More than a Secure Score screenshot
Microsoft 365 holds identities, email, documents, collaboration data and access to other business systems. Its security depends on more than whether a recommended setting is switched on. Licences, configuration, user behaviour, device management, external sharing and the way responsibilities are divided between the organisation and its IT provider all affect risk.
A useful Microsoft 365 Security Review should therefore examine how the tenant is actually configured and how that configuration supports the organisation’s working practices. It should gather evidence, identify meaningful gaps and explain what should be addressed first.
Microsoft Secure Score is a helpful source of recommendations and a way to track some changes over time. It is not, by itself, a complete review. A screenshot or generic checklist cannot establish whether a setting is appropriate, whether it is fully deployed or whether a more important risk sits outside the score.
Start with context and scope
Before reviewing individual controls, establish what the tenant supports. The reviewer should understand the organisation’s size, sector, key services, regulatory or customer obligations, licences, user population and approach to outsourced IT.
The scope should identify the workloads and connected services to be considered. That may include Microsoft Entra ID, Exchange Online, SharePoint, OneDrive, Teams, Intune, Defender products and third-party applications connected to the tenant.
Context matters because a practical recommendation for a small professional firm may be different from one for a larger organisation with dedicated security operations. The review should distinguish between controls that are essential, improvements that are proportionate and advanced features that may not be justified.
Identity and privileged access
Identity is usually the most important part of a Microsoft 365 review. An attacker who compromises an account may gain access to email, files, applications and business relationships without needing to breach a traditional network perimeter.
The review should examine multi-factor authentication coverage and how MFA is enforced. It should identify users or applications that can still authenticate without the intended controls, and consider whether stronger, phishing-resistant methods are appropriate for administrators and other high-risk users.
Privileged access needs separate attention. The reviewer should establish who holds administrative roles, whether those roles are broader than necessary and whether administrators use separate accounts for privileged work. Permanent assignments, dormant admin accounts and supplier access should be examined in the context of least privilege and operational need.
Emergency access, sometimes called break-glass access, should also be reviewed. The organisation needs a resilient way to regain control if normal administrator access fails, with secure credentials, clear ownership, monitoring and periodic testing. Those accounts should not simply be created and forgotten.
Other identity checks should include:
- Conditional Access coverage, exclusions and report-only policies;
- legacy authentication and older protocols;
- dormant, disabled and former-staff accounts;
- guest and external identities;
- risky sign-ins and identity alerts where available;
- registration and recovery of authentication methods;
- service accounts and other non-human identities.
The purpose is not to apply the same policy to every account. It is to understand who can sign in, under what conditions and with what level of privilege.
Endpoint and device controls
Microsoft 365 data is accessed from laptops, desktops, phones and browsers, including devices the organisation may not own. A review should determine which devices are managed, what security state is expected and how access from unmanaged devices is controlled.
Where Microsoft Intune is in use, the reviewer should examine enrolment, compliance policies, configuration profiles and the relationship between device compliance and Conditional Access. A device appearing in a management portal does not necessarily mean that the intended settings are applied successfully.
Endpoint review may cover:
- device inventory and ownership;
- update and security baseline deployment;
- Microsoft Defender configuration where licensed;
- local administrator rights;
- disk encryption and recovery arrangements;
- mobile application protection;
- lost or retired device handling;
- access from unmanaged or non-compliant devices.
Not every organisation needs full mobile-device management for every scenario. The review should explain where controls are proportionate and where another approach, such as application protection or restricted browser access, may be more practical.
Email security
Exchange Online is a frequent target because a compromised mailbox can be used for fraud, data theft and further phishing. The review should look beyond whether anti-malware is enabled and examine how email threats are prevented, detected and handled.
Relevant areas include anti-phishing policies, impersonation protection where available, mailbox forwarding, suspicious inbox rules, shared mailboxes and who can access them. Domain authentication using SPF, DKIM and DMARC should be considered alongside the tenant configuration because it affects how receiving systems judge messages sent from the organisation’s domains.
External forwarding deserves particular attention. It may be legitimate in limited cases, but broad or unmonitored forwarding can create a route for data loss and persistence after account compromise.
The reviewer should also consider how users report suspicious messages, who investigates them and whether alerts reach someone able to act. A strong setting has limited value if warnings are ignored or nobody owns the response.
SharePoint, OneDrive and Teams
Collaboration settings determine how easily information can move outside the organisation. A review should examine default and site-specific sharing, anonymous links, guest access and permissions that have accumulated over time.
For SharePoint and OneDrive, this includes the most permissive sharing settings, link expiry where used, access to sensitive sites and the process for reviewing external users. For Teams, it includes guest and external access, team ownership, meeting settings and how shared channels or connected sites affect information access.
