What a Microsoft 365 security assessment covers for a 20–200 person business
Short answer
A Microsoft 365 security assessment is a read-only review of how your tenant is configured against Microsoft's guidance and ASD's Essential Eight. It covers sign-in and Conditional Access, administrator roles, email and collaboration protection, data loss prevention, audit logging and your Microsoft Secure Score. CyberByte Security's assessment is from $7,500 ex GST, a fixed price for the agreed scope, typically over 1–2 weeks.
Written by Muhammad Gulzar, Founder & Principal Security Consultant
Principal Security Consultant · Enterprise & government experience · 10+ years across IT, cloud & cyber
Last reviewed October 2026 · General information only, current as at the review date — not professional advice for your specific circumstances.
Who this is for
This guide is for organisations of roughly 20–200 staff that run on Microsoft 365 and have not had the tenant independently reviewed. Common triggers are a phishing or account-takeover scare, a client security questionnaire, an insurer renewal, or a board asking for evidence rather than reassurance. It also suits organisations with a managed service provider (MSP) that want an independent second view of the configuration.
Why Secure Score is a starting point, not the answer
Microsoft describes Secure Score as a measurement of an organisation's security posture, with a higher number indicating more recommended actions taken. It is useful, and every assessment should capture it, but it needs interpretation:
- Microsoft shows the full set of possible recommendations for a product regardless of your licence, so some actions may need licences you do not have.
- Each recommended action is worth 10 points or less. Some are scored all-or-nothing, others as a percentage of users or devices covered.
- Actions can be marked as addressed by a third-party tool or an alternate mitigation, or as an accepted risk, which changes the score without changing the configuration.
A good assessment explains which recommendations matter for your risk and obligations, and in what order, rather than chasing points.
What the assessment reviews
| Area | What is reviewed | Why it matters |
|---|---|---|
| Sign-in and Conditional Access | MFA coverage, Conditional Access policies, security defaults, legacy authentication | Microsoft recommends blocking legacy protocols that don't support multifactor authentication |
| Administrator access | Global Administrator count, role assignments, emergency access accounts, Privileged Identity Management where licensed | Microsoft recommends fewer than five Global Administrators and two or more cloud-only emergency access accounts |
| Email and collaboration | Built-in mailbox protection, anti-phishing settings and Defender for Office 365 policies where licensed | Microsoft describes Defender for Office 365 as its primary email and collaboration security solution, with features such as Safe Links and Safe Attachments |
| Data protection | Sharing settings and Purview data loss prevention (DLP) across Exchange, SharePoint, OneDrive and Teams | DLP policies help identify, monitor and protect sensitive information |
| Audit and visibility | Whether the unified audit log is searchable, who can search it, and how long records are kept | Audit (Standard) keeps records for 180 days, which may be shorter than an investigation needs |
| Posture | Current Secure Score and a prioritised target state | Turns findings into a measurable plan |
Licensing changes what is possible
Two tenants with the same number of staff can need very different recommendations because of licensing. Microsoft notes that if you have Microsoft Entra ID P1 or P2 licences, security defaults are probably not right for you, and that organisations with complex requirements should consider Conditional Access. Defender for Office 365 Plan 1 is included in some subscriptions aimed at small and medium businesses, such as Microsoft 365 Business Premium. An assessment should confirm what you are entitled to before recommending anything, so the plan does not assume features you have not paid for.
How it relates to the Essential Eight
Two of the eight strategies, multi-factor authentication and restricting administrative privileges, are partly configured in Microsoft Entra ID for cloud services, so a tenant review can produce useful evidence for them. It is not an Essential Eight assessment: application control, patching, macro settings, user application hardening and backups are enforced mainly on devices and servers, and assessing them needs device-level evidence that a tenant review does not collect. If an insurer or client has asked for a maturity level, read what an Essential Eight assessment involves and costs.
What a careful review avoids
An assessment is read-only by default. Changes come afterwards and are best tested first. Microsoft's report-only mode lets administrators evaluate most Conditional Access policies before enforcing them, with results logged in the sign-in logs. Microsoft also recommends excluding emergency access accounts from Conditional Access policies so that a misconfigured policy cannot lock every administrator out. A useful report sequences changes in that spirit: test, stage, then enforce.
