Security assessment

Microsoft 365 security assessment for MSP customer tenants

A Microsoft 365 security assessment is a structured review of one tenant at one moment: what is configured, where the gaps are, and what to fix first. MSPs run one to onboard a customer, prepare for an audit, or answer "how bad is it" after taking over an environment.

When MSPs run an assessment

An assessment is a point-in-time exercise with a clear trigger. Most fall into one of these.

Onboarding a new customer

You have just been given delegated access to a tenant someone else configured. An assessment tells you what you have inherited and establishes the baseline every later review compares against.

Periodic review

A scheduled deep review, often annual or semi-annual, that goes further than day-to-day monitoring: a full pass over identity, configuration, sharing, and admin roles, written up for the customer.

Audit or compliance preparation

Cyber-insurance questionnaires, ISO 27001, SOC 2, and customer security reviews all ask for evidence of Microsoft 365 controls. An assessment produces that evidence in one document.

Due diligence and incident follow-up

Before an acquisition closes, or after a phishing incident, someone needs an objective read of the tenant’s current state rather than an assurance that it is fine.

What a complete assessment covers

A thin assessment checks Secure Score and stops. A useful one covers the surfaces that actually get exploited.

Identity and Conditional Access

MFA registration versus enforcement, Conditional Access coverage and exclusions, admin-specific protection, legacy authentication, and privileged role assignments.

Secure Score and Microsoft controls

The current score, its history, and the improvement actions behind it, read as one input rather than the verdict.

Defender, sharing, and admin configuration

Endpoint posture where licensed, external sharing settings, and tenant-level administrative controls, including whether admin access is standing or time-bound.

External footprint

The customer’s domains, DNS and email authentication, TLS certificates, and exposed services, so the report covers what an attacker sees as well as what the tenant contains.

Assessment versus continuous posture management

The assessment is the photograph

It is accurate on the day it is taken and decays from there. Its job is to establish where things stand and to seed a baseline.

Posture management is the video

Scheduled re-assessment and monitoring track what changes after the photograph, and raise regressions as findings. SecurityScore.me runs both from the same customer workspace: the first assessment sets the baseline, monitoring watches it.

How an assessment runs

Connect the tenant
Delegated read-only Microsoft Graph consent for the customer workspace. Register external assets.
Run the assessment
A full pass over identity, configuration, Defender, sharing, admin roles, and external checks.
Prioritise the output
Findings ranked by severity with remediation guidance, so the customer conversation starts with the critical few.
Report and set the schedule
Generate the customer report and turn on scheduled re-assessment so the baseline is maintained.
Security Posture Report

Related pages

Frequently asked questions

Next steps

Run Microsoft 365 assessments across your customer portfolio