Harbour IT
Monthly Security & Licensing Review

Fabrikam Dental Group

Prepared by
Harbour IT
Report date
11 October 2026
Period covered
13 September to 11 October 2026
Microsoft 365 tenant
fabrikam.onmicrosoft.com
Action needed

Fabrikam Dental Group's Microsoft 365 has a critical security gap that should be fixed now.

Harbour IT · help@harbourit.example · 0161 496 0000
Confidential. This report describes security settings for Fabrikam Dental Group; share it only with people who need it.

At a glance

We ran 54 security checks and 40 need attention (1 critical, 12 high, 15 medium and 12 low priority). The most urgent: 1 admin without MFA, and 1 whose registration isn't known.

On the positive side, 14 checks passed, including “Between 2 and 4 Global Administrators”, “Automatic forwarding to outside addresses is off” and “Shared mailboxes can't be signed in to”.

Since 13 September, Microsoft Secure Score rose from 31% to 33%, users with MFA rose from 47.8% to 50.9%, 2 issues were fixed and 17 new items came up.

About £164.40 a month (£1,972.80 a year) goes on licences that are unused or assigned to disabled or inactive accounts.

7 checks couldn't run because the data or a licence they need is missing.

Key figures

Secure Score
33%Secure Score since 19 Jul 2026: from 30% to 33%
↑ 2 pts since 13 September
Users with MFA
50.9%Users with MFA since 19 Jul 2026: from 42.7% to 50.9%
↑ 3.1 pts since 13 September
Privileged accounts
4Privileged accounts since 19 Jul 2026: from 4 to 4
No change since 13 September
Licensed users
54Licensed users since 19 Jul 2026: from 51 to 54
↑ 4 since 13 September
Inactive accounts
7
Licence waste / month
£164.40
40 of 54 checks need attention
Critical: 1High: 12Medium: 15Low: 12
1 Critical12 High15 Medium12 Low

This month

Findings found and fixed each month FoundFixed
01020May 26May 2026: no data yetJunJune 2026: no data yetJulJuly 2026: no data yetAugAugust 2026: no data yetSep00September 2026: 0 found, 0 fixedOct172October 2026: 17 found, 2 fixed

17 found and 2 fixed since September 2026. Found counts new findings and ones that came back.

What we did

  • Fixed Every active user has MFA registered · 2 items: george.walker@fabrikam.example, ella.hughes@fabrikam.example

What we recommend next

  1. Have each listed admin register a strong method

    1 admin without MFA, and 1 whose registration isn't known. See the detail

  2. Make sure each admin is included in an enabled Conditional Access policy that requires MFA for all apps, and isn't excluded from it directly or through a group

    1 admin not covered by MFA. See the detail

  3. Remove admin roles from guest accounts

    1 guest with admin roles. See the detail

Appendix

The detail

Everything behind the summary: what changed, each finding with the accounts or settings it affects, and licences line by line. The XLSX export has every row.

What changed since 13 September

Findings

2 fixed and 17 new or returning. New ones are also marked New in the checks below.

