Microsoft 365 Security Review

For firms on Microsoft 365 who want to know what the tenant enforces today, which controls their licence already includes, and what the rest would cost, before anyone touches a setting.

View All Engagements

A fixed-scope read on what your Microsoft 365 tenant actually enforces today, covering Entra ID role assignments and sign-in policy, SharePoint and OneDrive sharing, Purview retention, and how far back your audit log still reaches. Much of the Microsoft hardening advice you will find online quietly assumes Entra ID P1 or a Defender tier you may not be paying for, so we also mark which recommendations your current licences already cover and which ones would cost money. Deep Defender, Intune, and Copilot reviews are scoped separately.

Duration
7 to 10 business days
Engagement
Review

Output

What you walk away with

A defined output, on paper or in your tenant. Yours to use whether the work continues with us or not.

Identity and access findings

Where Global Administrator and the other privileged roles actually sit, whether security defaults or Conditional Access is enforcing MFA, and which of the tighter options need Entra ID P2 rather than the P1 that ships with Business Premium.

Sharing and exposure map

The tenant-level sharing ceiling you have set, how far individual sites and OneDrive sit inside it, and where Anyone links have put files in front of people who never had to sign in.

Retention and evidence read

What Purview retention policies and eDiscovery holds are doing today, how much audit history you can still search, and what your current licences let you prove if somebody asks.

Fix list with the licence cost attached

Every recommendation marked as either covered by what you already pay for or needing an upgrade, so the spend becomes a decision you make rather than one you discover.

How It Works

How the work runs.

A short, defined sequence. Nothing in your tenant or domain changes until the scope and access are confirmed.

Access and scope

We confirm which licences you hold, who owns tenant administration, and the read-only access we need to look without changing anything. The review is governed against the CIS Benchmark for the platform, so the findings sit against a published standard rather than against one consultant's checklist.

Identity inspection

We read Entra ID role assignments, the sign-in policy in force, guest accounts, and any legacy authentication paths still open.

Collaboration inspection

We work through SharePoint site and OneDrive sharing, external sharing settings, sensitivity labels if you have them, and the Teams-created sites that inherited defaults nobody chose.

Evidence and licence check

We check retention, holds, and audit history, then split the fixes your licence already covers from the ones that need a tier change.

Findings handoff

You get the findings, the order we would fix them in, and a straight answer on what stays open until you decide to spend.

Best Fit

Sound familiar?

Admin roles have piled up and nobody can say who holds Global Administrator today

Sign-in protection is still whatever security defaults gave you, or a set of Conditional Access rules nobody has re-read

Sharing links out of SharePoint and OneDrive have never been counted, and an Anyone link needs no sign-in at all

A client or insurer wants evidence, and the audit log only reaches back 180 days unless you are on E5 or a Purview add-on

Retention, offboarding, and what happens to a leaver's OneDrive have no named owner

Frequently asked questions.

Who is Microsoft 365 Security and Governance Review for?

Microsoft 365 Security and Governance Review is built for firms running on Microsoft 365, teams on Business Standard or Business Premium, and owners answering client or insurer security questions.

How does this engagement start?

Every engagement starts with a short first call to confirm the situation, the decision owner, the access required, and whether this is the right engagement for what you actually need.

What happens after the first call?

Teclara confirms the scope, the access, and the timing. If the engagement is a fit, we agree on the work and start. If a different engagement fits better, we say so.

Ready to start?

Book the first call. We will confirm the situation, the access required, and the right way to move forward, with no obligation past that conversation.