SecOps ForcesMicrosoft 365 audit

Expertise & support

The real state of yourMicrosoft 365,in one hour.

More than three hundred controls across identities, mail, sharing and endpoints, run in thirty to sixty minutes by our platform. Then a report ranked by risk and effort, reviewed by an expert, and a readout your board understands without a translator.

Scan in 30 to 60 min · No agent to deploy · No service interruption

audit.m365 — extract355 controls
58/100 · starting score as found
Identities & access7 critical gaps
Exchange Online12 to review
SharePoint / OneDrive sharing4 to review
Logging & retention2 critical
Endpoints & Defendercompliant

What the audit reveals

What we find
most often.

These are not rare vulnerabilities. They are settings left at their defaults, temporary exceptions that became permanent, and access that was never revoked. Here is what we find in most of the environments we audit.

Identities

Privileged accounts without MFA

Service accounts, break-glass accounts, contractors: exceptions to multi-factor outlive the projects that created them.

Mail

Forgotten forwarding rules

Automatic redirections to external mailboxes, often created during a departure or an incident, never removed afterwards.

Sharing

Permanent public links

Documents shared with "anyone with the link", no expiry date, indexed and reachable years later.

Email

DMARC left at p=none

The policy is published but enforces nothing. The domain stays spoofable, and nobody reads the reports.

Logging

Retention that is too short

Default retention that makes it impossible to investigate an incident found three months later, or to answer an insurer.

Applications

Consents granted to third parties

Applications allowed to read mailboxes or files, approved once, never reviewed since.

Deliverables

Three usable documents.

The detailed report

Every gap found, its real risk level, the estimated effort to fix it and the steps to follow. Usable directly by your team or your managed service provider.

PDF · ~60 pages

The executive readout

A one-hour presentation for your leadership: where you stand, what doing nothing costs, and what we recommend tackling first.

Presentation · 1 h

The remediation plan

The ordered list of what to fix, with the effort attached. You can run it yourself, hand it to your provider, or hand it to us.

Roadmap

How it runs

Four steps, one hour of collection.

You give us read-only access. The platform runs the scan in every case; the expert analysis and the readout are part of the packages below.

01

Scoping

Thirty minutes to understand your organization, your constraints and what matters to you.

02

Collection

The scan runs in 30 to 60 minutes depending on tenant size. No agent, no change, no interruption.

03

Analysis

Every control is run, then reviewed by an expert: context always outweighs the raw score.

04

Readout

Presented to your leadership within one business day, detailed report within the week.

Pricing

One fixed price,
and a defined scope.

The foundation is the platform, on subscription, priced on request: it scans, it measures and it applies remediation. The two options below are added only if you decide to. The analysis has a fixed price, which we publish because you deserve to know it before calling. Guided remediation depends on how many days your environment actually needs — five for some, ten for others — so it is quoted after scoping, not before.

Option 1 — Analysis & roadmap

€2,500excl. VAT · fixed

You want to establish where you stand and obtain a plan your own teams can execute.

  • Full tenant analysis: 300+ controls, plus DMARC, SPF and DKIM across all your domains
  • Executive summary presented to your leadership
  • Prioritized, costed remediation roadmap

Neither package is ever mandatory. Without them the platform still works: you run the scan, read your score and apply Microsoft 365 remediation yourself, with every change traced. Our experts step in only once you sign one of the two packages — and nothing stops you from starting alone and calling us later on a specific topic.

Next

What follows the readout.

After remediation, two arrangements maintain the level reached.

Continuous posture

The corrected configuration is monitored around the clock. Every drift is detected, qualified and documented for your compliance evidence.

From €1.20/user/mo annual · 100–500/tenant

Frequently asked

Before you grant us access.

What effort does this require from our teams?
Thirty minutes of scoping, plus the time to open read-only access. The scan then runs on its own, in thirty to sixty minutes depending on tenant size. Your teams have nothing else to do: no agent to deploy, no maintenance window, no interruption.
What permissions do we need to grant?
Read-only access to your tenant configuration, time-limited and revocable at any moment. We read neither the content of your messages nor of your files.
Can the audit disrupt production?
No. Collection is passive and read-only: no agent installed, no change applied, no downtime. Your users see nothing.
We already have a managed service provider. Is this redundant?
No, and it is often the opposite: the audit hands your provider a clear, prioritized list of fixes. We regularly work alongside in-house teams and incumbent providers, not against them.
Can the report be used for NIS2 or for our insurer?
Yes. Findings are timestamped and documented, and the remediation plan is evidence of due diligence. For a file tracked over time, continuous monitoring adds the history of the fixes.
What happens if the audit finds nothing critical?
It happens, and it is good news with real value: you get a dated, defensible statement of where you stand. We do not inflate severity to sell the next step.

Let us review your tenant together.

Thirty minutes to scope it, answer your questions and tell you whether the audit makes sense in your situation.