Microsoft 365 security guide
Microsoft 365 security review: agree priorities with your IT provider
A Microsoft 365 security review is a focused conversation about your current position and what has changed. Use it when taking over a tenant, changing IT providers, adding services or following up agreed remediation. The outcome should be clear decisions, not another reassuring score.
Published · Last reviewed · By CyberProva
Run your free Microsoft 365 security assessmentNo card required · Optional read-only Microsoft 365 connection
When is a security review useful?
A baseline ages as people, access and services change. A review can examine those changes without claiming to retest every part of the business.
- Before or after an IT-provider handover.
- After an administrator, employee or supplier leaves.
- When introducing external sharing or new business applications.
- After remediation, an incident or a material configuration change.
What should you discuss with your provider?
Send your provider a defined scope and the questions you want answered. Ask for dated evidence and make the review proportionate to the change.
- Which privileged roles or access policies changed?
- Does the intended MFA coverage still apply?
- Are forwarding and sharing exceptions still justified?
- Has recovery evidence been refreshed?
- Which actions were completed and what proves the outcome?
How do you turn the review into decisions?
Keep three categories visible: settings that were checked, controls supported by reviewed evidence, and unanswered questions. This makes it easier to agree responsibility.
- Assign owners to the findings requiring action.
- Record evidence requests and the control they support.
- Agree target dates and a follow-up review.
- Escalate questions that need specialist investigation.
How is a review different from an audit?
A review can focus on changes and priorities. An audit may require agreed criteria, deeper testing and independent professional judgement. Ask the provider to state the method and limitations.
- Define the question before choosing the service.
- Do not present a limited follow-up review as comprehensive assurance.
- Keep the previous baseline and the new review dates together.
Make the answer provable
Evidence to request
- An account and configuration change summary.
- Evidence showing whether agreed fixes were completed.
- An updated action list, scope and next review date.
How CyberProva helps
CyberProva helps your organisation and IT provider discuss selected checks, evidence gaps and practical priorities. Start with a baseline assessment and use subsequent assessments to review changes. Scheduled monitoring requires Professional.
See what a Microsoft 365 security assessment should cover →
See exactly what CyberProva checks · Learn how CyberProva assesses security · Review Microsoft permissions
Common questions
Can we review security without changing providers?
Yes. The aim is a clearer evidence discussion with the team responsible for your IT, rather than replacing them.
Does Free include continuous monitoring?
No. Free provides limited lifetime on-demand assessments. Scheduled monitoring is a Professional feature.
Official guidance
Use these sources with your IT provider when reviewing the controls described above.
From assumptions to evidence
See what needs attention in your organisation
Start with a free CyberProva assessment. Review the findings, identify evidence gaps and agree priorities with your IT team.
Free includes 3 lifetime core assessments. Report exports and advanced features require a paid plan.