Security assessment
Microsoft 365 security assessment for MSP customer tenants
A Microsoft 365 security assessment is a structured review of one tenant at one moment: what is configured, where the gaps are, and what to fix first. MSPs run one to onboard a customer, prepare for an audit, or answer "how bad is it" after taking over an environment.
When MSPs run an assessment
An assessment is a point-in-time exercise with a clear trigger. Most fall into one of these.
Onboarding a new customer
You have just been given delegated access to a tenant someone else configured. An assessment tells you what you have inherited and establishes the baseline every later review compares against.
Periodic review
A scheduled deep review, often annual or semi-annual, that goes further than day-to-day monitoring: a full pass over identity, configuration, sharing, and admin roles, written up for the customer.
Audit or compliance preparation
Cyber-insurance questionnaires, ISO 27001, SOC 2, and customer security reviews all ask for evidence of Microsoft 365 controls. An assessment produces that evidence in one document.
Due diligence and incident follow-up
Before an acquisition closes, or after a phishing incident, someone needs an objective read of the tenant’s current state rather than an assurance that it is fine.
What a complete assessment covers
A thin assessment checks Secure Score and stops. A useful one covers the surfaces that actually get exploited.
Identity and Conditional Access
MFA registration versus enforcement, Conditional Access coverage and exclusions, admin-specific protection, legacy authentication, and privileged role assignments.
Secure Score and Microsoft controls
The current score, its history, and the improvement actions behind it, read as one input rather than the verdict.
Defender, sharing, and admin configuration
Endpoint posture where licensed, external sharing settings, and tenant-level administrative controls, including whether admin access is standing or time-bound.
External footprint
The customer’s domains, DNS and email authentication, TLS certificates, and exposed services, so the report covers what an attacker sees as well as what the tenant contains.
Assessment versus continuous posture management
The assessment is the photograph
It is accurate on the day it is taken and decays from there. Its job is to establish where things stand and to seed a baseline.
Posture management is the video
Scheduled re-assessment and monitoring track what changes after the photograph, and raise regressions as findings. SecurityScore.me runs both from the same customer workspace: the first assessment sets the baseline, monitoring watches it.
How an assessment runs
- Connect the tenant
- Delegated read-only Microsoft Graph consent for the customer workspace. Register external assets.
- Run the assessment
- A full pass over identity, configuration, Defender, sharing, admin roles, and external checks.
- Prioritise the output
- Findings ranked by severity with remediation guidance, so the customer conversation starts with the critical few.
- Report and set the schedule
- Generate the customer report and turn on scheduled re-assessment so the baseline is maintained.
Related pages
- Microsoft 365 security posture
What happens after the assessment: continuous tracking and drift detection.
- Microsoft Secure Score
One input to the assessment, tracked over time.
- Security findings
The severity-ranked output an assessment produces.
- Security reporting
Turning assessment output into a customer-ready document.
- Entra ID security
The identity portion of the assessment in detail.
- Entra ID & Conditional Access review (checklist)
The identity checklist an assessment works through per tenant.