First page of Microsoft's 100,000-partner directory, sorted by responsiveness All 6 Microsoft Solutions Partner designations Microsoft Solutions Partner since 2006 1,100+ organizations under management
Home/Services/Microsoft 365 Advanced Security Audit Using the SCuBA Framework
Security and Protection

Microsoft 365 Advanced Security Audit Using SCuBA — Baseline Compliance Assessment

This service uses the Security Configuration Baseline Assessment (SCuBA) framework to assess a Microsoft 365 tenant against Microsoft security baselines and provide a report with findings and recommendations. It is for organizations that want to understand the current security configuration of their Microsoft 365 services and identify non-compliant settings that should be remediated.

Timeline 10 daysService owner Roman SotnikOffice 365microsoft 365

What this engagement is

The Security Configuration Baseline Assessment (SCuBA) service is a security assessment tool developed by the government agency in collaboration with Microsoft to help organizations evaluate and improve the security of their Microsoft 365 tenant. IT Partner uses SCuBA to assess the tenant configuration against Microsoft security baselines, generate a compliance report, and help the client understand the findings and recommended changes. The report may include recommendations across suite offerings such as Azure AD, Exchange, Teams, Defender, OneDrive, SharePoint, and Power Platform. Service details: SKU ITPWW140SECOT; price $1500 per project; duration 10 days; manager Roman Sotnik; date 2024-05-09; products Office 365 and microsoft 365; type Security and Protection.

Success criteria

01Current Status of Microsoft 365 Services Analyzed - Comprehensive review completed.

What you receive

SCuBA-generated report on the tenant's compliance with the Microsoft security baselines.
Report provided to the client in an easy-to-understand format.
Findings and recommendations from the SCuBA scan results.

How the work unfolds

Kickoff meeting

Kickoff meeting.

SCuBA scan of the tenant

SCuBA scan of the tenant.

Analysis of scan results and report generation

Analysis of scan results and report generation.

Reporting of findings and recommendations

Reporting of findings and recommendations.

Prerequisites

Grant access to the Microsoft 365 tenant and related permissions.
Provide a dedicated point of contact responsible for working with our team.

Who does what

IT Partner

  • Use SCuBA to generate a report on the tenant's compliance with the Microsoft security baselines.
  • Provide the report to the client in an easy-to-understand format.

Your team

  • Grant access to the Microsoft 365 tenant and related permissions.
  • Provide a dedicated point of contact responsible for working with our team.

What's not included

Implementation or remediation of recommended configuration changes unless separately agreed.
24/7 support, continuous monitoring, ongoing maintenance, managed detection and response, security operations, or recurring compliance reporting are not included by default; these are available as optional extra-cost add-ons delivered through IT Partner's NOC, third-party support partnerships, and a Microsoft Premier Support agreement.
Incident response, forensic investigation, breach containment, or malware removal.
Penetration testing, vulnerability scanning outside the SCuBA framework, phishing simulations, or red-team activities.
Purchase, provisioning, or upgrade of Microsoft 365, Microsoft Defender, Microsoft Entra, or other licenses.
Custom security architecture, policy development, end-user training, or formal change management beyond the assessment findings review.
Assessment of non-Microsoft cloud platforms, on-premises infrastructure, third-party SaaS applications, or custom applications.
Formal compliance certification, legal attestation, audit representation, or guarantee of regulatory compliance.

Frequently asked questions

What is the Microsoft 365 Advanced Security Audit using the SCuBA framework?

The Microsoft 365 Advanced Security Audit is a security assessment that uses the Security Configuration Baseline Assessment, or SCuBA, framework to evaluate a Microsoft 365 tenant against Microsoft security baselines. IT Partner uses the scan results to produce a report with findings and recommendations so the organization can understand which settings are compliant or non-compliant.

Who is this SCuBA security assessment for?

This service is for organizations that want to understand the current security configuration of their Microsoft 365 services and identify settings that should be remediated. It is relevant when an organization needs a baseline view of its Microsoft 365 tenant security posture across core Microsoft 365 services.

Which Microsoft 365 services can be covered by the SCuBA assessment?

The SCuBA-generated report may include recommendations across Microsoft 365 suite offerings such as Azure AD, Exchange, Teams, Defender, OneDrive, SharePoint, and Power Platform. The exact findings depend on the tenant configuration and the results returned by the SCuBA scan.

What deliverables are included in this service?