  • Fixed george.walker@fabrikam.example: No MFA method registered
  • Fixed ella.hughes@fabrikam.example: No MFA method registered
  • New rhys.hall@fabrikam.example: Mailbox forwarding to rhys.hall@homemail.example (doesn't keep a copy)
  • New rhys.walker@fabrikam.example: Mailbox forwarding to rhys.walker@homemail.example (doesn't keep a copy)
  • New DESK-ROBINSON51 (owen.robinson@fabrikam.example): Windows disk isn't encrypted
  • New DESK-ROBINSON51 (owen.robinson@fabrikam.example): Not compliant
  • New Tenant SharePoint storage: 88% of about 1.45 TB used (1 TB + 10 GB × 46 licences)
  • New Budget.xlsx (Finance / Documents): Can be edited by accountant@hargreaves-partners.example
  • New aisha.brown@fabrikam.example: 47.2 GB of 49.5 GB (95%), no archive
  • New thomas.robinson@fabrikam.example: 45.6 GB of 49.5 GB (92%), no archive
  • New DESK-ROBINSON51 (owen.robinson@fabrikam.example): Windows 11 24H2: updates for Home and Pro end 13 Oct 2026.
  • New LAPTOP-SMITH50 (oscar.smith@fabrikam.example): Windows 11 24H2: updates for Home and Pro end 13 Oct 2026.
  • New DESK-ROBINSON51 (owen.robinson@fabrikam.example): Last check-in 38 days ago
  • New https://fabrikam.sharepoint.com/sites/finance: 117.5 GB, of which 3.0 GB in the recycle bin and 7.6 GB older versions
  • New https://fabrikam.sharepoint.com/sites/imaging: 483.2 GB, of which 46.0 GB in the recycle bin and 33.3 GB older versions
  • New https://fabrikam.sharepoint.com/sites/marketing: 65.3 GB, of which 1.0 GB in the recycle bin and 4.9 GB older versions
  • New https://fabrikam.sharepoint.com/sites/patient-records: 352.6 GB, of which 12.0 GB in the recycle bin and 25.2 GB older versions
  • …and 2 more new

In Microsoft 365

  • New Accounts: oscar.smith@fabrikam.example: New member account
  • New Accounts: owen.robinson@fabrikam.example: New member account
  • New Licences: oscar.smith@fabrikam.example: Given Microsoft 365 Business Basic
  • New Licences: owen.robinson@fabrikam.example: Given Microsoft 365 Business Premium
  • New Mail: rhys.walker@fabrikam.example: Now forwards to rhys.walker@homemail.example
  • New Mail: rhys.hall@fabrikam.example: Now forwards to rhys.hall@homemail.example
  • New Devices: LAPTOP-SMITH50 (oscar.smith@fabrikam.example): Enrolled Windows
  • New Devices: DESK-ROBINSON51 (owen.robinson@fabrikam.example): Enrolled Windows
  • Changed Admin activity: Payroll Sync: Update application – Certificates and secrets management by admin@fabrikam.example on 2026-09-29: Added certificate
  • Changed Admin activity: Block risky countries: Delete conditional access policy by admin@fabrikam.example on 2026-10-05
  • Changed Admin activity: Require MFA for all users: Update conditional access policy by admin@fabrikam.example on 2026-10-06: On → Off
  • Changed Admin activity: anna.kowalski@fabrikam.example: Add eligible member to role in PIM completed (permanent) by admin@fabrikam.example on 2026-10-08: Exchange Administrator
  • Changed Admin activity: fabrikam.example: Set domain authentication by mallory.quinn@fabrikam.example on 2026-10-09
  • Changed Admin activity: ben.okafor@fabrikam.example: Add member to role by admin@fabrikam.example on 2026-10-09: Global Administrator
  • Changed Admin activity: Payroll Sync: Update application – Certificates and secrets management by admin@fabrikam.example on 2026-10-10: Added certificate
  • Changed Admin activity: Mail Sync Pro: Add service principal credentials by Contoso Automation on 2026-10-11: Credential added

Microsoft Secure Score

Microsoft's own measure of how many recommended security settings are turned on. Higher is better.

