Microsoft 365 Security Review & Roadmap

Microsoft 365 includes a wide range of security controls, but they need to be reviewed, configured and managed around your organisation’s actual risks.

We have created a set of best practice security recommendations (Baseline and Enhanced Security) that we are encouraging clients to adopt to protect from data breach. We have also developed complementary services that provide further enhancements to Microsoft 365 security, compliance, and management.

We offer a Microsoft 365 Security Review and Roadmap where we will:

1. Microsoft 365 security baseline review

Review your environment against the security recommendations – Baseline, and where applicable Enhanced. Read more about our baseline security standards.

microsoft secure score

2. Microsoft Secure Score validation

Undertake a pragmatic review and validation of the Microsoft Secure Score (Microsoft’s numerical measurement of an organisation’s security posture), taking into consideration your specific environment, requirements, and culture.

3. Prioritised Microsoft 365 security roadmap

Develop a Security Roadmap with areas of improvement or enhancement that are prioritised and costed (including any additional licence requirements), so these can be implemented in a phased approach based on risk, budget and operational impact.

What the Microsoft 365 Security Assessment Can Cover

There are a number of services that provide further enhancements to Microsoft 365 security, compliance, and management.

Within the Security Review & Roadmap, we determine the most appropriate elements and prioritisation for your organisation.

Microsoft 365 Audit Logging and Investigation Readiness

As standard, Microsoft 365 audit log retention depends on licensing and configuration, and standard retention may not be enough for longer-term investigation, audit or compliance requirements. In the case of an investigation this could be very limiting.

We strongly recommend reviewing audit log retention and, where required, extending log storage using Microsoft Purview Audit, Microsoft Log Analytics or another appropriate long-term logging approach.

Enhanced Logging and Microsoft 365 Security Monitoring

The standard logs that are recorded by Microsoft 365 can be difficult to interpret and correlate between different services.

In addition to reviewing audit log retention, we recommend reviewing the most appropriate Microsoft 365 security monitoring tools, including Microsoft Defender for Cloud Apps and Microsoft Sentinel where suitable, to capture a detailed audit trail of user and admin activities for forensic investigations.

SharePoint / OneDrive / Teams permissions

It is important to ensure that internal and external permissions on folders and individual files are appropriate and there is no risk of unauthorised access to sensitive or confidential information. The standard approach to SharePoint, OneDrive and Teams permissions is problematic and can be very complex, with ad-hoc sharing, external collaboration and inherited permissions increasing the risk of people gaining incorrect access rights.

We can undertake a Microsoft 365 security audit and review of permissions, develop an appropriate permission structure, and as applicable restructure the site/library.

Teams permissions should be reviewed alongside SharePoint and OneDrive permissions, as they are often connected through Microsoft 365 groups, guest access and external collaboration.

The use of Teams to collaborate with external parties has increased substantially over recent months. It is important to ensure that the security of data being shared via Teams is appropriately reviewed and managed.

It is also possible to implement Access Reviews, allowing the efficient management of group memberships, access to enterprise applications, and role assignments. User access can be reviewed on a regular basis to make sure only the right people have continued access.

Document Protection, Sensitivity Labels and DLP

It is important to ensure that internal and external permissions on folders and individual files are appropriate and there is no risk of unauthorised access to sensitive or confidential information. The standard approach to SharePoint, OneDrive and Teams permissions is problematic and can be very complex, with ad-hoc sharing, external collaboration and inherited permissions increasing the risk of people gaining incorrect access rights.

We can undertake a Microsoft 365 security audit and review of permissions, develop an appropriate permission structure, and as applicable restructure the site/library.

Teams permissions should be reviewed alongside SharePoint and OneDrive permissions, as they are often connected through Microsoft 365 groups, guest access and external collaboration.

The use of Teams to collaborate with external parties has increased substantially over recent months. It is important to ensure that the security of data being shared via Teams is appropriately reviewed and managed.

