365. We support Workspace, but this particular review is Microsoft 365.
  • You want the cheapest possible look rather than a written record you can act on.
,
,

What Tech True Point can help with

If you decide to act on the findings, the same person who wrote them does the work:

  • Remediating what the review found, in the order it needs doing.
  • Ongoing Microsoft 365 administration, so the tenant does not drift back within a year.
  • Joiner and leaver handling, which is what stops the former employee finding recurring.
  • Device management with Intune and Autopilot where laptops are currently unmanaged.
  • Mail authentication and deliverability if the review found problems with SPF, DKIM or DMARC.
,

A sample of what the findings look like

This is a sample, not a customer. No business is described here, and nothing on this page is drawn from a real engagement. It is here so you can see the shape of the report before you commit to anything.

How findings are written

Each one names the setting, what it is now, why it matters, and what we would change. For example: Critical. Two accounts hold global administrator and have not signed in for over a year. Both belong to people no longer with the business. Recommendation: block sign-in, revoke sessions, reassign anything owned by those accounts, then remove the roles.

Example categories, ranked

Critical: a former employee who can still sign in, an administrator without MFA, mail forwarding to an outside address that nobody set up deliberately.

High: MFA enforced for most people but excluded for several, anonymous sharing links that never expire, unmanaged laptops holding company data.

Medium: licences assigned to people who left, a shared mailbox that is really one person's account, application consent nobody remembers granting.

Informational: retention set to the default nobody chose, no written record of who holds what.

Example remediation plan, sanitized

Week one: block the two dormant admin accounts and revoke their sessions. Remove the external forwarding rule. Enforce MFA on every administrative account.

Week two: close the MFA exclusions one team at a time, starting with anyone who touches money. Review sharing links older than a year.

Then: release licences in the safe order, enrol the unmanaged laptops, and write the environment down.

Your report will not look like this one, because your tenant is not this tenant. The structure is what stays the same.

,

What usually happens next

Most findings become one of four pieces of work: remediation of what was found, tenant takeover where ownership turned out to be the real problem, Intune and Autopilot where devices are unmanaged, or a licence audit acted on properly so the saving reaches the invoice.

If the review was prompted by an insurance questionnaire, the specific answers those forms want are set out in the controls insurers ask about, and the ownership question behind most of them is who owns your admin account.

,

If somebody else is bringing us in

Agencies, repair shops, phone providers and consultants refer this work in when a customer's tenant is outside what they do. The customer relationship stays with them. How that works is on the partners page.

,

Common questions

What access do you need to run the review?

Read access to the tenant is enough for most of it. A global reader role, or a global admin account if the reporting we need is not exposed to reader, plus a short conversation about who works there and what each shared mailbox is for.

The scope and the price are agreed before any access is granted, and the account you create for us can be removed the day the review is delivered. If you would rather we work in a screen share while you hold the keyboard, that also works and takes longer.

How long does it take?

The technical work is usually a few days once access is in place. What sets the calendar is the conversation at the end: the findings are worth going through together rather than emailing over and hoping the important parts get read.

If something genuinely urgent turns up on the first day, such as a former employee who can still sign in, you hear about it that day rather than in the report.

Do we have to buy the remediation from you?

No. The findings are yours, written plainly enough that another administrator can act on them. Some businesses hand the report to whoever already looks after their IT, and that is a reasonable outcome.

If you would rather we did the work, the remediation is quoted separately once you have seen what is actually there, which is the only honest moment to price it.

Is this a penetration test or a compliance audit?

Neither. It is a configuration review of a Microsoft 365 tenant: who has access, how sign-in is protected, where mail is going, what devices are managed, and what you are paying for.

A penetration test attacks a system to find exploitable weaknesses. A compliance audit measures you against a named standard and is signed by an assessor. If either of those is what you need, you need a different firm, and we will say so rather than sell you this instead.

We think our setup is fine. Is there any point?

Sometimes there is not, and that is a fine result to pay for once. The reviews that find least are the ones where somebody senior has been paying attention, and the report then says so in writing, which is useful when an insurer or a customer asks.

The reviews that find most are the ones where the tenant was set up years ago by somebody who has since left, and nobody has opened the admin centre since. If that sounds like yours, the licensing findings alone often cover the cost.

,
Get a Quote

Start with the review

Tell us roughly how many people use Microsoft 365 and what prompted the question. We will confirm the scope and the price in writing before asking for any access.

Call now Request a quote