0%50%100%28 Jun 202611 Oct 20262026-06-28: 27%2026-06-29: 27%2026-06-30: 27%2026-07-01: 27%2026-07-02: 27%2026-07-03: 27%2026-07-04: 27.1%2026-07-05: 27.1%2026-07-06: 27.1%2026-07-07: 27.1%2026-07-08: 27.1%2026-07-09: 27.2%2026-07-10: 27.2%2026-07-11: 27.2%2026-07-12: 27.2%2026-07-13: 27.3%2026-07-14: 27.3%2026-07-15: 27.3%2026-07-16: 27.4%2026-07-17: 27.4%2026-07-18: 27.4%2026-07-19: 30%2026-07-20: 27.5%2026-07-21: 27.5%2026-07-22: 27.6%2026-07-23: 27.6%2026-07-24: 27.6%2026-07-25: 27.7%2026-07-26: 31%2026-07-27: 27.8%2026-07-28: 27.8%2026-07-29: 27.9%2026-07-30: 27.9%2026-07-31: 27.9%2026-08-01: 28%2026-08-02: 29%2026-08-03: 28.1%2026-08-04: 28.1%2026-08-05: 28.2%2026-08-06: 28.2%2026-08-07: 28.3%2026-08-08: 28.3%2026-08-09: 31%2026-08-10: 28.4%2026-08-11: 28.5%2026-08-12: 28.5%2026-08-13: 28.6%2026-08-14: 28.7%2026-08-15: 28.7%2026-08-16: 30%2026-08-17: 28.8%2026-08-18: 28.9%2026-08-19: 28.9%2026-08-20: 29%2026-08-21: 29.1%2026-08-22: 29.1%2026-08-23: 29%2026-08-24: 29.3%2026-08-25: 29.3%2026-08-26: 29.4%2026-08-27: 29.5%2026-08-28: 29.5%2026-08-29: 29.6%2026-08-30: 32%2026-08-31: 29.7%2026-09-01: 29.8%2026-09-02: 29.9%2026-09-03: 29.9%2026-09-04: 30%2026-09-05: 30.1%2026-09-06: 31%2026-09-07: 30.2%2026-09-08: 30.3%2026-09-09: 30.4%2026-09-10: 30.4%2026-09-11: 30.5%2026-09-12: 30.6%2026-09-13: 31%2026-09-14: 30.7%2026-09-15: 30.8%2026-09-16: 30.9%2026-09-17: 31%2026-09-18: 31%2026-09-19: 31.1%2026-09-20: 31%2026-09-21: 31.3%2026-09-22: 31.4%2026-09-23: 31.4%2026-09-24: 31.5%2026-09-25: 31.6%2026-09-26: 31.7%2026-09-27: 33%2026-09-28: 31.9%2026-09-29: 31.9%2026-09-30: 32%2026-10-01: 32.1%2026-10-02: 32.2%2026-10-03: 32.3%2026-10-04: 33%2026-10-05: 32.5%2026-10-06: 32.5%2026-10-07: 32.6%2026-10-08: 32.7%2026-10-09: 32.8%2026-10-10: 32.9%2026-10-11: 33%33%

Fix first 13

critical

1 admin without MFA, and 1 whose registration isn't known

Admins

What to do: Have each listed admin register a strong method (Authenticator or a FIDO2 key), or remove the role. Break-glass accounts should use FIDO2 keys kept offline.

Account or itemDetailSeverity
breakglass@fabrikam.exampleGlobal Administrator with no MFA method registeredcritical
g#EXT#@fabrikam.exampleExchange Administrator: MFA registration unknownlow
high

1 admin not covered by MFA

Admins

What to do: Make sure each admin is included in an enabled Conditional Access policy that requires MFA for all apps, and isn't excluded from it directly or through a group. Use a separate policy for break-glass accounts.

Account or itemDetailSeverity
breakglass@fabrikam.exampleGlobal Administrator: excluded from Require MFA for all usershigh
high

1 guest with admin roles

Admins

What to do: Remove admin roles from guest accounts. If an external partner needs access, use GDAP or a member account in this tenant protected by MFA.

Account or itemDetailSeverity
g#EXT#@fabrikam.exampleGuest holding Exchange Administratorhigh
high

1 app with access to mail, files or the directory

Apps

What to do: Review each app with the client. Remove apps nobody recognises (Enterprise applications > Delete), and for the rest confirm the vendor and that it still needs mailbox or file access.

Account or itemDetailSeverity
Mail Sync ProMail.Read (application permission; unverified publisher)high
high

6 of 54 computers not encrypted

Devices

What to do: Turn on BitLocker (Windows) and FileVault (macOS) with an Intune disk encryption policy, with recovery keys escrowed to Entra ID, so a lost or stolen laptop doesn't expose the client's data.

