Microsoft 365 security guide
Microsoft 365 security assessment for small businesses
A useful Microsoft 365 security assessment answers three questions: which controls are working, which claims still need evidence, and what should be fixed first. It combines configuration checks with a review of how your organisation actually uses and manages the service.
Published · Last reviewed · By CyberProva
Run your free Microsoft 365 security assessmentNo card required · Optional read-only Microsoft 365 connection
What should the assessment cover?
Start with a defined scope: your Microsoft 365 environment, people, administrator accounts and connected services. Record any exclusions before interpreting a score.
- Identity: MFA, administrator access and authentication exceptions.
- Email: forwarding, phishing protection and changes to mailbox rules.
- Data access: external sharing, guests and access reviews.
- Recovery: backup coverage, restore testing and incident responsibilities.
How do you run a useful assessment?
Ask your IT team or provider to identify the owner of each control. Review current settings, request missing evidence and give each finding a clear next action.
- Confirm the people, devices and services included.
- Collect dated settings reports and identify anything that could not be checked.
- Separate verified controls from evidence gaps and controls needing action.
- Agree owners and target dates, then reassess after changes.
What does a score tell you?
A score summarises the selected checks. It does not prove that every part of the business is secure, that an attack has never occurred, or that a restore will work.
- Read the findings behind the score.
- Treat missing data as a gap, rather than a pass.
- Do not use a configuration assessment as a substitute for incident investigation or penetration testing.
Assessment, audit or review: which do you need?
An M365 security assessment establishes a baseline. A Microsoft 365 security audit may involve agreed criteria, detailed testing and independent professional judgement. A security review helps revisit the position after changes. Define the scope and deliverables before comparing services.
- Use a baseline assessment to identify selected control gaps and missing evidence.
- Commission specialist audit or penetration-testing work when the question requires it.
- Use follow-up reviews to check whether agreed changes were completed.
Make the answer provable
Evidence to request
- A scope statement and dated settings exports.
- MFA and privileged-access review records.
- A recent restore-test record and named remediation owners.
How CyberProva helps
CyberProva combines selected read-only Microsoft 365 checks with evidence-based controls. You can start without connecting Microsoft 365, record evidence gaps and work through the findings with your IT provider.
Compare baseline checks with a Microsoft 365 security audit · Plan a follow-up security review
See exactly what CyberProva checks · Learn how CyberProva assesses security · Review Microsoft permissions
Common questions
Is Microsoft Secure Score enough?
It is a useful signal about selected Microsoft recommendations. Review the individual recommendations and your wider evidence; a score alone does not cover every business control.
Does the assessment change our settings?
CyberProva's Microsoft 365 connection is read-only. Your authorised IT team makes any agreed changes.
Is an Office 365 security assessment different?
Office 365 security assessment is often used to describe a review of the same Microsoft cloud environment. Agree the specific tenant, services, users and devices in scope rather than relying on the name alone.
Official guidance
Use these sources with your IT provider when reviewing the controls described above.
From assumptions to evidence
See what needs attention in your organisation
Start with a free CyberProva assessment. Review the findings, identify evidence gaps and agree priorities with your IT team.
Free includes 3 lifetime core assessments. Report exports and advanced features require a paid plan.