"We've been on Microsoft 365 for years, everything's fine" is one of the most common things IT hears right before a security assessment turns up a dozen things that aren't fine at all. Most businesses set up Microsoft 365 once, get email and file sharing working, and never revisit the security configuration again. Meanwhile Microsoft has added and changed hundreds of security-relevant settings since that initial setup, almost none of which get enabled automatically.
A Microsoft 365 security assessment is a structured review of exactly what your tenant is doing today, compared against what it should be doing. It's the starting point for the entire security program, and skipping it means hardening work ends up guessing at priorities instead of targeting the actual gaps.
What a Microsoft 365 Security Assessment Actually Reviews
A thorough assessment looks well beyond a single settings page. It typically covers:
- Identity and authentication. MFA coverage across every user, legacy authentication protocols still in use, and guest and external user access.
- Admin roles and privileged access. Who holds Global Administrator and other privileged roles, and whether that access matches what those people actually need.
- Mail flow and anti-phishing configuration. Transport rules, spoofing protection, and mailbox forwarding rules that could be routing mail somewhere it shouldn't go.
- External sharing and data loss settings. How SharePoint, OneDrive, and Teams are configured for sharing files outside the organization.
- Conditional Access policy coverage. Whether Conditional Access is in use at all, and how completely it covers your users and applications.
- Microsoft Defender configuration. Whether Defender for Office 365, Identity, and Endpoint are enabled and properly tuned.
- Audit logging and retention. Whether the tenant is actually capturing the activity logs you'd need during an incident investigation.
- Microsoft Secure Score and CIS benchmark comparison. A baseline score plus a comparison against the CIS Microsoft 365 Foundations Benchmark, a widely used independent standard.
Why Microsoft Secure Score Isn't the Whole Picture
Secure Score is a genuinely useful starting point: it's built into the tenant, it's free, and it gives a rough numeric sense of where things stand. But it's a generic baseline, not a business-specific risk assessment. It doesn't know that your finance team handles wire transfers, that your healthcare staff work with protected health information, or that a particular legacy application still depends on a less secure authentication method. A real assessment uses Secure Score as one input among several, not as the final answer.
Common Findings in a First-Time Assessment
Across most tenants that have never had a formal review, the same handful of issues show up again and again:
- Legacy authentication protocols still enabled, giving attackers a way around modern MFA requirements.
- MFA available but not actually enforced tenant-wide, leaving some users unprotected.
- Unused or forgotten admin accounts that still hold privileged access.
- No Conditional Access policies in place at all, or policies that cover only a fraction of users and apps.
- External sharing defaults left wide open on SharePoint and OneDrive.
- Mailbox forwarding rules quietly routing mail to personal or external accounts.
- Audit logging either disabled or set to too short a retention window to be useful later.
From Findings to Action
An assessment is only useful once its findings turn into actual changes. Rating a gap as high-risk doesn't help much if nobody follows up on fixing it. The next stage is hardening: applying MFA, Conditional Access, and Defender configuration to close the gaps the assessment identified.
Our guide, Microsoft 365 Security Hardening: MFA, Conditional Access & Defender Explained, picks up exactly where the assessment leaves off.
Call us at 937-428-9234, email info@harbourtech.net, or contact Harbour Technology Consulting to talk through where your tenant stands today.






