Microsoft Identity & Cloud Security Assessment
What the assessment examines
Evidence is gathered via a client-approved, read-only application registered in the Microsoft tenant. This provides access to configuration data without touching user content, email, or documents. Access is scoped to the engagement and removed on close.
£4,950
Fixed price · + VAT
Delivered in 7 working days
Assessment areas
- Entra ID tenant posture and authority boundaries How identity authority is structured, where it concentrates, and what an account compromise actually grants access to in practice. The gap between the organisational chart and the real authority map is often significant.
- Conditional Access design and enforcement integrity Whether the policies in place behave the way they are described. Whether gaps are accidental or the result of deliberate exceptions that were never reviewed. Whether legacy authentication pathways bypass controls that look enforced.
- Privileged access exposure and role sprawl Standing privilege, role assignment patterns, service accounts with excessive permissions, and the hidden surface created by accumulated entitlements that were never deprioritised.
- Azure subscription-level security posture Subscription boundaries, configuration integrity, resource-level access controls, and the structural decisions shaping platform exposure. Particular attention to the gap between tenant-level policy and actual resource-level enforcement.
- Detection and visibility at the platform layer What is actually being captured in audit logs, what is being acted on, and where blind spots live. Whether a significant event in the identity platform would produce an alert that anyone would see and act on.
- Controls that appear secure but do not reduce risk The most common and consequential category in real Microsoft environments: policies that are configured, enabled, and named correctly, but that do not enforce in the way the organisation believes. These are the controls that fail quietly.
You receive
- Executive-level posture summary A short, plain-language overview written for accountable leadership. Not a technical report reformatted for a different audience. A genuinely different document, written for the person who needs to make decisions, not the person who will implement them.
- Prioritised decision and risk register A working register of decisions and risks ranked by impact and authority. Not a raw findings dump. Each entry states the decision required, who holds the authority to make it, and what the consequence of delay is.
- Trade-off and accepted-risk explanation Where risk is accepted and where it should not be. The difference between a risk that is accepted because it is genuinely low, and one that is accepted because nobody has looked at it properly.
- Recommendations expressed as decisions Direction stated as decisions to make, not products to procure. No vendor recommendations, no tool suggestions, no implementation projects embedded in the deliverable.
- Working session (90 minutes) A working call to align technical findings with leadership context. Both technical and non-technical attendees can participate. The session is structured around the decisions, not the findings list.