Microsoft 365 & Entra ID Security Assessment
A fixed-scope assessment of the Microsoft 365 tenant most organizations run their business on: identity and conditional access in Entra ID, Exchange Online and anti-phishing, SharePoint/OneDrive/Teams sharing, Defender and Purview configuration, admin roles and break-glass accounts. Measured against the CIS Microsoft 365 Foundations Benchmark and Microsoft Secure Score, delivered as a prioritized hardening plan your IT team or MSP can execute.
In scope
- Entra ID: MFA, conditional access, legacy auth, privileged roles
- Exchange Online: anti-phishing, SPF/DKIM/DMARC, mail flow rules, forwarding
- SharePoint, OneDrive and Teams external sharing and guest access
- Defender for Office 365 / Endpoint and Purview baseline
- Audit logging, alerting and break-glass account review
You receive
- CIS Microsoft 365 benchmark scorecard
- Prioritized hardening plan (quick wins / 30 / 90 days)
- Conditional access policy recommendations
- Executive summary for leadership or your cyber insurer
Tiers
Choose the depth.
Essential M365 Review
$4.5K
Single tenant up to 100 users: CIS benchmark review, Secure Score analysis and a prioritized hardening plan
- Users
- 100
- Sites
- 3
Advanced M365 & Entra Assessment
$9.5K
Up to 500 users: adds conditional access design, privileged access review, Defender and Purview configuration and a remediation workshop
- Users
- 500
- Sites
- 10
Enterprise M365 Security Program
$18K
Multi-tenant or 500+ users: adds hybrid identity (AD Connect), application consent and service principal review, and 30 days of remediation support
- Users
- 5000
- — Tenants above 5,000 users are scoped individually
Members: engagement coupons from the CISO Marketplace coupon book apply to services. There is no blanket discount.
What's inside this engagement
Phase by phase.
How a cloud & identity assessment engagement runs, what happens in each phase and what you see. Exact scope, tier and timeline are fixed in your proposal and SOW.
01Scoping & read-only access
Accounts, subscriptions and tenants in scope, with read-only audit roles set up.
You see · Read-only access for the assessment.
02Configuration & identity review
IAM, network exposure, logging, encryption and workload configuration against CIS benchmarks and provider best practice.
You see · Nothing further.
03Attack-path analysis
Misconfigurations chained into realistic paths to sensitive data or admin control.
You see · The paths that matter, not just a list.
04Reporting & remediation plan
Prioritized findings with the exact configuration change, plus quick wins.
You see · A fix plan your platform team can run.
Commercials
From first call to final report.
- 01
Scoping call
A practitioner, not a salesperson, walks through targets, constraints and what a good outcome looks like for you.
- 02
Proposal & rules of engagement
A fixed-scope proposal with tier, price and deliverables. Rules of engagement, contacts and out-of-bounds systems are agreed in writing.
- 03
Sign, then start
MSA and SOW are signed electronically and the deposit is paid. Only then does testing begin.
- 04
Execution
Testing runs to the agreed plan. Critical findings are escalated as they are found; you don't wait for the report.
- 05
Report & debrief
An executive summary plus technical findings with evidence, reproduction steps and fixes, walked through with your team.
- 06
Retest
Where the tier includes it, we verify your fixes and reissue the report, so auditors and customers see the issues closed.
Timelines are set per engagement in the SOW.
Related
DevSecOps Pipeline Testing
Comprehensive security testing integrated into your development pipeline with regular assessments.
Cloud Security Monitoring
Continuous monitoring and assessment of your cloud infrastructure security posture.
Cloud Security Posture Management
Advanced cloud security assessment and continuous monitoring implementation across multi-cloud environments, focusing on compliance, cost optimization, and security automation.
Research
Latest from the blog

identity-security · Aug 28, 2026
"No Customer Action Required": A CVSS 10.0 in Entra ID and the Disclosure Problem Nobody Has Solved
CVE-2026-69836 was a maximum-severity unauthenticated RCE in Microsoft Entra ID — the identity layer under a large share of the world's enterprises. Microsoft patched it, told customers to do nothing, and briefly flagged it as exploited before correcting the record on August 21. There was no action to take, no IOC to hunt, and no way to verify. That is the actual problem.

operations · Aug 12, 2026
421 CVEs in One Tuesday: Running Risk-Based Triage Under BOD 26-04
Microsoft shipped 421 CVEs on August Patch Tuesday, including an actively exploited afd.sys zero-day. Nobody patches 421 things in a month. CISA's BOD 26-04 already conceded the point in June with a four-variable risk model and a three-day clock for the worst tier. Here is how to run that model in a private enterprise, and why SharePoint proved that patching and remediation are not the same thing.

identity-security · Apr 25, 2026
AI Device Code Phishing: The Auth Flow That Survives MFA, Password Resets, and Your SOC
Microsoft's Defender Security Research team documented a new AI-enabled phishing campaign leveraging the OAuth device code flow to compromise organizational accounts at scale. The EvilTokens toolkit automates code generation, bypasses the standard 15-minute expiration window, and leaves tokens that survive both MFA and password resets. Here's the technical breakdown and what to do about it.
Start an engagement