Microsoft 365 Review
Complete M365 security assessment
A comprehensive security review of your Microsoft 365 environment. Including configuration analysis, policy assessment and concrete recommendations. Performed together with the Attic platform.
What is a Microsoft 365 Review?
A Microsoft 365 Review is a security assessment of your complete M365 environment. We analyse Exchange Online, SharePoint, OneDrive, Teams, Entra ID, Intune, Defender and all other M365 services. The goal: find misconfigurations that expose your organisation to data leaks, account takeover or unauthorised access.
We perform this review with Attic Security - our own platform for M365 monitoring. We built Attic because we saw organisations reverting to insecure configurations after a one-time review. Attic automatically scans your tenant for hundreds of misconfigurations and compares against CIS Benchmarks. Our researchers then manually analyse the results and deliver a prioritised report.
What do we assess?
- Exchange Online - mailflow rules, external forwarding, anti-phishing policies, DMARC/DKIM/SPF.
- SharePoint & OneDrive - sharing settings, guest access, anonymous links, document sensitivity.
- Teams - external sharing, guest policies, app permissions.
- Entra ID - MFA, conditional access, password policies, legacy authentication, PIM.
- Intune - compliance policies, device configuration, app protection.
- Defender - threat policies, safe links/attachments.
- Audit & Compliance - unified audit logging, DLP, retention policies.
Why should you get a Microsoft 365 Review?
Virtually every Dutch organisation uses M365. The default configuration is not secure:
- External sharing is open: SharePoint and OneDrive share with external parties by default, including anonymous links.
- Mail forwarding rules: attackers configure forwarding to external - rarely detected.
- Legacy authentication bypasses MFA: old protocols are often still enabled.
- Excessive guest access: external guests have more access than necessary.
- Audit logging off: must be explicitly enabled - many organisations have not done this.
Our approach
We built Attic Security. Nobody knows M365 security better than we do:
- Attic Security scan - automated scan for hundreds of configuration points.
- Manual analysis - our researchers review results, identify false positives and analyse context.
- Risk prioritisation - each finding assessed on actual impact and exploitability, not just compliance.
- Quick wins - which changes can you implement today for immediate improvement?
- Reporting - management summary, prioritised findings, step-by-step implementation guide.
- Optional: implementation support - we help implement if your IT team wants it.
What does a Microsoft 365 Review cost?
Fixed package price of €3,000 (excl. VAT). This includes:
- Attic Security scan
- Manual analysis by an M365 security researcher
- Prioritised report with concrete recommendations
- Presentation of results
Frequently asked questions
What is the difference between an M365 Review and an Azure / Entra ID Assessment?
The M365 Review focuses on all M365 services: Exchange, SharePoint, Teams, Intune, Defender. The Azure / Entra ID Assessment goes deeper into identity management and Azure cloud resources. We regularly combine both - that is our recommendation for a complete picture.
How long does the review take?
Turnaround: 1-2 weeks from start to report. The Attic scan runs in hours; manual analysis and reporting take the majority of the time. We work efficiently because we built the tooling ourselves.
What permissions do you need?
A Global Reader or Security Reader account. Read-only - we change nothing. We only ask for what is needed.
Can you also help implement recommendations?
Yes. From conditional access policies to Exchange configuration - we help with implementation if your team wants it. Quoted separately based on hours. Short lines: you call the person who wrote the report.
Ready to test your security?
Get in touch with our team for a no-obligation conversation about your security challenges.