Consulting Service

Microsoft 365 Security &
Compliance Assessment

Get an expert review of your Microsoft 365 tenant and identify security, compliance, and governance gaps before they become audit findings.

Most Microsoft 365 tenants have hidden compliance gaps

These are the findings we most commonly encounter during assessments — issues that are invisible until an auditor or attacker looks for them.

MFA not fully enforced across all users and admins

Guest users never reviewed or offboarded

Weak or misconfigured Conditional Access policies

Excessive privileged access assignments

No structured evidence trail for auditors

Low Microsoft Secure Score with no remediation plan

What the assessment covers

Each area is reviewed against Microsoft security baselines and mapped to ISO 27001 and SOC 2 control requirements where applicable.

Microsoft Secure Score Review

We review your current Secure Score, identify the highest-impact improvement actions, and explain what each recommendation means in terms of real risk — not just a number.

Multi-Factor Authentication Review

Coverage across all users, admin accounts, and service principals. We identify MFA gaps, legacy authentication exposure, and accounts that would be most impactful to secure first.

Conditional Access Review

Which policies are active, which users and applications they cover, and what attack paths remain open. We flag policies with conflicting configurations or unintended exclusions.

Guest User Governance Review

An inventory of guest accounts, their access levels, last activity, and whether a review process exists. Guest sprawl is one of the most commonly overlooked compliance gaps in M365.

Privileged Access Review

Global admin assignments, permanent vs. eligible roles, PIM usage, emergency access accounts, and whether privileged accounts are adequately protected.

Compliance & Evidence Readiness Review

Audit log configuration, evidence collection practices, and how well your current M365 setup maps to ISO 27001 or SOC 2 control requirements.

Executive Summary Report

All findings delivered in a structured written report — suitable for your IT team, CISO, board, or external auditor. Risk-rated and prioritised.

What you receive

The assessment is delivered as a structured written report — not a dashboard login or a raw export. Something you can share with your auditor, board, or security team.

  • Executive summary with key findings
  • Risk observations with severity ratings
  • Recommended remediation actions, prioritised by impact
  • Compliance readiness observations for ISO 27001 and SOC 2
  • Prioritised improvement roadmap
  • Written report suitable for auditors, boards, or enterprise customers

Report structure

Executive Summary

High-level findings for management

Detailed Findings

Technical findings, risk-rated

Compliance Observations

ISO 27001 · SOC 2 mapping

Improvement Roadmap

Prioritised by risk impact

Who this is for

The assessment is designed for organisations that run on Microsoft 365 and need a clear, structured picture of their security and compliance posture.

IT Managers

Get a clear picture of your M365 security posture and a prioritised list of what to fix — without spending weeks on manual configuration reviews.

Microsoft 365 Administrators

Validate your configuration against security baselines and get specific, actionable guidance — not just a Secure Score percentage.

Compliance Teams

Understand how your current M365 configuration maps to ISO 27001 or SOC 2 requirements before your audit begins.

SaaS Companies

Enterprise customers increasingly require evidence of a security review. A structured assessment report satisfies most due diligence questionnaires.

MSPs

Offer a security assessment as a managed service to your clients. Certvik can support MSPs reviewing multiple M365 tenants.

ISO 27001 & SOC 2 Preparation

Preparing for certification? A pre-audit M365 assessment identifies the gaps your auditor will find — before they do.

How it works

A structured process from initial request to report delivery — typically completed within 5–7 business days.

01

Assessment Request

Submit the form below. We'll confirm scope, timeline, and any access requirements within 1 business day.

02

Microsoft 365 Review

We review your M365 tenant configuration using read-only access — no disruption to your production environment.

03

Findings Analysis

Findings are analysed against security baselines and compliance frameworks. Each observation is risk-rated.

04

Executive Report Delivery

You receive a structured written report with findings, risk ratings, and a prioritised improvement roadmap.

05

Optional: Remediation & Certvik Platform

If remediation support or ongoing compliance monitoring would be useful, we can discuss how Certvik's platform helps.

Get started

Request your assessment

Fill in the form and we'll be in touch within 1 business day to discuss scope, timeline, and next steps.

We review every request personally and reply within 1 business day.

Why Certvik

Microsoft 365 focused — not a generic security checklist

ISO 27001 readiness observations included

SOC 2 readiness observations included

Read-only access — no disruption to production systems

Written report delivered, not just a dashboard

Frequently asked questions

What does the assessment include?

The assessment covers Microsoft Secure Score, MFA coverage, Conditional Access configuration, guest user governance, privileged access assignments, audit log setup, and compliance readiness for ISO 27001 and SOC 2. All findings are delivered in a written executive summary report.

Do you need Global Administrator access?

No. We use read-only access scoped to security and configuration data via the Microsoft Graph API. We never store, read, or analyze the content of emails or documents — mailbox access is limited to detecting risky admin forwarding rules. We can discuss the exact permissions required during the scoping call.

Can this help with ISO 27001 readiness?

Yes. The report includes compliance readiness observations that map your M365 configuration to ISO 27001:2022 controls. This is useful as a pre-audit review or to identify control gaps before formal certification.

Can MSPs use this service for clients?

Yes. Certvik works with MSPs who want to offer a security assessment as part of their service catalogue. Contact us to discuss multi-tenant arrangements.

Do you provide remediation guidance?

Yes. Every finding in the report includes a recommended remediation action, prioritised by risk impact. We can also discuss ongoing remediation support and the Certvik platform for continuous compliance monitoring.

Understand your Microsoft 365 security posture

Get an expert review of your M365 tenant before your next audit, a new enterprise customer asks, or a security incident forces the question.