Identities
SecOps ForcesMicrosoft 365 audit
Expertise & support
The real state of yourMicrosoft 365,in one hour.
More than three hundred controls across identities, mail, sharing and endpoints, run in thirty to sixty minutes by our platform. Then a report ranked by risk and effort, reviewed by an expert, and a readout your board understands without a translator.
Scan in 30 to 60 min · No agent to deploy · No service interruption
What the audit reveals
What we find
most often.
These are not rare vulnerabilities. They are settings left at their defaults, temporary exceptions that became permanent, and access that was never revoked. Here is what we find in most of the environments we audit.
Forgotten forwarding rules
Sharing
Permanent public links
DMARC left at p=none
Logging
Retention that is too short
Applications
Consents granted to third parties
Deliverables
Three usable documents.
The detailed report
The executive readout
The remediation plan
How it runs
Four steps, one hour of collection.
You give us read-only access. The platform runs the scan in every case; the expert analysis and the readout are part of the packages below.
Scoping
Thirty minutes to understand your organization, your constraints and what matters to you.
Collection
The scan runs in 30 to 60 minutes depending on tenant size. No agent, no change, no interruption.
Analysis
Every control is run, then reviewed by an expert: context always outweighs the raw score.
Readout
Presented to your leadership within one business day, detailed report within the week.
Pricing
One fixed price,
and a defined scope.
The foundation is the platform, on subscription, priced on request: it scans, it measures and it applies remediation. The two options below are added only if you decide to. The analysis has a fixed price, which we publish because you deserve to know it before calling. Guided remediation depends on how many days your environment actually needs — five for some, ten for others — so it is quoted after scoping, not before.
Option 1 — Analysis & roadmap
You want to establish where you stand and obtain a plan your own teams can execute.
- Full tenant analysis: 300+ controls, plus DMARC, SPF and DKIM across all your domains
- Executive summary presented to your leadership
- Prioritized, costed remediation roadmap
Optional
Option 2 — Analysis & guided remediation
You want the gaps closed, not merely documented. Our experts remain engaged until remediation is applied, for as many days as your environment requires.
- Everything in option 1
- The number of consulting days matched to your environment, no more and no less
- Microsoft 365 remediation applied from the platform, with every change traced
- Verification after the fix: the posture score is measured again
Neither package is ever mandatory. Without them the platform still works: you run the scan, read your score and apply Microsoft 365 remediation yourself, with every change traced. Our experts step in only once you sign one of the two packages — and nothing stops you from starting alone and calling us later on a specific topic.
Next
What follows the readout.
After remediation, two arrangements maintain the level reached.
Continuous posture
Frequently asked
Before you grant us access.
What effort does this require from our teams?
What permissions do we need to grant?
Can the audit disrupt production?
We already have a managed service provider. Is this redundant?
Can the report be used for NIS2 or for our insurer?
What happens if the audit finds nothing critical?
Let us review your tenant together.
Thirty minutes to scope it, answer your questions and tell you whether the audit makes sense in your situation.