A focused first step
Is your Microsoft 365
actually secure?
We review the identities, email and cloud access attackers target first, then give management and your IT provider a clear plan to close the gaps.
Prefer to check the basics first? Take the free health check.
What we review
The gaps behind
real incidents.
This is not a settings checklist. We connect identities, permissions and controls into the attack paths they create, then rank what needs fixing now and what can wait.
Identity and access
- Entra ID and Microsoft 365 configuration
- MFA (multi-factor authentication), conditional access and admin roles
- Inactive users, guests and service identities
Email and data exposure
- Exchange Online and email authentication
- SharePoint, OneDrive and Teams sharing
- The data exposed by a compromised account
Applications and assurance
- Third-party applications and permissions
- Unused security features in your licences
- CIS security benchmark checks and likely attack paths
What you receive
A plan your IT
provider can use.
The documentation works for management, technical teams, boards, insurers and prospective clients.
Configuration Findings Report
A plain-English breakdown of the M365 gaps we found, ranked by real-world risk. Written so management can understand what matters and what happens next.
Identity and Access Map
A clear picture of admin roles, guest accounts, overprivileged users, service identities and third-party application permissions.
Remediation Playbook
Step-by-step fix instructions for every finding. Structured so your IT provider can work through it directly without needing us to interpret it. Quick wins highlighted separately.
Walk-Through Call
We walk through every finding with your team and answer questions. It comes with every engagement, at no extra charge.
How it works
Ten days.
One clear plan.
No disruption and no open-ended consulting. Every phase is included as standard, with one experienced reviewer responsible from scope to handover.
Scope and read-only access
We confirm the Microsoft 365 tenant, users and licences in scope with you and your IT provider. Read-only access is all we need and we make no changes during the review.
Review and risk analysis
We connect identities, privileges, applications, email controls, sharing and available security features into the real paths an attacker could use.
Report, playbook and walkthrough
You receive the peer-reviewed findings and prioritised remediation playbook. We walk management and IT through what gets fixed first and who owns it.
A current baseline
Microsoft 365 changes. The review changes with it.
We keep the methodology aligned with current Microsoft guidance, CIS benchmarks and the control failures we continue to see during real incidents.
Use the Microsoft 365 security reset checklistFixed scope. Honest outcome.
A useful answer.
Either way.
At the handover, one of three things happens
Your tenant is in good shape
Your IT provider receives the remaining fix list. You reassess in 12 months and no ongoing engagement is required.
The Microsoft 365 findings need work
Your IT provider implements the changes. Cubit can guide the work and independently verify the critical fixes.
The risk extends beyond Microsoft 365
We show you the evidence and scope a broader assessment only where the findings justify looking further.
Cubit does not sell software or receive commissions on recommendations. The advice stays independent of the tools and providers involved.
Need a broader review?
A Breach Prevention Assessment adds endpoints, networks, backups and vendor access. We recommend it only when your findings or known risk justify looking beyond Microsoft 365.
Common questions
Before
we begin.
How long does a Microsoft 365 security review take?
Most reviews complete within five to ten business days from kick-off to report delivery. The exact timeline depends on tenant size and complexity. We agree on a schedule before we begin.
Do you need admin access to our Microsoft 365 tenant?
We use documented read-only roles such as Global Reader wherever possible. We record exactly what access was granted and remove it after the review. We never make changes to your environment during the assessment.
We already have an IT provider managing Microsoft 365. Why do we need a review?
Managed service providers set up M365 tenants to work, not to be secure. In most tenants we review, legacy authentication is still enabled, conditional access policies are not configured, and admin accounts have no MFA enforced. These are not edge cases. They are the default state of the average MSP-managed M365 tenancy. Your IT provider is not doing anything wrong by their brief. A security review is a different brief.
What parts of Microsoft 365 do you review?
The standard scope covers Entra ID, Exchange Online, SharePoint, OneDrive, Teams, privileged identities, third-party applications, logging and the security features available under your licences. Wider Azure or infrastructure work is scoped separately when needed.
Can we use the review report for cyber insurance applications?
Yes. Cloud security configuration is one of the areas insurers now specifically ask about. Our report documents your current posture, the gaps we found, and the remediation steps you are taking. Several clients have used it to support better premiums or satisfy underwriter requirements.
What happens after the review?
Your IT provider can execute the remediation playbook directly. If you want independent oversight, Cubit can guide and verify the fixes. Security Stewardship is available only after completing our broader Breach Prevention Assessment.
Prevention, not panic.
Ready to review
your Microsoft 365?
We respond within one business day.