Free Microsoft 365 Security Assessment — Tenant Security Review
Free Microsoft 365 Security Assessment is a 1-day service for organizations with a Microsoft 365 tenant used in production. IT Partner connects to the tenant and uses tools such as Secure Score, Azure AD, and PowerShell to create a security report that reflects the current security state and includes a prioritized list of recommendations to increase data security, control, protection, and Secure Score. The assessment also includes a quote if the client would like IT Partner to work on tenant hardening.
What this engagement is
Small- and medium-sized businesses face many of the same cyberattacks and data-regulation pressures as larger companies, often without the same IT department or budget. Users face threats such as credential theft, malware, phishing, and infrastructure attacks. Cloud-migrated organizations can be especially vulnerable because documents, historic emails, and company information may be available at any time, from any device, and from any place. This assessment helps the client evaluate the current security state of its Microsoft 365 tenant and identify high-priority security concerns. IT Partner collects and analyzes Microsoft 365 tenant data using tools such as Secure Score, Azure AD, and PowerShell, then provides a security report with prioritized recommendations. Some platform security capabilities are free, such as a basic level of MFA, while some may require an additional license. Service SKU: ITPWW305IMPOT. Duration: 1 day. Manager: Mike Mackey.
Success criteria
What you receive
How the work unfolds
Kickoff meeting
Identify security objectives
Assess your current security state and identify security gaps
Provide recommendations and best practices
Create an actionable security roadmap
Meeting to review the deliverables
Prerequisites
Who does what
IT Partner
- Microsoft 365 data collection and analysis
- Building of a security report
Your team
- Providing a dedicated point of contact responsible for working with IT Partner
- Coordinating any outside vendor resources and schedules (if needed)
- Setting up temporary access with global admin permissions
What's not included
Limitations & technical notes
Frequently asked questions
What is the Free Microsoft 365 Security Assessment?
The Free Microsoft 365 Security Assessment is a 1-day service for organizations using a Microsoft 365 tenant in production. IT Partner connects to the tenant and uses Microsoft 365 security data, including tools such as Secure Score, Azure AD, and PowerShell, to assess the current security state and produce prioritized recommendations.
Who is this Microsoft 365 Security Assessment designed for?
This assessment is designed for small and medium-sized organizations that use Microsoft 365 in production and want to understand their tenant’s security posture. It is especially relevant for businesses concerned about credential theft, phishing, malware, cloud access risks, and Microsoft 365 data protection.
What is included in the Microsoft 365 Security Assessment?
The assessment includes Microsoft 365 tenant data collection and analysis, a security report, a prioritized list of potential vulnerabilities, recommendations to increase protection and Secure Score, and an actionable security roadmap. IT Partner also provides a quote if the client wants IT Partner to perform tenant hardening after the assessment.
What deliverables will we receive after the assessment?
You will receive a security report based on Microsoft 365 data collection and analysis, a prioritized list of potential vulnerabilities, recommendations to increase protection and Secure Score, and an actionable security roadmap. The deliverables also include a quote for IT Partner’s services if you want help implementing tenant hardening.
How long does the Microsoft 365 Security Assessment take?
The assessment is planned as a 1-day engagement. The plan may vary depending on your needs, but the stated service duration is 1 day.
What happens during the assessment process?
The engagement typically includes a kickoff meeting, identification of security objectives, assessment of the current security state, identification of security gaps, recommendations and best practices, creation of an actionable roadmap, and a meeting to review deliverables. IT Partner performs Microsoft 365 data collection and analysis and then builds the security report.
What prerequisites are required before the assessment can start?
You must have a Microsoft 365 tenant used in a production environment. You must also be able to provide temporary access with global admin permissions so IT Partner can collect and analyze the tenant security data required for the assessment.
Why does IT Partner need global admin access?
Global admin access is required because the assessment reviews Microsoft 365 tenant security settings and data that may not be visible with lower-permission roles. The client is responsible for setting up temporary global admin access for the engagement.
Which Microsoft tools are used in the assessment?
IT Partner uses Microsoft 365 security and administration tools such as Secure Score, Azure AD, and PowerShell to collect and analyze tenant security data. The exact analysis is based on the current state of your Microsoft 365 tenant and the security objectives identified during the engagement.
Will the assessment cause downtime or interrupt users?
The service is described as an assessment and reporting engagement, not an implementation or configuration change project. Because IT Partner is collecting and analyzing Microsoft 365 tenant data, downtime is not part of the stated scope; however, any access or scheduling requirements should be coordinated with IT Partner before the engagement.
Does the assessment include fixing security issues or hardening the tenant?
No, tenant hardening and implementation of recommended changes are not included in the assessment scope. The service provides findings, recommendations, an actionable roadmap, and a quote if you would like IT Partner to perform the hardening work afterward.
What is not included in the Microsoft 365 Security Assessment?
The assessment does not include initial setup or configuration of Microsoft 365 services. It also does not include gathering or assessing data outside the Microsoft 365 tenant, such as desktop computers, servers, or active networking equipment.
Does the assessment review desktops, servers, or network devices?
No, the assessment is limited to data located in the Microsoft 365 tenant. Desktop computers, servers, and active networking equipment are explicitly outside the scope of this service.
Is the Microsoft 365 Security Assessment really free?
The source title is “Free Microsoft 365 Security Assessment,” but the source price field is blank. Confirm pricing with IT Partner before relying on a fixed $0 price. Any follow-on tenant hardening work is separate and is provided as a quote after the assessment.
What is Secure Score, and how is it used in the assessment?
Microsoft Secure Score is used as one of the tools to evaluate the tenant’s security posture. The assessment includes your current Secure Score-related findings and recommendations intended to increase protection and improve Secure Score where appropriate.
Will every recommendation be free to implement?
No, not every recommendation can be assumed to be free because some Microsoft security capabilities require additional licensing. The service notes that some tools and services are free, such as a basic level of MFA, while others may require an additional license.
What are the client’s responsibilities during the assessment?
The client must provide a dedicated point of contact to work with IT Partner, coordinate any outside vendor resources or schedules if needed, and set up temporary global admin access. These responsibilities help IT Partner complete the data collection, analysis, and deliverable review efficiently within the planned engagement.
What is IT Partner responsible for during the assessment?
IT Partner is responsible for Microsoft 365 data collection and analysis and for building the security report. IT Partner also provides recommendations, best practices, an actionable roadmap, and a quote for optional tenant hardening services.
What happens after the assessment is completed?
After the assessment, IT Partner reviews the deliverables with you, including the security report, prioritized vulnerabilities, recommendations, and actionable roadmap. If you want IT Partner to implement the recommended hardening, the assessment includes a quote for those follow-on services.
Can the assessment be customized to our organization’s needs?
Yes, the plan may vary depending on your needs. The engagement includes identifying security objectives, so IT Partner can align the assessment discussion and recommendations with the priorities of your Microsoft 365 environment.