Microsoft 365 security

Microsoft 365 security across every customer tenant

For an MSP, "Microsoft 365 security" is not one setting or one score. It is five connected domains, in every tenant you manage, changing every week. This page maps what you are accountable for and links to how SecurityScore.me covers each part.

The domains an MSP is accountable for

A Microsoft 365 tenant has several security surfaces that are administered separately but fail together. A gap in one usually shows up as an incident somewhere else.

Identity and Entra ID

Who can sign in, from where, and with what. Authentication methods and MFA enforcement, Conditional Access policies and their exclusions, privileged role assignments, guest access, and sign-in risk signals.

Identity is where most real-world compromise starts and where most posture regressions happen between reviews.

Microsoft Secure Score and configuration

Microsoft’s own weighted view of tenant configuration, plus the improvement actions behind it. Useful as a trend and a talking point, incomplete as a security measure on its own.

Defender and endpoint

Device posture, active alerts, and at-risk devices where the customer is licensed for Defender for Endpoint, so endpoint state sits next to identity and configuration rather than in a separate console.

Email, collaboration, and sharing

Exchange Online configuration, external sharing settings for SharePoint and OneDrive, and the collaboration controls that decide how far data can travel outside the organization.

Tenant administration

Admin role assignments and whether they are standing or time-bound, legacy authentication, and the tenant-level switches a hardening baseline checks. These drift quietly because each individual change looks reasonable.

Why this is hard across a portfolio

Every console is single-tenant

The Microsoft admin center, Entra, Defender, and the Secure Score page all assume you are looking at one organization. An MSP with fifty customers has fifty of each, and no screen that ranks them.

A manual review is a snapshot

Whatever you check by hand describes the tenant on the day you checked it. Without a schedule, "we reviewed that client" quietly means "we reviewed that client eight months ago".

Seeing an issue is not resolving it

Recommendations do not assign work, track completion, alert on regression, or record that the customer was told. That workflow has to live somewhere, connected to the data that produced it.

How SecurityScore.me covers it

One read-only connection per tenant
Delegated read-only Microsoft Graph consent. No endpoint agent, no write access to customer configuration.
All domains in one assessment
Identity, Secure Score, Defender, sharing, and admin configuration assessed together and expressed as severity-ranked findings.
External assets included
Customer domains and websites registered in the workspace, so posture is not cut off at the edge of the tenant.
Portfolio ranking
The organization view orders customers by open critical and high findings so effort follows risk.
Org-wide posture

Where each domain goes deeper

Security posture management

Continuous tracking, baselines, and drift detection across all of the above. See /microsoft-365-security-posture.

Microsoft Secure Score

Per-tenant Secure Score across the portfolio, with trend and regression alerting. See /microsoft-secure-score.

Entra ID security

The identity surface in detail: MFA, Conditional Access, privileged roles, and guests. See /entra-id-security.

Continuous monitoring

The schedule and alert routing that keep the picture current. See /microsoft-365-monitoring.

Related pages

Frequently asked questions

Next steps

Assess Microsoft 365 security across your customer portfolio