Account or itemDetailSeverity
DESK-MOORE18 (ava.moore@fabrikam.example)Windows disk isn't encryptedhigh
DESK-ROBINSON51 (owen.robinson@fabrikam.example)NewWindows disk isn't encryptedhigh
LAPTOP-OKAFOR (ben.okafor@fabrikam.example)Windows disk isn't encryptedhigh
LAPTOP-ROBINSON07 (thomas.robinson@fabrikam.example)Windows disk isn't encryptedhigh
LAPTOP-WARD29 (jack.ward@fabrikam.example)Windows disk isn't encryptedhigh
LAPTOP-WATSON40 (lily.watson@fabrikam.example)Windows disk isn't encryptedhigh
high

7 of 54 Windows computers past end of support

Devices

What to do: Upgrade computers on Windows 10 or an old Windows 11 release to the current Windows 11 release (Intune: Windows feature updates policy). Replace hardware that can't run Windows 11, or buy Extended Security Updates as a stopgap.

Account or itemDetailSeverity
LAPTOP-HARRIS31 (noah.harris@fabrikam.example)Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.high
LAPTOP-JACKSON49 (chloe.jackson@fabrikam.example)Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.high
LAPTOP-OKAFOR (ben.okafor@fabrikam.example)Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.high
LAPTOP-SMITH13 (owen.smith@fabrikam.example)Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.high
LAPTOP-WALKER04 (rhys.walker@fabrikam.example)Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.high
LAPTOP-WATSON40 (lily.watson@fabrikam.example)Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.high
LAPTOP-WOOD22 (william.wood@fabrikam.example)Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.high
DESK-ALLEN09 (thomas.allen@fabrikam.example)Windows 11 24H2: updates for Home and Pro end 13 Oct 2026.low
DESK-CLARK06 (ruby.clark@fabrikam.example)Windows 11 24H2: updates for Home and Pro end 13 Oct 2026.low
DESK-HARRISON21 (leo.harrison@fabrikam.example)Windows 11 24H2: updates for Home and Pro end 13 Oct 2026.low
…and 26 more in the XLSX export.
high

1 suspicious inbox rule

Email

What to do: Check each rule with the mailbox owner. Rules that delete or bury messages about payments or security alerts are a sign of a compromised account: reset the password, revoke sessions and review sign-ins.

Account or itemDetailSeverity
anna.kowalski@fabrikam.example".": Moves to RSS Feeds mail mentioning invoice, payment; Rule name '.' looks deliberately blankhigh
high

5 external forwards

Email

What to do: Remove forwarding to outside addresses unless the client has a documented business reason. Forwarding is the most common way attackers keep reading a mailbox after a password reset.

Account or itemDetailSeverity
anna.kowalski@fabrikam.exampleMailbox forwarding to anna.kowalski@homemail.example (keeps a copy)high
anna.kowalski@fabrikam.exampleInbox rule "Copy to home" forwards to anna.kowalski.home@homemail.examplehigh
rhys.hall@fabrikam.exampleNewMailbox forwarding to rhys.hall@homemail.example (doesn't keep a copy)high
rhys.walker@fabrikam.exampleNewMailbox forwarding to rhys.walker@homemail.example (doesn't keep a copy)high
thomas.robinson@fabrikam.exampleInbox rule "Invoices to bookkeeper" forwards to bookkeeping@ledgerline.examplehigh
high

27 users without MFA

Identity

What to do: Ask these users to register the Microsoft Authenticator app. Until they do, anyone with their password can register MFA in their place.

Account or itemDetailSeverity
breakglass@fabrikam.exampleNo MFA method registeredhigh
aaron.smith@fabrikam.exampleNo MFA method registeredmedium
aisha.brown@fabrikam.exampleNo MFA method registeredmedium
amelia.khan@fabrikam.exampleNo MFA method registeredmedium
arthur.williams@fabrikam.exampleNo MFA method registeredmedium
ava.jackson@fabrikam.exampleNo MFA method registeredmedium
ava.moore@fabrikam.exampleNo MFA method registeredmedium
ava.thomas@fabrikam.exampleNo MFA method registeredmedium
carl.svensson@fabrikam.exampleNo MFA method registeredmedium
chloe.jackson@fabrikam.exampleNo MFA method registeredmedium
…and 17 more in the XLSX export.
high

Legacy authentication is allowed

Identity

What to do: Block legacy authentication (Exchange ActiveSync and other clients) with a Conditional Access policy for all users. Legacy protocols can't do MFA and are the most common password-spray target.