It is also possible to implement Access Reviews, allowing the efficient management of group memberships, access to enterprise applications, and role assignments. User access can be reviewed on a regular basis to make sure only the right people have continued access.

Identity, Access and Password Security

As part of the Microsoft 365 security review, we can assess identity and access controls including multi-factor authentication, Conditional Access, administrator roles, guest access, sign-in risk and access reviews.

Self-Service Password Reset (SSPR) can also be implemented where appropriate, allowing users to reset their passwords without contacting IT staff for help.

Microsoft Defender and Endpoint Protection

We can review your existing anti-virus/malware provision and, where appropriate, recommend Microsoft Defender endpoint security technologies such as Microsoft Defender for Endpoint or Microsoft Defender for Business.

Microsoft Defender for Endpoint helps organisations prevent, detect, investigate and respond to advanced threats on endpoints. This can include threat and vulnerability management, automated investigation and remediation, endpoint detection and response, and ongoing security monitoring.

Cloud App Security and Shadow IT Visibility

Microsoft 365 security should also consider how users access and share data across other cloud applications. Some cloud services may be approved and managed, while others may be used informally by employees without IT oversight, known as Shadow IT.

We can review whether Microsoft Defender for Cloud Apps is appropriate for your organisation and determine the most suitable configuration and reporting settings. This can support visibility of cloud app usage, information protection, threat detection and compliance monitoring.

Where appropriate, this can also help detect suspicious data movement and apply controls for unmanaged devices.

Microsoft Sentinel, SIEM and Security Monitoring

A Security Information and Event Management (SIEM) system collects data from various sources, normalises and aggregates it, and analyses it to help identify security incidents and support investigation.

Microsoft Sentinel is Microsoft’s cloud-native SIEM platform, designed to support threat detection, investigation and response across Microsoft and third-party data sources.

Sentinel can integrate with Microsoft services and other data sources such as firewalls, proxies and endpoints.

Where required, we offer implementation, tuning and 24×7 SOC monitoring. This can be implemented in a phased approach, sized and scaled appropriately to your organisation, requirements and risk profile.

Office 365 Management Enhancements

We are also able to offer a range of Enhanced Management services, building upon the functionality of Enhanced Security. We are working closely with Microsoft to identify new ways to help you stay secure, and we are developing a roadmap of recommendations which we will be sharing with you regularly to ensure that you are kept abreast of best practice as the security landscape evolves.

Please do not hesitate to contact us if you are interested in undertaking a Security Review & Roadmap, or need any additional information relating to any of these elements.

To discuss your specific requirements.
Call today 020 7307 5008

FAQs about Microsoft 365 Security Assessment

What is a Microsoft 365 security assessment?

A Microsoft 365 security assessment is a review of your Microsoft 365 environment to identify security risks, configuration gaps and opportunities for improvement. It can include identity, access, permissions, audit logging, Microsoft Secure Score, Defender, data protection, cloud app security and monitoring, with findings prioritised into a practical roadmap.

What is included in a Microsoft 365 security review?

A Microsoft 365 security review can include Secure Score validation, identity and access review, SharePoint and Teams permissions review, external sharing review, audit logging review, Defender review, data protection review, cloud app security review and Microsoft Sentinel monitoring recommendations. The exact scope can be tailored around your licensing, risk profile and internal IT resources.

Is Microsoft Secure Score enough?

Microsoft Secure Score is useful, but it should not be relied on in isolation. It should be reviewed in the context of your organisation’s licensing, risk profile and security requirements.

Do you provide ongoing Microsoft 365 security management?

Yes. Syntax can help implement and manage recommendations from your Microsoft 365 security assessment, including configuration changes, monitoring, reporting, access reviews, Microsoft Defender optimisation and Microsoft Sentinel monitoring.

Can you review SharePoint, OneDrive and Teams external sharing?

Yes. Syntax can review external sharing, guest users, Teams membership, SharePoint permissions, OneDrive sharing and access to sensitive information, then recommend changes to improve control without preventing effective collaboration.