Identity and privilege

Verify MFA coverage and strength, Conditional Access, Global Administrators, privileged roles, legacy authentication, password controls, guest lifecycle and device compliance. Exceptions must be visible, justified and monitored.

  • MFA and Conditional Access
  • Privileged roles and emergency access
  • Legacy authentication
  • Guests and device compliance

Email, applications and data

Review forwarding, suspicious inbox rules, Defender protections, application consent, third-party applications, DLP, external sharing and SharePoint/OneDrive permissions. These controls must reflect how people actually collaborate.

  • Mailbox forwarding and rules
  • Defender and identity protection
  • Application consent
  • DLP and sharing permissions

What the assessment should deliver

The output should include evidence, affected scope, prioritized risks, quick wins, longer-term controls, accountable owners and a validation plan. Common gaps include incomplete MFA, excessive privilege, unmanaged guests, unsafe consent and insufficient logging.

Questions leaders ask

Is enabling MFA enough?

No. Coverage, phishing resistance, exceptions, privileged access and Conditional Access design determine effectiveness.