It is also not a penetration test. A configuration review checks how settings are set; a penetration test checks what an attacker could actually do. Read how to scope a penetration test if you need both.
What you receive
- Your current Microsoft Secure Score, with a prioritised target-state improvement plan and an indicative Secure Score improvement opportunity where technically supportable.
- An identity and Conditional Access review covering MFA, legacy authentication and admin roles.
- A Defender and Purview configuration review against Microsoft and ASD guidance.
- A prioritised hardening plan, quick wins first and then structural fixes, that your IT team or MSP can work from.
See the format on the sample deliverables page.
Cost and timeline
CyberByte Security's Microsoft 365 Security Assessment is from $7,500 ex GST and typically takes 1–2 weeks. The price assumes one tenant, an agreed user range and a read-only review; implementation is scoped separately. If you would like the changes made for you, a Microsoft Security Hardening Sprint is from $12,000 ex GST through our Security Remediation service. The exact fixed price for the agreed scope is confirmed in writing after a short scoping call, and all published prices are on the packages page.
How CyberByte would approach it
We would start with a short scoping call to confirm the tenant, user range, licences and who manages the environment. With read-only access, we would capture the current Secure Score and configuration, then work through identity, administrator access, Defender, Purview and auditing. Findings would be rated by risk and tied to the Secure Score and Essential Eight controls they affect, so you and your MSP could see why each change matters and in what order to make it. More detail is on the Microsoft 365 Security page.
Want a head start? Download the free Microsoft 365 Security Quick-Wins Checklist below, then request a scoping call when you are ready.
Common questions
Do you change our settings during the assessment?
No. The assessment is read-only by default. You or your MSP apply the changes using the plan, or we can implement them for you as a separately scoped Microsoft Security Hardening Sprint.
Do we need Microsoft 365 E5 for a useful assessment?
No. The review works with the licences you have and identifies where a licence would unlock a control that matters for your risk. Recommendations are prioritised so that you can act on the highest-value items within your current entitlements first.
Our MSP manages Microsoft 365. Is this a conflict?
It is designed to complement them. An independent review gives your MSP a prioritised list to work from and gives you a second view of whether the configuration matches your risk.
Will our Secure Score reach a particular number?
We give an indicative improvement opportunity where it is technically supportable, but the score depends on which changes you choose to make, your licences, and how Microsoft scores each action, so no specific number is promised.
Authoritative sources
- Microsoft Learn — Microsoft Secure Score, accessed 2 October 2026
- Microsoft Learn — Conditional Access overview, accessed 2 October 2026
- Microsoft Learn — Block legacy authentication with Conditional Access, accessed 2 October 2026
- Microsoft Learn — Security defaults in Microsoft Entra ID, accessed 2 October 2026
- Microsoft Learn — Best practices for Microsoft Entra roles, accessed 2 October 2026
- Microsoft Learn — Manage emergency access accounts, accessed 2 October 2026
- Microsoft Learn — Conditional Access report-only mode, accessed 2 October 2026
- Microsoft Learn — Microsoft Defender for Office 365 overview, accessed 2 October 2026
- Microsoft Learn — Learn about data loss prevention (Purview), accessed 2 October 2026
- Microsoft Learn — Purview auditing solutions, accessed 2 October 2026
- ASD — Essential Eight maturity model (November 2023), accessed 2 October 2026
Microsoft 365 Security Quick-Wins Checklist
Drop your email and we'll send the Microsoft 365 Security Quick-Wins Checklist straight to your inbox.
No spam. Unsubscribe from marketing at any time.
Request a scoping call
Talk to a senior advisor.
A 20-minute scoping call: tell us what's prompting this, and we'll tell you the smallest credible engagement that solves it. Fixed price for the agreed scope, no obligation.
- 10+ years across IT, cloud & cyber
- Enterprise & government experience
- Principal consultant-led delivery
- Independent & Australian-owned
- Melbourne-based · Australia-wide