Recommended projects
Identity and Conditional Access
Most break-ins start with a stolen password, and admin accounts are the biggest prize. Requiring a second factor everywhere, blocking the old sign-in methods that can't ask for one and locking down admin accounts stops nearly all of them.
What we found
- highLegacy authentication is allowed Legacy authentication is blocked
- high14 users without MFA Every active user has MFA registered
- high1 guest with admin roles No guests hold admin roles
- high1 admin not covered by MFA Every admin is covered by an MFA policy
- mediumEnforced by Require MFA for all users, with 1 exclusion to review MFA is enforced for all users
- medium1 app with privileged roles Apps with admin roles are reviewed
- medium2 admins without a phishing-resistant method Admins use phishing-resistant sign-in methods
- low3 people can only use a text or call as a second factor Nobody relies on a text or call as their only second factor
What the project covers
- Conditional Access policies: MFA for everyone, legacy sign-in blocked, break-glass accounts
- MFA registration drive, moving people off text and call codes to the Authenticator app
- Admin accounts: the right number of Global Administrators, cloud-only, phishing-resistant sign-in
- Risky sign-in and risky user handling
- Report-only rollout first, so nobody is locked out
Last changed by demo, 3 hours ago.
Email security
Email is how most attacks arrive and how fraud gets paid. Locking down the domain stops others pretending to be the business, and closing forwarding and old protocols stops mail leaking out.
What we found
- high4 external forwards No mail is forwarded outside the organisation
- high1 suspicious inbox rule No inbox rules hide mail
- medium2 domains without DMARC enforcement Every domain enforces DMARC
- medium1 mail domain without DKIM DKIM signing is on for every mail domain
- low1 domain with SPF problems Every domain has a working SPF record
- low1 of 1 mail domain doesn't fully enforce MTA-STS Mail domains require encrypted delivery (MTA-STS)
- lowSMTP AUTH is on for the organisation SMTP AUTH is turned off
What the project covers
- SPF, DKIM and DMARC set up and enforced for every domain
- Encrypted delivery (MTA-STS and TLS reporting)
- External forwarding and suspicious inbox rules removed and blocked
- SMTP AUTH turned off, mailbox auditing on, shared mailboxes locked
Last changed by demo, 3 hours ago.
Device management with Intune
Company data lives on laptops and phones. Managing them means they're encrypted, kept up to date and can be wiped if lost, and unmanaged devices can be kept away from company data.
What we found
- high4 of 36 computers not encrypted Company computers are encrypted
- medium6 of 37 managed devices not compliant Managed devices meet compliance policies
- low1 of 37 joined computers not in Intune Joined computers are managed by Intune
- low3 devices haven't checked in for 30+ days Managed devices check in with Intune
- low1 of 39 device records unused for 90+ days No old devices left in Entra ID
What the project covers
- Intune enrolment for every company computer (Autopilot for new ones)
- Compliance policies: encryption, updates, antivirus, screen lock
- BitLocker with recovery keys stored in Entra ID
- Clean-up of old devices
Windows upgrade and hardware refresh
Computers on a Windows version that no longer gets security updates stay open to every flaw found from now on. Upgrading, or replacing machines that can't upgrade, closes that gap.
What we found
- high5 of 36 Windows computers past end of support Windows computers still get security updates
What the project covers
- Which computers can upgrade in place and which need replacing
- Upgrades scheduled around the working day
- Replacement hardware quoted and set up
| What we found | Priority | What to do | Estimate |
|---|---|---|---|
| 1 admin without MFA, and 1 whose registration isn't knownEvery admin has MFA registered | critical | Have each listed admin register a strong method | Under an hour |
| 3 files and folders shared with anyoneNo files are shared with anyone links | high | Remove anyone links that are no longer needed, and set the rest to view-only with an expiry date | Under an hour |
| 1 site with no owner, 2 sites with one ownerEvery site has at least two owners | high | Give each site a second owner | About 1 hour |
| 1 app with access to mail, files or the directoryThird-party apps hold only the access they need | high | Review each app with the client | Under an hour |
| 1 domain had sign-in settings changed in the last 30 daysNo unexpected changes to how domains sign in | high | Confirm with the client that each change was planned | Under an hour |
| 1 guest with full control of 1 siteGuests don't have full control of sites | high | Take guests out of each site's owners group and away from Full Control; give them Edit or Read through the site's members or visitors group instead | Under an hour |
| 4 teams and groups without an ownerEvery team and Microsoft 365 group has an owner | medium | Make an active person, ideally two, an owner of each listed team or group | About 1 hour |
| 4 accounts inactive for 90+ days or never usedNo inactive accounts | medium | Disable accounts that haven't signed in for 90 days, or were created over 30 days ago and never used | About 1 hour |
| 3 mailboxes at or over 90% of quotaNo mailbox is nearly full | medium | Turn on the online archive for each listed mailbox | About 2 hours |
| Users can consent to any appUsers can't consent to apps on their own | medium | Set user consent to "Allow user consent for apps from verified publishers, for selected permissions" or turn it off and use the admin consent workflow | Under an hour |
| Anyone, including anonymous linksFiles can't be shared with anonymous links | medium | Change SharePoint external sharing to "New and existing guests" | Under an hour |
| 1 disabled account still licensedNo licences on disabled accounts | medium | Remove licences from disabled accounts, or convert leavers' mailboxes to shared mailboxes | Under an hour |
| 1 file or folder outside people can editPeople outside can only view shared files | medium | Change sharing with people outside the organisation to view-only unless they need to edit, and remove sharing that's no longer needed | Under an hour |
| Links and attachments in email aren't checked when they're openedNo Defender for Office 365 | medium | Add Defender for Office 365 Plan 1 and turn on Safe Links and Safe Attachments | About 2 hours |
| 2 subscriptions with spare licencesNo paid licences sit unassigned | low | Reduce the subscription quantity at the next renewal, or assign the spare licences | Under an hour |
| 1 app registration with expiring or expired credentialsApp secrets and certificates are current | low | Renew credentials before they expire to avoid an outage, and delete app registrations whose credentials have all expired if nothing uses them any more | Under an hour |
| Any user can register an appUsers can't register apps | low | Set "Users can register applications" to No | Under an hour |
| Anyone, including guests, can invite guestsOnly admins and members can invite guests | low | Restrict guest invitations to admins and the Guest Inviter role, or at least to members, under External collaboration settings | Under an hour |
| 1 account reports to a blocked managerNo account reports to a blocked manager | low | Set a current manager on each listed account | Under an hour |