Microsoft 365 security assessment Sydney

Find the security gaps in your Microsoft 365 tenant

Get a structured review of identity, email, endpoints, data controls, audit readiness and backup coverage, with a prioritised remediation plan your team can use.

One tenantEvidence backedPrioritised roadmap

What is a Microsoft 365 security assessment?

A Microsoft 365 security assessment is a point-in-time review of how your tenant is configured and operated. We examine the controls protecting user identities, administrator access, email, devices, Microsoft 365 data, audit records and recoverability. You receive evidence-backed findings, risk priorities and a staged remediation plan.

Microsoft Secure Score is one input, not the whole assessment. Microsoft describes Secure Score as a measure of security posture and the extent to which recommended controls are in use. It is not an absolute measure of breach likelihood or a guarantee against a breach.[1] We validate relevant recommendations against your licences, business requirements, exceptions and current operating practices before assigning priority.

In plain English: you will know what is configured, what is missing, what needs attention first, what may require additional licensing and what can be improved using capabilities you already own.

Who this assessment is for

This service suits Sydney organisations that:

  • use Microsoft 365 but have not had an independent tenant security review
  • have grown through rapid hiring, acquisitions or changes of IT provider
  • need to validate MFA, administrator access or Conditional Access coverage
  • want to understand whether Defender and Intune controls are configured and reaching the intended users and devices
  • need a clearer view of external sharing, audit logging, retention or sensitive-data controls
  • are preparing for cyber insurance, customer due diligence, governance reviews or Essential Eight uplift
  • have Secure Score recommendations but need business context and an implementation order
  • want a defined security improvement project before committing to ongoing managed services

The assessment can work with an internal IT team, an incumbent provider or as a direct engagement with Code Hyper One. Responsibilities and access are agreed before the review starts.

What is included

The standard assessment covers one Microsoft 365 tenant. The final boundary is confirmed in writing before commencement and reflects the products present, licences assigned and evidence available.

1. Tenant, identity and administrator security

We review:

  • verified domains, tenant-level settings and administrative ownership
  • active users, guests, dormant accounts and account lifecycle controls
  • privileged roles, standing administrator access and separation of admin and day-to-day accounts
  • MFA registration and enforcement coverage
  • authentication methods, legacy authentication exposure and security defaults where relevant
  • Conditional Access policies, assignments, exclusions, report-only policies and coverage gaps
  • emergency access account design and monitoring evidence
  • enterprise applications, consent settings and service principals at a review level
  • sign-in and risk information available under the tenant’s licences

Conditional Access can make access decisions using signals such as user, location, device, application and risk, then require controls such as MFA or a compliant device.[2] The assessment checks policy intent, scope, exclusions and evidence. It does not assume that having policies listed means every intended sign-in is protected.

2. Email and collaboration protection

We review the controls available for:

  • Exchange Online Protection and anti-spam policy posture
  • anti-phishing, impersonation and spoof protection
  • Safe Links and Safe Attachments where licensed
  • Defender for Office 365 preset or custom policy coverage where licensed
  • external email indicators and mail-flow rules that affect security
  • outbound spam controls and automatic forwarding exposure
  • user and domain allow/block entries, with attention to broad exceptions
  • Teams, SharePoint and OneDrive sharing settings at a tenant level
  • guest access and anonymous-link exposure at a review level

Microsoft provides Standard, Strict and Built-in preset security policies for eligible Defender for Office 365 environments, with different recipient scope and protection behaviour.[7] We compare the effective configuration with Microsoft guidance and your operating requirements rather than applying a preset blindly.

3. Endpoint management and protection

Where Intune or Microsoft Defender for Endpoint is present, we review:

  • device enrolment and inventory coverage
  • compliance policy assignments and exceptions
  • how devices without an assigned compliance policy are treated
  • Conditional Access use of device compliance signals
  • Windows security baseline versions, assignments and conflicts
  • endpoint security policy coverage, including antivirus, firewall, encryption and attack-surface settings visible in the tenant
  • Defender for Endpoint onboarding and health indicators available to the reviewer
  • device risk integration with Intune and Entra where configured
  • material gaps between enrolled, active, compliant and protected device populations

Intune security baselines are groups of preconfigured settings that can be customised for an organisation. Microsoft also warns that restrictive defaults and overlapping baselines should be validated for conflicts before deployment.[4] Intune compliance results can feed Conditional Access decisions, including whether a noncompliant device can access organisational resources.[5]

4. Data protection, sharing and governance

We review the configuration visible and licensed for:

  • SharePoint, OneDrive and Teams external sharing
  • sensitivity labels and label publishing where in use
  • data loss prevention policies where in use
  • retention policies and retention labels where in use
  • high-level access and exposure concerns for selected collaboration locations
  • Purview alerts, policies and compliance features included in the agreed scope
  • governance gaps that need a dedicated data-discovery or Purview project

This is a configuration assessment, not a full content-classification exercise. We do not inspect every file, mailbox, Team or SharePoint site unless that deeper review is separately scoped.