Application consent and third-party integrations should also be checked. Users and administrators may have granted applications access to mailboxes, files or directory data. The review should identify high-impact permissions, unclear ownership and applications that are no longer required.
The objective is not to disable collaboration. It is to make sure sharing is intentional, visible and appropriate for the information involved. This becomes especially important before enabling Microsoft 365 Copilot, because Copilot can make existing overshared information much easier to find. Our guide asks whether Microsoft 365 Copilot is safe for business use .
Data protection and governance
A proportionate review should examine how the organisation understands and protects important data. The depth depends on risk, regulatory requirements, licences and the maturity of existing governance.
Relevant areas may include sensitivity labels, information classification, retention, audit logging and data loss prevention. These controls should have a clear purpose. Deploying complex labels or DLP rules without ownership, testing and user guidance can create disruption without delivering useful protection.
The review should also look at who can access sensitive locations, how access changes when people move roles and what evidence would be available during an incident investigation. Audit settings and retention should support realistic investigation needs rather than exist only as a compliance tick box.
Backup and recovery assumptions need to be made explicit. Microsoft provides resilient services and retention capabilities, but the organisation should understand what can be restored, for how long, by whom and whether separate backup arrangements are needed for its risks and obligations.
Defender, alerting and monitoring
Where Microsoft Defender products are licensed, the review should examine configuration as well as product presence. That may include endpoint protection, email and collaboration protection, identity signals, cloud application visibility and the way incidents are combined in the Defender portal.
Alerting needs an owner. The reviewer should establish where security alerts go, which events are investigated, what escalation route exists and whether the organisation or its provider can act within an appropriate timeframe.
Exposure information and recommendations can help prioritise improvement, but they need operational follow-up. A backlog of unowned recommendations is not the same as an exposure-management process. The review should identify how findings are accepted, remediated or monitored and how progress is reported.
For organisations without advanced Defender licensing, the review should still establish what visibility is available and what practical monitoring can be maintained. Recommendations should fit the services the organisation actually owns.
Licensing and feasibility
Microsoft 365 licensing affects which controls and evidence sources are available. Conditional Access, advanced identity protection, endpoint management, data protection and Defender capabilities may require particular products or licence levels.
A useful review records the licences held and checks recommendations against them. It should distinguish among configuration changes available now, controls that require additional licensing and alternative approaches that may meet the underlying need.
Licence names and entitlements change, so a report should verify current Microsoft documentation before making a purchasing recommendation. It should not assume that every organisation needs the highest licence tier or every advanced security feature.
Feasibility also includes operational capacity. A control that produces alerts nobody can investigate may need a different implementation or supporting service. Recommendations should account for internal skills, provider responsibilities and the effort needed to maintain the control after it is introduced.
The limitations of Microsoft Secure Score
Secure Score is useful for identifying recommended actions and tracking aspects of security posture. Microsoft itself notes that recommendations need to be balanced with usability and may not suit every environment. The score should not be interpreted as a guarantee against compromise.
It also cannot replace configuration review, evidence gathering and business-context analysis. A high score may coexist with excessive sharing, unclear ownership, weak incident handling or an important exception that has not been examined. A lower score may include recommendations that are unavailable under current licensing or inappropriate for the organisation’s operating model.
The reviewer should use Secure Score as one input, validate relevant recommendations and explain why each selected action matters. Our Microsoft 365 security checklist provides a practical starting point, but a review should go further than a checklist.
What the review output should contain
The final deliverable should help both decision-makers and the people responsible for implementation. A long export of settings is not enough.
A useful report normally includes:
- an executive summary of the most important risks;
- a clear statement of scope, evidence and limitations;
- prioritised findings with risk and business context;
- evidence showing how conclusions were reached;
- practical remediation recommendations;
- quick wins that can be completed safely;
- longer-term actions and dependencies;
- accepted risks, constraints or justified exceptions;
- ownership and an implementation roadmap.
Priorities should reflect likely impact, exposure and practical effort rather than simply mirroring product severity labels. Where a finding depends on licensing, provider action or a wider policy decision, the report should say so.
The output should also support follow-up. Organisations need a way to record completed actions, revisit accepted risks and check that important changes had the intended effect.
How Be Secure Cyber can help
Be Secure Cyber provides a practical Microsoft 365 Security Review shaped around the tenant, licences and organisation rather than a generic score target. The work can cover identity, privileged access, devices, email, sharing, Defender, monitoring and governance, with prioritised findings and proportionate recommendations.
Where the findings form part of a wider improvement programme, we can support implementation through a defined cyber security consultancy engagement or provide ongoing leadership and oversight through vCISO support .
Contact Be Secure Cyber to discuss the scope and the assurance your organisation needs.