Microsoft 365 security guide

Microsoft 365 security review: agree priorities with your IT provider

A Microsoft 365 security review is a focused conversation about your current position and what has changed. Use it when taking over a tenant, changing IT providers, adding services or following up agreed remediation. The outcome should be clear decisions, not another reassuring score.

Published · Last reviewed · By CyberProva

Run your free Microsoft 365 security assessment

No card required · Optional read-only Microsoft 365 connection

When is a security review useful?

A baseline ages as people, access and services change. A review can examine those changes without claiming to retest every part of the business.

  • Before or after an IT-provider handover.
  • After an administrator, employee or supplier leaves.
  • When introducing external sharing or new business applications.
  • After remediation, an incident or a material configuration change.

What should you discuss with your provider?

Send your provider a defined scope and the questions you want answered. Ask for dated evidence and make the review proportionate to the change.

  • Which privileged roles or access policies changed?
  • Does the intended MFA coverage still apply?
  • Are forwarding and sharing exceptions still justified?
  • Has recovery evidence been refreshed?
  • Which actions were completed and what proves the outcome?

How do you turn the review into decisions?

Keep three categories visible: settings that were checked, controls supported by reviewed evidence, and unanswered questions. This makes it easier to agree responsibility.

  • Assign owners to the findings requiring action.
  • Record evidence requests and the control they support.
  • Agree target dates and a follow-up review.
  • Escalate questions that need specialist investigation.

How is a review different from an audit?

A review can focus on changes and priorities. An audit may require agreed criteria, deeper testing and independent professional judgement. Ask the provider to state the method and limitations.

  • Define the question before choosing the service.
  • Do not present a limited follow-up review as comprehensive assurance.
  • Keep the previous baseline and the new review dates together.

Make the answer provable

Evidence to request

  • An account and configuration change summary.
  • Evidence showing whether agreed fixes were completed.
  • An updated action list, scope and next review date.

How CyberProva helps

CyberProva helps your organisation and IT provider discuss selected checks, evidence gaps and practical priorities. Start with a baseline assessment and use subsequent assessments to review changes. Scheduled monitoring requires Professional.

See what a Microsoft 365 security assessment should cover →

See exactly what CyberProva checks · Learn how CyberProva assesses security · Review Microsoft permissions

Common questions

Can we review security without changing providers?

Yes. The aim is a clearer evidence discussion with the team responsible for your IT, rather than replacing them.

Does Free include continuous monitoring?

No. Free provides limited lifetime on-demand assessments. Scheduled monitoring is a Professional feature.

Official guidance

Use these sources with your IT provider when reviewing the controls described above.

From assumptions to evidence

See what needs attention in your organisation

Start with a free CyberProva assessment. Review the findings, identify evidence gaps and agree priorities with your IT team.

Free includes 3 lifetime core assessments. Report exports and advanced features require a paid plan.

Run your free assessment →