Cambridge: 01223 209920        London: 020 3519 0124        Ireland: +353 1697 2287        Sheffield: 0114 349 8054        Suffolk: 0144 059 2163         Email: Lucy@breathetechnology.com
What a Microsoft 365 Security Assessment Finds

What a Microsoft 365 Security Assessment Finds

A compromised Microsoft 365 account rarely starts with a dramatic technical failure. More often, it begins with a convincing phishing email, a reused password, an old user account that was never removed, or a sharing setting that made sensitive information easier to reach than anyone realised. A Microsoft 365 security assessment shows where those everyday weaknesses exist before an attacker, accidental data leak or compliance issue turns them into a costly incident.

For a business, school or multi-academy trust, the aim is not simply to achieve a better security score. It is to understand whether the Microsoft 365 tenant protects people properly while allowing them to work without constant friction. That means looking beyond a single setting and examining the whole picture: identities, devices, email, files, collaboration, monitoring and the processes around them.

What a Microsoft 365 security assessment should examine

Microsoft 365 is a powerful platform, but it is not configured once and left alone. New staff join, licences change, teams create new sites, suppliers need access and users increasingly work across personal mobiles, shared devices and home networks. Each change can alter the organisation’s risk profile.

A worthwhile assessment reviews the technical controls alongside how the organisation actually operates. A blanket policy that looks good in a report but stops a teacher accessing lesson materials or a finance team approving an urgent payment is unlikely to last. The best outcome is practical protection that staff can use confidently.

Identity and access controls

Identity is usually the first priority. If an attacker gains access to a valid user account, they can bypass many perimeter controls and appear to be a legitimate member of staff. The assessment should establish whether multi-factor authentication is in place for all users, especially administrators, and whether the chosen methods are resistant to modern phishing techniques.

It should also review Conditional Access policies. These can restrict access based on risk, location, device compliance or application, but they need careful design. For example, blocking sign-ins from countries where your organisation has no staff may reduce exposure. However, it needs an agreed exception process for employees travelling or a trusted overseas partner.

Other questions matter just as much: Are legacy authentication methods blocked? Are privileged roles assigned only where genuinely needed? Is there a regular review of dormant accounts, guest users and former employees? Are emergency administrator accounts secured, monitored and tested? A single forgotten account can undermine an otherwise sensible security approach.

Email protection and payment fraud risk

Email remains one of the most common routes into an organisation. A proper review looks at Microsoft Defender for Office 365 controls where available, including anti-phishing, anti-malware and safe link protections. It should also check whether phishing policies are applied consistently to everyone, not just a selected group of users.

Domain protections deserve close attention. SPF, DKIM and DMARC help reduce email spoofing, but they must be configured and monitored correctly. This is particularly relevant for organisations that issue invoices, change bank details or communicate regularly with parents, governors, suppliers and external partners. A spoofed message that appears to come from a familiar address can be highly convincing.

Technology alone cannot prevent every fraudulent request. The assessment should identify where financial controls need to sit alongside email security, such as a mandatory telephone verification process for changed bank details or unusual payment instructions. Good security is as much about reducing avoidable pressure on staff as it is about filtering messages.

Devices, mobile access and shared equipment

Microsoft 365 security is closely connected to the devices used to access it. A secure account on an unmanaged, unpatched laptop is still a concern, particularly if sensitive data can be downloaded and stored locally.

An assessment should review how Windows, macOS and mobile devices are enrolled, encrypted, patched and protected. Microsoft Intune and Microsoft Defender for Endpoint can provide valuable visibility and controls, but the configuration must reflect the organisation. A company with staff using managed laptops has different needs from a school with shared classroom devices, a bring-your-own-device policy or a mixture of staff and student accounts.

The balance matters. Requiring compliant devices for access to finance systems may be entirely appropriate. Applying the same rule to every low-risk collaboration tool could create unnecessary disruption. The assessment should help define sensible tiers of access rather than treating every user and device in exactly the same way.

Data sharing, Teams and SharePoint

Microsoft Teams, SharePoint and OneDrive make collaboration quick, which is precisely why sharing settings need scrutiny. Files can be sent externally in seconds, guests can be invited to Teams, and link permissions can live long after a project has ended.

The assessment should test whether external sharing is controlled at tenant, site and user level. It should identify whether anonymous links are permitted, how long sharing links remain active and whether guest access is reviewed regularly. For schools and charities, this may include checking how information is shared with parents, trustees, volunteers and partner organisations. For businesses, it often includes suppliers, auditors, consultants and clients.

Data classification and sensitivity labels can add meaningful protection where they are introduced with a clear purpose. For example, payroll or safeguarding documents may need tighter sharing rules than general marketing material. Yet over-labelling every document can lead users to ignore the system altogether. The right approach depends on the types of data held, the regulatory requirements involved and the capacity available to manage the controls.

Turning findings into a practical action plan

A Microsoft 365 security assessment should not finish with a long technical spreadsheet that lands on someone’s desk and goes untouched. Decision-makers need a prioritised plan that explains what to do first, why it matters and who owns each action.

Immediate actions often include securing administrator accounts, enforcing multi-factor authentication, removing risky legacy access and closing obvious gaps in email or sharing policies. These are the controls most likely to reduce risk quickly. The next stage may involve refining Conditional Access, improving endpoint management, deploying data loss prevention policies or introducing better reporting and review processes.

The plan should distinguish between configuration changes, licensing decisions and operational changes. Not every recommendation is free, and not every recommendation needs a new product. Some improvements are about using existing Microsoft 365 capabilities properly; others require additional licences, managed monitoring or a change in staff behaviour. Clear priorities help finance and operations leaders make informed decisions rather than approving technology because it sounds reassuring.

It is also wise to agree what “good” looks like. This could include a regular review of privileged access, a tested process for leavers, monthly checks of high-risk alerts, quarterly reviews of external guests and phishing awareness training that reflects the threats staff actually see. Security improves through repeatable habits, not a one-off project.

Why regular reviews matter

A tenant that was secure a year ago may no longer be secure today. Microsoft introduces new features, attackers change tactics, and your organisation changes too. An acquisition, a new school site, hybrid working arrangements or a move to cloud telephony can all introduce new identities, devices and data flows.

Regular assessments provide a useful independent check, particularly for sole IT administrators and internal teams already handling day-to-day support. They can validate good work, highlight blind spots and provide the evidence senior leaders need to invest in the right areas. For organisations without an internal IT function, they provide clearer accountability and less uncertainty about whether basic protections are actually in place.

Breathe Technology approaches this work as part of an ongoing security conversation, not a box-ticking exercise. The objective is to give your people safe, reliable access to the tools they need, while making it much harder for an attacker to misuse them.

The most helpful next step is simple: ask who has access to your Microsoft 365 data, from which devices, and what would happen if one of those accounts was compromised this morning. If the answer is unclear, an assessment can turn uncertainty into a focused, manageable plan.

Download the Outsourced IT Support Checklist

Every Manager responsible for IT (Finance, Office Manager, Ops etc), that's not an IT Manager by profession should review their IT Support experience. How do you know if your expectations are realistic, is the team performing, are you at risk and didn't realise? Do you have doubts? Or are they simply great,

This Check Outsourced IT Support Checklist has been created, after performing hundreds of IT Audits over more than 20 years, revealing the most commonly found problems caused by IT Support Providers.

How does yours compare? Download for free today!

(PS. Your details remain confidential and will never be shared with anyone else)