Account or itemDetailSeverity
Whole organisationNo enabled policy blocks legacy authentication for all usershigh
high

1 domain had sign-in settings changed in the last 30 days

Identity

What to do: Confirm with the client that each change was planned (for example, setting up AD FS or another identity provider). If it wasn't, an attacker with admin rights may have federated the domain to their own identity provider so they can sign in as any user without a password or MFA: switch the domain back to managed sign-in, remove unknown federation settings, reset admin credentials and review the audit log.

Account or itemDetailSeverity
fabrikam.exampleSet domain authentication by mallory.quinn@fabrikam.example on 9 Oct 2026high
high

2 sites with no owner, 2 sites with one owner

Sharing

What to do: Give each site a second owner (in the Microsoft 365 group, or as a site administrator) so access requests and content questions have someone to go to when one person leaves. The Site access report lists each site's owners.

Account or itemDetailSeverity
MarketingNo enabled owner (Microsoft 365 group)high
Old ProjectsNo enabled owner (site administrators)high
Practice ManagementOne owner (Microsoft 365 group)low
Staff IntranetOne owner (site administrators)low
high

1 guest with full control of 1 site

Sharing

What to do: Take guests out of each site's owners group and away from Full Control; give them Edit or Read through the site's members or visitors group instead. Full Control lets someone outside the organisation change who can open the site and delete anything on it. The Site permissions report lists them.

Account or itemDetailSeverity
accounts@hollis-partners.example on FinanceFull Control, given Full Control directlyhigh

Also worth fixing 27

Lower-risk items. Each one lists the accounts or settings affected; the XLSX export has the full detail.

medium

7 accounts inactive for 90+ days or never used

Accounts

Affects aaron.smith@fabrikam.example, aisha.brown@fabrikam.example, jack.lee@fabrikam.example, noah.wood@fabrikam.example and 3 more.

Disable accounts that haven't signed in for 90 days, or were created over 30 days ago and never used (after checking with the client), then remove their licences. Inactive accounts are a common foothold for attackers.

medium

2 admins without a phishing-resistant method

Admins

Affects anna.kowalski@fabrikam.example, breakglass@fabrikam.example.

Have each listed admin register a passkey (in Microsoft Authenticator or on a security key) or Windows Hello for Business, then require the Phishing-resistant MFA authentication strength for admin roles in Conditional Access. Codes and push approvals can be relayed by a fake sign-in page; these can't.

medium

1 app with privileged roles

Admins

Affects Some app.

Check each app that holds a privileged directory role still needs it. A compromised app secret with an admin role bypasses MFA entirely.

medium

9 of 55 managed devices not compliant

Devices

Affects DESK-LEWIS12 (william.lewis@fabrikam.example), DESK-MOORE18 (ava.moore@fabrikam.example), DESK-ROBINSON51 (owen.robinson@fabrikam.example)New, LAPTOP-DAVIES38 (ruby.davies@fabrikam.example) and 5 more.

Open each non-compliant device in Intune (Devices > Monitor > Noncompliant devices) to see which setting fails, fix it or retire the device, and block non-compliant devices with a Conditional Access policy that requires a compliant device.

medium

1 mail domain without DKIM

Email

Affects fabrikam.example.

Turn on DKIM for each domain in the Defender portal (Email authentication settings > DKIM), publishing the two selector CNAME records it shows. This applies to domains behind a mail gateway too when Microsoft 365 still sends for them (their SPF includes spf.protection.outlook.com); a gateway signs only the mail that goes out through it.

medium

2 domains without DMARC enforcement

Email

Affects fabrikam.example, parked.example.