5. Audit, alerting and operational readiness

We review:

  • availability and permissions for unified audit log search
  • audit settings and retention visible under the current subscription
  • security alert queues and incident workflows available in the tenant
  • named ownership for alert review and escalation
  • evidence that important security changes and exceptions are recorded
  • integration points with a SIEM, SOC or ticketing process where present and in scope

Microsoft Purview Audit can make user and administrator activity searchable across Microsoft services. Audit capabilities and retention vary by subscription, with Audit Standard and Audit Premium providing different features.[6]

6. Backup and recovery posture

We review evidence for:

  • whether Exchange Online, SharePoint, OneDrive and Teams data is included in a separate backup service
  • backup scope, exclusions and administrative ownership
  • retention settings and protected workload coverage
  • recent job status and available restore-test evidence
  • documented recovery responsibilities

The assessment validates configuration and evidence made available to us. It does not perform a destructive recovery test or certify recoverability unless a separate restore test is agreed.

7. Secure Score and Essential Eight context

We review relevant Microsoft Secure Score recommendations across the products visible in the tenant. Secure Score can include recommendations for identity, apps, devices and data, but Microsoft notes that recommendations do not cover every attack surface and may be shown regardless of licence edition.[1]

Where requested, we also map applicable observations to relevant Essential Eight themes. This is an alignment view, not an Essential Eight maturity certification. Several Essential Eight controls depend on systems and processes outside Microsoft 365, including application control, patching across the wider environment and backup operations.

Evidence we review

Subject to the agreed scope, permissions and licences, evidence may include:

  • tenant and subscription details
  • licence inventory and assignment reports
  • user, guest and administrator-role exports
  • authentication-method registration reports
  • sign-in, risk and audit records available for the review period
  • Conditional Access policy configuration, status, assignments and exclusions
  • Secure Score history and recommended actions
  • Exchange Online, Defender for Office 365 and collaboration protection policies
  • Intune enrolment, configuration, compliance and endpoint-security reports
  • Defender incidents, alerts, device inventory and onboarding status available in the portal
  • SharePoint, OneDrive and Teams sharing settings
  • Purview audit, sensitivity, DLP and retention configurations where present
  • backup policy, protected-object, job and restore-test evidence supplied by the customer or backup provider
  • relevant policies, procedures, diagrams, exception records and prior assessment reports supplied by the customer
  • stakeholder explanations needed to distinguish an accepted exception from an undocumented gap

We prefer time-limited, read-only access using the least privilege necessary. If access cannot be granted, agreed exports and screen-sharing can be used, but the report will state the resulting evidence limitations.

How the assessment works

1. Confirm the boundary

We confirm the tenant, user and device population, licence mix, business-critical workloads, known constraints, assessment goals and evidence-access method. Anything outside the agreed boundary is recorded as out of scope.

2. Collect evidence

We gather configuration and operational evidence through approved read-only access, customer-supplied exports, screen-sharing or a documented combination of these methods. We record unavailable evidence rather than assuming a control exists.

3. Analyse control effectiveness

We compare the observed configuration with relevant Microsoft guidance, your licensed capabilities and the business context provided. We look for gaps in coverage, weak exclusions, conflicting policies, stale access, missing ownership and controls that exist on paper but lack supporting evidence.

4. Prioritise findings

Each finding is documented with the affected area, observed evidence, risk statement, recommended action and priority. Recommendations distinguish between configuration work, process work and items that may require licence changes or a separate project.

5. Present the results

We walk stakeholders through the executive summary, material findings, dependencies and recommended order of work. Questions and factual corrections identified during the review are captured before the report is finalised.

6. Choose the next step

You can take the plan to your internal team, provide it to your current IT provider or ask Code Hyper One to scope remediation. The assessment does not lock you into an ongoing service.

