When this assessment helps
A growing Microsoft 365 environment can accumulate stale accounts, broad application permissions and inconsistent device policies. IT leaders need to know which of those conditions are present, what evidence supports them and which changes deserve attention first.
This assessment supports organisations reviewing their tenant, preparing a security improvement programme or bringing a newly connected environment into regular reporting. Start with the business services and user groups that matter to you, then agree which parts of the tenant will be assessed.
What can be included
The supported Microsoft connection can collect directory and group information, administrative role assignments, application consent and credential-expiry context, Conditional Access policies, MFA registration, and available sign-in and audit activity. These sources help explain access exposure beyond a single headline score.
Depending on the agreed permissions and licensing, the scope can also include Intune device inventory and compliance, Defender alerts and incidents, Microsoft Secure Score, SharePoint sharing context and selected mailbox evidence. Specific Exchange and Purview checks require separate access arrangements. We establish that coverage before relying on a finding.
What the assessment gives you
ThreatShield brings collected evidence into assessment reporting, technical findings and leadership priorities. The useful output is a reviewable account of the conditions observed, the systems or identities affected, and the work needed to investigate or improve them.
For example, an MFA registration gap is a reason to review the affected accounts and access policies. Registration alone does not establish that MFA is enforced at every sign-in. Keeping those distinctions visible helps the team choose an appropriate action and define the evidence needed to confirm it.
Permissions, coverage and next steps
Begin with the assessment questions, confirm the authorised tenant and review the requested access. Read-only Microsoft collection is available for assessment; it is distinct from permission to administer accounts, policies or devices. Some deeper checks require additional permissions or separately authorised administrative access.
Licensing, consent, retention and collection health affect what can be assessed. An unavailable feed is a coverage gap. After reviewing the results, agree owners and priorities, authorise any change through the appropriate process, and collect fresh evidence for the next review.
Questions about Microsoft 365 security assessment
Can we start with a read-only assessment?
Yes. ThreatShield supports a read-only Microsoft collection tier. The proposed scope should identify checks that need additional permissions or separate administrative access before consent is requested.
Does Microsoft Secure Score cover the whole assessment?
Secure Score is one source of context. The assessment can also use identity, policy, device and activity evidence, with coverage limited to the sources available in your tenant.
Will the assessment automatically change our tenant?
Read-only assessment access does not authorise changes. Remediation requires the relevant permissions and the applicable approval and action policies.