The deliverables include a SCuBA-generated report on the tenant’s compliance with Microsoft security baselines, an easy-to-understand version of the report for the client, and findings with recommendations based on the scan results. The service is focused on assessment, reporting, and guidance from the SCuBA results.

Does this service include remediation of non-compliant Microsoft 365 settings?

The stated scope includes scanning the tenant, analyzing results, generating the report, and reporting findings and recommendations. Remediation work is not specifically listed in the service deliverables, so any implementation of recommended changes should be confirmed separately with IT Partner.

How long does the Microsoft 365 SCuBA security audit take?

The listed duration for this service is 10 days. During that period, IT Partner runs the SCuBA assessment, analyzes the results, generates the report, and presents findings and recommendations.

How much does the SCuBA-based Microsoft 365 security audit cost?

The listed price for the Microsoft 365 Advanced Security Audit using the SCuBA framework is $1500 per project.

What is the SKU for this service?

The SKU for this service is ITPWW140SECOT. The service is categorized under Security and Protection for Office 365 and Microsoft 365.

What happens during the SCuBA audit engagement?

The engagement includes a kickoff meeting, a SCuBA scan of the Microsoft 365 tenant, analysis of the scan results and report generation, and reporting of findings and recommendations. This process is designed to give the client a clear view of the tenant’s current alignment with Microsoft security baselines.

What access does IT Partner need to perform the assessment?

The client must grant access to the Microsoft 365 tenant and provide the related permissions needed for the SCuBA scan. The exact permission details should be coordinated during kickoff because access must be sufficient to assess the relevant Microsoft 365 service configurations.

What are the client responsibilities for this service?

The client is responsible for granting access to the Microsoft 365 tenant and related permissions. The client must also provide a dedicated point of contact to work with IT Partner during the assessment.

What are IT Partner’s responsibilities during the SCuBA assessment?

IT Partner is responsible for using SCuBA to generate a report on the tenant’s compliance with Microsoft security baselines. IT Partner also provides the report to the client in an easy-to-understand format and reports the findings and recommendations.

Will the SCuBA audit cause downtime or interrupt Microsoft 365 users?

The service description identifies the work as an assessment, scan, analysis, and reporting engagement, not a production migration or configuration change project. Downtime or user impact is not listed as part of the service, but any operational concerns should be confirmed with IT Partner before the scan is scheduled.

Does the audit make changes to the Microsoft 365 tenant?

The stated service scope is to assess the tenant configuration using SCuBA and provide findings and recommendations. It does not state that IT Partner will change tenant settings as part of the engagement, so clients should not assume remediation or configuration changes are included unless separately agreed.

What does the SCuBA report show?

The report shows the tenant’s compliance with Microsoft security baselines based on SCuBA scan results. It includes findings and recommendations that help identify non-compliant Microsoft 365 settings that should be reviewed or remediated.

What is the success criterion for this service?

The stated success criterion is that the current status of Microsoft 365 services is analyzed through a comprehensive review. In practical terms, the engagement is successful when the SCuBA scan has been completed, results have been analyzed, and the client receives the report with findings and recommendations.

What happens after the final report is delivered?

After the report is delivered, the client has a documented view of Microsoft 365 security baseline compliance and recommended changes to consider. The service scope does not include post-assessment remediation or ongoing monitoring by default, so follow-up implementation, ongoing monitoring, 24/7 support, or ongoing maintenance should be discussed separately with IT Partner as optional extra-cost add-ons delivered through IT Partner's NOC, third-party support partnerships, and a Microsoft Premier Support agreement.

Is this assessment a substitute for a full security program or managed security service?

No, this service is specifically an assessment using the SCuBA framework to evaluate Microsoft 365 tenant configuration against Microsoft security baselines. It provides findings and recommendations, but the service does not include continuous monitoring, 24/7 support, ongoing maintenance, managed detection and response, or a broader security operations program by default. Those capabilities are available as optional extra-cost add-ons delivered through IT Partner's NOC, third-party support partnerships, and a Microsoft Premier Support agreement.

What information should we prepare before the kickoff meeting?

Before kickoff, the client should be ready to provide Microsoft 365 tenant access, related permissions, and a dedicated point of contact for coordination. This preparation matters because IT Partner needs tenant access to run the SCuBA scan and a client contact to resolve questions during the engagement.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$1500 per project
10 days
Book a meeting