Publish a DMARC record with a rua= reporting address, start at p=none to see who sends as the domain, then move to p=quarantine and p=reject. Without enforcement, spoofed mail from the domain is delivered.

medium

4 teams and groups without an owner

Groups

Affects Project Phoenix, Marketing, Marketing, Provisioned.

Make an active person, ideally two, an owner of each listed team or group (Teams admin center or Microsoft 365 admin center > Teams & groups). Owners approve members and guests and renew the group; without one, nobody looks after its files and conversations. The ownerless group policy (Microsoft 365 admin center > Settings > Org settings > Microsoft 365 Groups) asks members to take over when the last owner leaves.

medium

Enforced by Require MFA for all users, with 1 exclusion to review

Identity

Affects breakglass@fabrikam.example.

Create a Conditional Access policy requiring MFA for all users and all cloud apps, or turn on Security Defaults if the tenant has no Entra ID P1. Keep exclusions to break-glass accounts.

medium

1 disabled account still licensed

Licences

Affects ben.okafor@fabrikam.example.

Remove licences from disabled accounts, or convert leavers' mailboxes to shared mailboxes (free up to 50 GB) before removing the licence.

medium

Anyone, including anonymous links

Sharing

Affects SharePoint and OneDrive.

Change SharePoint external sharing to "New and existing guests" so every external person signs in. If the client relies on Anyone links, set them to expire and to view-only.

medium

2 files and folders outside people can edit

Sharing

Affects Budget.xlsx (Finance / Documents)New, Lab dockets (Patient Records / Documents).

Change sharing with people outside the organisation to view-only unless they need to edit, and remove sharing that's no longer needed. The File and folder permissions report lists each person outside and what they can edit.

medium

3 mailboxes at or over 90% of quota

Storage

Affects accounts@fabrikam.example, aisha.brown@fabrikam.exampleNew, thomas.robinson@fabrikam.exampleNew.

Turn on the online archive for each listed mailbox (Exchange admin center > Mailboxes > Manage mailbox archive) with a retention policy that moves old mail into it, or clear large old items. A mailbox at its quota can't send, and soon after can't receive.

medium

88% of about 1.45 TB used (1 TB + 10 GB × 46 licences)

Storage

Affects Tenant SharePoint storageNew, https://fabrikam.sharepoint.com/sites/financeNew, https://fabrikam.sharepoint.com/sites/imagingNew, https://fabrikam.sharepoint.com/sites/marketingNew and 2 more.

Free up space before the tenant runs out, when people can no longer save files. The SharePoint storage report shows where the space goes and what to clear first; otherwise buy Office 365 Extra File Storage.

low

1 account reports to a blocked manager

Accounts

Affects anna.kowalski@fabrikam.example.

Set a current manager on each listed account (Entra admin center > Users > Properties > Manager, or in on-premises AD for synced accounts). The manager is where approvals, leaver notices and access reviews go; when they've left, those go nowhere, and their blocked account is usually waiting to be deleted too.

low

1 app registration with expiring or expired credentials

Apps

Affects Old connector.

Renew credentials before they expire to avoid an outage, and delete app registrations whose credentials have all expired if nothing uses them any more.

low

1 of 55 joined computers not in Intune

Devices

Affects DESK-RECEPTION.

Enrol Entra-joined and hybrid-joined computers in Intune (automatic enrolment under Devices > Enrollment > Windows) so compliance, encryption and updates can be enforced on them.

low

5 devices haven't checked in for 30+ days

Devices

Affects DESK-LEWIS12 (william.lewis@fabrikam.example), DESK-ROBINSON51 (owen.robinson@fabrikam.example)New, LAPTOP-DAVIES38 (ruby.davies@fabrikam.example), LAPTOP-LEE25 (arthur.lee@fabrikam.example) and 1 more.

