Identity and privilege
Verify MFA coverage and strength, Conditional Access, Global Administrators, privileged roles, legacy authentication, password controls, guest lifecycle and device compliance. Exceptions must be visible, justified and monitored.
- MFA and Conditional Access
- Privileged roles and emergency access
- Legacy authentication
- Guests and device compliance
Email, applications and data
Review forwarding, suspicious inbox rules, Defender protections, application consent, third-party applications, DLP, external sharing and SharePoint/OneDrive permissions. These controls must reflect how people actually collaborate.
- Mailbox forwarding and rules
- Defender and identity protection
- Application consent
- DLP and sharing permissions
What the assessment should deliver
The output should include evidence, affected scope, prioritized risks, quick wins, longer-term controls, accountable owners and a validation plan. Common gaps include incomplete MFA, excessive privilege, unmanaged guests, unsafe consent and insufficient logging.
Questions leaders ask
Is enabling MFA enough?
No. Coverage, phishing resistance, exceptions, privileged access and Conditional Access design determine effectiveness.
