Assessment

Identity Security Review

Who has access to what in your environment — and does it match what they actually need? The Identity Security Review goes deep on identity and permissions in Entra ID: MFA coverage, Conditional Access, administrative roles, OAuth permissions and guest access — without covering the full Microsoft 365 surface. A faster engagement with a sharp scope, performed as an independent third party.

What the assessment covers

  • Authentication methods, MFA coverage and Security Defaults
  • Password policies, legacy protocols (IMAP/POP/SMTP) and session controls
  • Conditional Access policies and their coverage for admins, users, guests and service accounts
  • Administrative roles, least privilege and inactive users
  • OAuth permissions, App Registrations, Enterprise Apps, secrets and consent settings
  • Tenant region and data residency

What you get

  • Written report with observations, risks and recommendations
  • Prioritised by risk and practical applicability
  • A faster engagement than the full M365 assessment

Out of scope

  • Not a full M365 assessment
  • Does not cover Exchange, SharePoint, OneDrive, Teams, Intune or endpoints beyond identity-related matters

How it works

01

Free pre-analysis

We assess the scope and give you a fixed price. No obligation, no surprises.

02

Read-only data collection

Automated extracts via PowerShell and Graph — zero operational disruption.

03

Analysis & assessment

Manual specialist review with risk prioritisation and business context.

04

Report & plan

An executive summary for leadership, technical depth for your team — ready to act on.

Frequently asked questions

When should we choose the Identity Security Review over the full M365 assessment?

Choose the Identity Security Review when identity and access are your main concern, or as a focused follow-up to a QuickScan. If mail, sharing, Intune and the rest of the surface should be covered too, the full M365 assessment is the right choice.

Will the review disrupt operations?

No. All data collection is read-only via Microsoft Graph and PowerShell — nothing is changed in your environment.

First step

Ready to have your security verified?

A free, no-obligation pre-analysis. A fixed price. A concrete plan you can act on right away.

Book a free pre-analysis