What you receive

Executive security summary

A concise view of the current posture, material risks, strengths, evidence limitations and decisions required from management.

Detailed findings register

A structured list of findings with:

  • affected Microsoft 365 control area
  • observation and supporting evidence reference
  • risk and likely business impact
  • priority rating and rationale
  • recommended treatment
  • licence or dependency note where relevant
  • suggested owner
  • status field for remediation tracking

Prioritised remediation roadmap

A staged plan grouped into:

  • urgent exposure reduction
  • near-term hardening
  • planned governance and capability uplift
  • longer-term operational improvements

The roadmap identifies sequencing and dependencies. It does not promise an implementation date until remediation scope, change windows and customer responsibilities are agreed.

Licence and capability notes

A practical summary of which recommendations appear supportable under the licences observed, which need confirmation and which may require different or additional subscriptions.

Assessment playback

A stakeholder session covering the key findings, recommended order of work and open decisions.

Evidence limitations and exclusions record

A clear statement of unavailable data, inaccessible portals, incomplete samples and areas not tested, so the report is not mistaken for broader assurance than the evidence supports.

Microsoft 365 licence caveats

Microsoft 365 security capabilities vary by plan, add-on, user assignment, workload and product terms. For example, Microsoft states that Conditional Access requires Microsoft Entra ID P1, while risk-based Conditional Access requires Entra ID P2. Microsoft 365 Business Premium includes Entra ID P1.[2][3]

Licence status affects both what can be assessed and what can be recommended for implementation:

  • a control shown in Microsoft guidance or Secure Score may not be included in your current licence edition
  • some features require licences for each user benefiting from or governed by the feature
  • Defender, Intune and Purview capabilities differ across Microsoft 365 plans and add-ons
  • audit features and retention periods depend on subscription and user licensing[6]
  • portal visibility does not by itself confirm entitlement to deploy a feature broadly
  • Microsoft product names, bundles and entitlements can change

We record observed licence information and flag assumptions. Final licensing, quantities, eligibility and product terms must be confirmed against Microsoft’s current product terms or a formal licensing quote before purchase or deployment. The assessment fee, any licence purchase and remediation work are separate unless the proposal explicitly says otherwise.

What is not included

Unless added to the written scope, the assessment does not include:

  • penetration testing, phishing simulation or attempts to bypass controls
  • incident response, threat hunting or forensic investigation
  • malware removal or compromise eradication
  • implementation of recommended changes
  • full review of Azure subscriptions, on-premises Active Directory, servers, networks, firewalls or non-Microsoft SaaS platforms
  • line-by-line review of every file, mailbox, Team, SharePoint site or third-party application
  • legal advice, privacy advice or formal regulatory certification
  • a certified Essential Eight maturity assessment
  • guaranteed improvement to a particular Secure Score
  • a guarantee that a security incident, data loss or compliance failure will not occur
  • backup restoration or disaster-recovery testing unless specifically agreed
  • ongoing monitoring, alert response or managed SOC coverage
  • procurement of Microsoft licences or third-party products
  • remediation timeframes, after-hours work or service levels not expressly included in a separate agreement

If the evidence suggests an active compromise or urgent operational risk, we will raise it through the agreed contact path. Investigation and containment require separate authorisation and scope.

From assessment to remediation

A useful assessment should lead to controlled change, not a report that sits unread.

Option 1. Your team remediates

Use the findings register and roadmap with your internal IT team. Code Hyper One can answer report clarification questions through the agreed engagement channel.

Option 2. Your current provider remediates

Provide the report to your incumbent provider. Findings are written to support assignment, evidence collection and closure tracking rather than prescribe a change without context.

Option 3. Code Hyper One scopes the uplift

Ask us to convert selected findings into a remediation proposal. Depending on the gaps, the work may include:

  • Entra ID and Conditional Access hardening
  • administrator and guest-access clean-up
  • Defender for Office 365 configuration
  • Defender for Endpoint onboarding and policy uplift
  • Intune enrolment, compliance and security-baseline work
  • SharePoint, OneDrive and Teams sharing controls
  • Purview sensitivity, DLP, retention or audit improvements
  • Microsoft 365 backup onboarding or restore testing
  • Essential Eight-aligned improvement activities
  • ongoing Microsoft 365 management, security monitoring or SOC integration

Remediation is separately scoped, approved and scheduled. We favour staged rollouts, documented exclusions, rollback planning and validation after change. Controls that can disrupt sign-in, email flow, device access or business applications should not be switched on without impact review and an agreed change approach.

