Cloud Security Assessment
How is security configured in your cloud environment?
We assess the security configuration of Microsoft 365, Entra ID and Azure. You gain insight into vulnerable settings, excessive access and practical ways to reduce risks.
Identity and configuration
Three questions we answer
- Who can gain access to your environment?
- Which accounts and applications have excessive permissions?
- Which settings need attention first?
When is this relevant?
Growing cloud use calls for an overview of permissions and settings.
Accounts, guest users, applications and subscriptions often grow alongside each other. We consider security decisions in the context of how your organisation uses the cloud.
- You have completed a cloud migration or expansion.
- You want the configuration of MFA and Conditional Access assessed.
- You want to manage administrator roles, guest access and application permissions.
- You need an evidence-based improvement agenda for Microsoft 365 or Azure.
The assessment
What do we assess?
Your environment and assessment question determine the content. We agree in advance which elements we will examine.
01
Identities and access policies
We assess users, guest accounts, authentication policies and relevant exceptions. The focus is on the access that is actually possible and the configuration of strong authentication.
02
Privileged access and applications
We examine administrator roles, app registrations and other identities with access to the environment. We consider which permissions are needed and where account misuse could have a significant impact.
03
Data and public accessibility
Within the scope, we assess sharing settings, data access and the accessibility of Azure resources, among other things. We connect settings to the data or processes that depend on them.
04
Logging and administration
We examine whether relevant log sources and administration settings align with the security objectives. The advice distinguishes between configuration, administration and any additional validation.
Defining the scope together
A scope that fits your question.
An assessment focuses on the agreed tenant, subscriptions and services. We determine which read permissions and exports are needed to assess the configuration.
What do we agree in advance?
- Microsoft 365 tenants, Azure subscriptions and services in scope.
- Temporary assessment accounts, read permissions and required exports.
- Relevant administrators, suppliers and existing policy decisions.
- Reporting format, priorities and any additional technical validation.
The assessment is carried out using the agreed access. Changes to your configuration and active attack simulations are agreed separately.
The result
Insight you can act on.
01
An overview of the configuration
An evidence-based picture of relevant settings and interconnected access risks.
02
Practical configuration advice
Improvements your administrators can translate into changes to policies, permissions and settings.
03
A workable order
Priorities based on impact, dependencies and how your organisation uses the cloud.
Our approach
From the initial question to follow-up.
01
Discussing use and scope
We determine which cloud services and access risks to focus on.
02
Assessing the configuration
We collect the agreed configuration data and discuss relevant exceptions.
03
Interpreting the findings
We connect settings to specific risks and discuss the proposed measures.
04
Improvement and follow-up
Your administrators implement changes. We can agree a follow-up check separately.
Frequently asked questions
What you need to know in advance.
Is this a penetration test or a configuration assessment?
This assessment starts with a review of the security configuration. If you also want technical demonstrations of misuse scenarios, we explicitly include that validation in the scope.
Do you need Global Administrator access?
We determine the permissions needed for each area and choose appropriate assessment permissions. Broad administrative access is not a standard requirement; where necessary, we use additional exports or assistance from your administrator.
Can you assess Microsoft 365 on its own?
Yes. We can limit the scope to Microsoft 365 and Entra ID, or include specific Azure subscriptions and resources.
Why is assessing our own configuration relevant?
When using the cloud, decisions about identities, data and access settings remain with the customer. We focus the assessment on the elements for which your organisation and administrators are responsible.
Our approach
From assessment to clear next steps.
Read how we define the scope, carry out the assessment and discuss the results with you. With a dedicated secure data room and evidence-based reporting.
Discuss your situation
Manage your cloud settings.
Tell us which services you use and what questions you have. Together, we define the scope of the assessment.
The form is currently unavailable. Use our general contact form or call 036 5367 573.
We use your details to handle your enquiry. Read our privacy policy.