Microsoft 365 Security Review
Understand the configuration, risks and priority actions across identity, email, devices, applications and collaboration.
What we examine
- Security baseline and Secure Score context
- MFA and authentication methods
- Conditional Access and legacy authentication
- Global and privileged administrator roles
- Defender and email protection configuration
- SharePoint, Teams and guest sharing
- Joiner, mover and leaver controls
- Prioritised remediation roadmap
Part of Kilwhiss Group. Explore all nine specialist businesses and their enquiry routes →
How the security review works
We agree the tenant, users, licences and areas to examine before requesting access. The review looks at the controls that protect sign-in, privileged roles, email, endpoints and collaboration. We use available tenant evidence and discuss business exceptions with an authorised contact; a Secure Score value is useful context, not a complete measure of security.
Access and evidence requirements are agreed as part of the scope. We do not ask for passwords or recovery codes through the website form. Where a finding depends on a licence or a connected system, the report identifies that dependency rather than assuming a feature is already available.
What the findings should help you decide
- Which changes reduce the most relevant risks first.
- Which settings or admin permissions need further owner approval.
- What can be handled within the existing licensing and what has a separate cost.
- Which changes need testing, a rollback route or user communication.
- Who will own the controls after the review.
The review produces a prioritised action plan. Remediation is separately scoped and authorised; the assessment does not itself make tenant changes. See Services & Pricing for the published Security Review starting range of £950–£1,500 and the exclusions that may affect a proposal.
Security review questions
Will you change settings during the review?
No tenant change is assumed. We agree access and evidence requirements first, then provide findings and recommendations. Approved remediation can be scoped separately.
Does a high Secure Score mean we are secure?
No. It highlights selected Microsoft configuration opportunities, but the review also considers your roles, sharing, email, devices, business context and exceptions.
Can the review lead into ongoing management?
Yes, where appropriate. Managed Microsoft 365 Security can track agreed controls and findings under a separate service scope.