Validation after remediation

Where included in the remediation proposal, Code Hyper One can re-check selected findings and record evidence of closure, partial treatment, accepted risk or remaining work. A configuration change is not treated as complete solely because it was saved in a portal.

Frequently asked questions

Is this the same as checking Microsoft Secure Score?

No. Secure Score is useful evidence and a source of recommended actions, but Microsoft says it is not an absolute measure of breach likelihood and its recommendations do not cover every attack surface.[1] We add licence validation, policy-scope review, evidence checks, business context, operational ownership and a prioritised treatment plan.

Will you make changes during the assessment?

No, not unless a separate written scope authorises a specific change. The assessment is designed as a point-in-time review. Keeping assessment and remediation approvals separate reduces the risk of unexpected disruption.

Do you need Global Administrator access?

Not by default. We prefer time-limited, read-only access with the least privilege needed for the agreed evidence. The exact roles depend on which Entra, Defender, Exchange, Intune and Purview areas are in scope. If suitable portal access is not available, we can agree on exports and screen-sharing, then document any limitations.

Can you assess a tenant managed by another IT provider?

Yes. We can work with your internal team or incumbent provider, provided the business authorises the review and the required evidence is available. The report can separate customer, provider and Microsoft dependencies where ownership is clear.

Does the assessment include all users and devices?

The tenant-level configuration review covers the agreed tenant. Population and coverage analysis depends on the reports available. Detailed device, site, mailbox or application inspection may use an agreed sample unless full-population analysis is practical and included in scope. The final report states the boundary and sampling method.

Can this certify our Essential Eight maturity level?

No. We can map relevant Microsoft 365 observations to applicable Essential Eight themes, but a formal maturity assessment needs a wider evidence set across endpoints, applications, patching, privileged access, backups and operational processes. Any mapping in this service is directional unless a separate Essential Eight assessment is contracted.

What if we do not have Microsoft 365 Business Premium or E5?

The assessment still identifies gaps and available controls. Recommendations will separate changes that may be possible with current capabilities from those needing licensing confirmation or an alternative control. We do not assume that an enterprise licence is the right commercial answer.

Does a higher Secure Score mean we are secure?

Not by itself. Microsoft says Secure Score is a numerical summary of control adoption, not a guarantee against breach.[1] Priorities should also reflect your users, data, threat exposure, usability needs, exceptions and compensating controls.

Will the assessment disrupt staff?

Evidence collection is intended to be read-only and low impact. We do not deploy policies or change user access as part of the assessment. Any later remediation that could affect sign-in, email, devices or collaboration is separately planned and approved.

Do you test Microsoft 365 backups?

We review available backup configuration, coverage, job status and restore-test evidence. We do not claim that data is recoverable without an agreed restore test. A controlled restore test can be scoped separately.

How long does the assessment take and what does it cost?

Both depend on tenant size, products in use, licence mix, evidence access and whether deeper sampling is required. Code Hyper One confirms the scope, commercial terms and delivery expectations in writing before work starts. This page does not publish a fixed price or service-level commitment.

What happens if you find signs of an active incident?

We notify the agreed customer contact using the engagement escalation path. Investigation, containment and recovery are separate activities that require authorisation. If incident response is needed, we will distinguish urgent response actions from the remaining assessment work.

Get a clear Microsoft 365 security action plan

Know which controls are working, which users and devices may be outside policy coverage, where evidence is missing and what to fix first.

Start with a scope call. Bring your approximate user count, Microsoft 365 plan, device-management approach, backup platform and any current security concerns. We will confirm what can be assessed, the evidence required and the commercial scope before commencement.

  • Name
  • Organisation
  • Work email
  • Phone
  • Approximate Microsoft 365 user count
  • Current Microsoft 365 plan or licence mix
  • Are devices managed in Intune? Yes / No / Unsure
  • Do you use a separate Microsoft 365 backup service? Yes / No / Unsure
  • Main concern or assessment goal
  • Preferred contact method

Microsoft product references

  1. Microsoft Secure Score
  2. Conditional Access overview
  3. Microsoft Entra licensing
  4. Intune security baselines
  5. Microsoft Purview Audit
  6. Defender for Office 365 preset policies

Ready for a clear security action plan?

Tell us what you need reviewed. We will confirm the scope, evidence required and next step before work begins.