Find out whether each device is lost, replaced or broken. Retire devices that are gone; for devices still in use, restart the Intune Management Extension or re-enrol.

low

1 of 57 device records unused for 90+ days

Devices

Affects OLD-PC.

Disable, then after 30 days delete, device records that haven't signed in for 90 days (Entra admin center > Devices > All devices, filter by activity). Old records can still hold BitLocker keys and count toward device limits.

low

1 domain with SPF problems

Email

Affects parked.example.

Publish one SPF record per domain ending in -all (or ~all while testing), e.g. "v=spf1 include:spf.protection.outlook.com -all". Domains that never send mail should publish "v=spf1 -all".

low

1 of 1 mail domain doesn't fully enforce MTA-STS

Email

Affects fabrikam.example.

Publish an MTA-STS policy so other mail servers only deliver to the domain over a verified, encrypted connection: a TXT record at _mta-sts.<domain> ("v=STSv1; id=20260101") and a policy file at https://mta-sts.<domain>/.well-known/mta-sts.txt listing the domain's MX hosts (for Microsoft 365, "mx: *.mail.protection.outlook.com"). Start with "mode: testing" and TLS-RPT reports, then switch to "mode: enforce" and change the id.

low

SMTP AUTH is on for the organisation

Email

Applies to the whole organisation.

Turn off SMTP AUTH for the organisation and enable it only on the mailboxes of devices or apps that still need it, such as scanners. It accepts passwords without MFA.

low

Anyone, including guests, can invite guests

Guests

Applies to the whole organisation.

Restrict guest invitations to admins and the Guest Inviter role, or at least to members, under External collaboration settings.

low

4 people can only use a text or call as a second factor

Identity

Affects george.baker@fabrikam.example, owen.robinson@fabrikam.exampleNew, owen.turner@fabrikam.example, thomas.allen@fabrikam.example.

Ask these people to set up the Microsoft Authenticator app (the registration campaign in the authentication methods policy prompts them at sign-in), then turn off text message and voice call sign-in, or keep them only as a backup. Texts and calls can be intercepted or moved to an attacker's SIM.

low

2 subscriptions with spare licences

Licences

Affects Microsoft 365 Business Basic, Microsoft 365 Business Premium.

Reduce the subscription quantity at the next renewal, or assign the spare licences.

low

Any user can register an app

Tenant settings

Applies to the whole organisation.

Set "Users can register applications" to No (Entra admin center > Users > User settings) and give the Application Developer role to the people who need it.

Licences

£164.40 a month
could be saved: that's £1,972.80 a year on licences that are unassigned or held by disabled or inactive accounts.
LicencePurchasedAssignedUnassigned Disabled usersInactive usersWaste / month
Microsoft 365 Business Premium4643 31 4 £144.80
Microsoft 365 Business Basic1311 20 2 £19.60
Total5954 51 6 £164.40

In good shape 14

  • Between 2 and 4 Global Administrators
  • Automatic forwarding to outside addresses is off
  • Shared mailboxes can't be signed in to
  • Mailbox auditing is on
  • Guests have limited directory access
  • Users have a way to get apps approved
  • No old, unaccepted guest invitations
  • No guest owns a team or group
  • Only chosen people can create teams and groups
  • Unused groups and teams expire
  • Admin accounts are cloud-only
  • Every licence assignment works
  • No subscriptions are about to lapse
  • No OneDrive is nearly full

Not checked 7

These checks need data or a Microsoft licence that isn't available, so they're neither a pass nor a fail.

  • Users can't create new tenants. Microsoft didn't return this setting
  • People can't join the tenant just by verifying an email address. Microsoft didn't return this setting
  • Encrypted delivery failures are reported (TLS-RPT). TLS-RPT is checked on mail domains that use MTA-STS, and none do yet
  • Directory sync is running. Cloud-only tenant: directory sync isn't turned on
  • Password hash sync is on. Cloud-only tenant: directory sync isn't turned on
  • No risky sign-ins succeeded. Sign-in risk needs Entra ID P2
  • No accounts are at risk in Entra ID Protection. Risky users need Entra ID P2