First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/Free Microsoft 365 Security Assessment
Security and Protection

Free Microsoft 365 Security Assessment — Tenant Security Review

Free Microsoft 365 Security Assessment is a 3-day service for organizations with a Microsoft 365 tenant used in production. IT Partner connects to the tenant and uses tools such as Secure Score, Microsoft Entra ID, and PowerShell to create a security report that reflects the current security state and includes a prioritized list of recommendations to increase data security, control, protection, and Secure Score. The assessment also includes a quote if the client would like IT Partner to work on tenant hardening.

Timeline 3 daysService owner Dan ApplebyOffice 365microsoft 365

Free assessment

Request your free Microsoft 365 security assessment

Two fields. No calendar. We take it from there.

Enter the work email you want the reply sent to.
Enter a domain like contoso.com or contoso.onmicrosoft.com.

Free. A human replies the same business day. Your address never joins a marketing list.

Prefer to talk? Book 30 minutes with Mike

Request received.

Your free security assessment for your tenant is in the queue.

What happens next: a person — not an autoresponder — replies to the same business day with your results and anything worth fixing. Your address never joins a marketing list.

Want to walk through the results live? Book 30 minutes with Mike

What this engagement is

Small- and medium-sized businesses face many of the same cyberattacks and data-regulation pressures as larger companies, often without the same IT department or budget. Users face threats such as credential theft, malware, phishing, and infrastructure attacks. Cloud-migrated organizations can be especially vulnerable because documents, historic emails, and company information may be available at any time, from any device, and from any place. This assessment helps the client evaluate the current security state of its Microsoft 365 tenant and identify high-priority security concerns. IT Partner collects and analyzes Microsoft 365 tenant data using tools such as Secure Score, Microsoft Entra ID, and PowerShell, then provides a security report with prioritized recommendations. Some platform security capabilities are free, such as a basic level of MFA, while some may require an additional license.

Success criteria

01Your current Microsoft Secure Score, with context on what it measures
02List of potential vulnerabilities sorted in order of importance
03Recommendation on how to increase your protection and Secure Score
04Quote for IT Partner's services in case you'd like us to work on your tenant hardening

What you receive

Security report based on Microsoft 365 data collection and analysis
Prioritized list of potential vulnerabilities
Recommendations on how to increase protection and Secure Score
Actionable security roadmap
Quote for IT Partner's services in case you'd like IT Partner to work on your tenant hardening

How the work unfolds

Kickoff meeting

Introduce the team, confirm scope, and schedule temporary global admin access.

Identify security objectives

Agree on the security objectives and priorities that matter most to your organization.

Assess your current security state and identify security gaps

Collect and analyze tenant security data with Secure Score, Microsoft Entra ID, and PowerShell to identify gaps.

Provide recommendations and best practices

Translate the findings into prioritized recommendations and Microsoft best practices.

Create an actionable security roadmap

Assemble the recommendations into an actionable security roadmap for your tenant.

Meeting to review the deliverables

Walk through the report, vulnerabilities, roadmap, and optional hardening quote together.

Prerequisites

You must have a Microsoft 365 tenant used in a production environment
You must have a global admin access to your Microsoft 365 tenant

Who does what

IT Partner

  • Microsoft 365 data collection and analysis
  • Building of a security report

Your team

  • Providing a dedicated point of contact responsible for working with IT Partner
  • Coordinating any outside vendor resources and schedules (if needed)
  • Setting up temporary access with global admin permissions

What's not included

Initial setup and configuration of any Microsoft 365 services
Gathering of any data located outside of Microsoft 365 tenant (for example, desktop computers, servers, and active networking equipment are outside the scope)

Limitations & technical notes

!The plan may vary depending on your needs.
!Some security tools and services are free, like a basic level of MFA. Some will require an additional license.

Frequently asked questions

What is the Free Microsoft 365 Security Assessment?

The Free Microsoft 365 Security Assessment is a 3-day service for organizations using a Microsoft 365 tenant in production. IT Partner connects to the tenant and uses Microsoft 365 security data, including tools such as Secure Score, Microsoft Entra ID, and PowerShell, to assess the current security state and produce prioritized recommendations.

Who is this Microsoft 365 Security Assessment designed for?

This assessment is designed for small and medium-sized organizations that use Microsoft 365 in production and want to understand their tenant’s security posture. It is especially relevant for businesses concerned about credential theft, phishing, malware, cloud access risks, and Microsoft 365 data protection.

What deliverables will we receive after the assessment?

You will receive a security report based on Microsoft 365 data collection and analysis, a prioritized list of potential vulnerabilities, recommendations to increase protection and Secure Score, and an actionable security roadmap. The deliverables also include a quote for IT Partner’s services if you want help implementing tenant hardening.

How long does the Microsoft 365 Security Assessment take?

The listed project duration is 3 days. Within that window, the hands-on assessment work is compact — a kickoff, data collection and analysis in your tenant, and a closing meeting to review the deliverables.

What prerequisites are required before the assessment can start?

You must have a Microsoft 365 tenant used in a production environment. You must also be able to provide temporary access with global admin permissions so IT Partner can collect and analyze the tenant security data required for the assessment.

Why does IT Partner need global admin access?

Global admin access is required because the assessment reviews Microsoft 365 tenant security settings and data that may not be visible with lower-permission roles. The client is responsible for setting up temporary global admin access for the engagement.

Does the assessment include fixing security issues or hardening the tenant?

No, tenant hardening and implementation of recommended changes are not included in the assessment scope. The service provides findings, recommendations, an actionable roadmap, and a quote if you would like IT Partner to perform the hardening work afterward.

What is not included in the Microsoft 365 Security Assessment?

The assessment does not include initial setup or configuration of Microsoft 365 services. It also does not include gathering or assessing data outside the Microsoft 365 tenant, such as desktop computers, servers, or active networking equipment.

Is the Microsoft 365 Security Assessment really free?

Yes — the assessment is provided free of charge to IT Partner clients. Follow-on tenant hardening work is separate and is quoted after the assessment.

What is Secure Score, and how is it used in the assessment?

Microsoft Secure Score is used as one of the tools to evaluate the tenant’s security posture. The assessment includes your current Secure Score-related findings and recommendations intended to increase protection and improve Secure Score where appropriate.

What are the client’s responsibilities during the assessment?

The client must provide a dedicated point of contact to work with IT Partner, coordinate any outside vendor resources or schedules if needed, and set up temporary global admin access. These responsibilities help IT Partner complete the data collection, analysis, and deliverable review efficiently within the planned engagement.

What happens after the assessment is completed?

After the assessment, IT Partner reviews the deliverables with you, including the security report, prioritized vulnerabilities, recommendations, and actionable roadmap. If you want IT Partner to implement the recommended hardening, the assessment includes a quote for those follow-on services.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

Free, Clients Only
3 days
Book a meeting