ES
All services

dForts services

Cybersecurity audit and hardening for Microsoft 365

We review how your Microsoft 365 is configured against Zero Trust principles and the CIS benchmark, explain the risks in plain language and close the doors the most common attacks come through. Everything measured and verifiable, AI security included.

Request a security audit

Who it is for

Businesses whose Microsoft 365 "works" but nobody has ever reviewed how it is configured. Most tenants we audit share the same problems: accounts without MFA, legacy protocols left open, information shared with "anyone with the link" and unencrypted laptops. It does not take a sophisticated attack to cost you dearly; a well-crafted email is enough. And, increasingly, businesses about to switch on Copilot that need to know first what the AI will be able to see.

What the audit covers

  • Identities (Entra ID): MFA, conditional access, admin accounts, guests, legacy authentication, apps with excessive permissions.
  • Email (Exchange and Defender for Office 365): anti-phishing, anti-impersonation, forwarding rules, SPF/DKIM/DMARC, attachments and links.
  • Devices (Intune and Defender for Endpoint): enrolment, compliance, encryption, updates.
  • Data (SharePoint, OneDrive, Teams and Purview): external sharing, permissions, sensitivity labels and retention.
  • Data loss prevention (DLP) with Purview: which sensitive information is in circulation (national IDs, IBANs, health data, contracts), where it leaks (email, Teams, devices, sharing) and which policies detect and stop it. Purview is one of our specialities: labelling, DLP, retention, insider risk and eDiscovery.
  • AI security (Copilot and agents): what data Copilot can reach with current permissions (oversharing), which labels and policies it honours, governance of Copilot Studio agents and Power Platform connectors, and what leaves the tenant towards other AI services.
  • Criteria and measurement: every control is assessed against Zero Trust principles (verify explicitly, least privilege, assume breach) and the CIS benchmark for Microsoft 365, with a before-and-after state you can check: accounts without MFA, open protocols, public links, unencrypted devices, Secure Score.

What you get

  1. A report with findings ranked by severity, explained in plain language, each with the Zero Trust or CIS reference it fails, the metric that proves it and the proposed fix.
  2. A prioritised hardening plan, showing what we do and what needs a decision from you. We start from Microsoft's security baseline and the CIS benchmark for Microsoft 365, adapted to your company so security does not get in the way of work.
  3. Execution of the plan, if you want us to do it: in phases, with the team informed, and verified afterwards with the same metrics: what was open is now closed, and you can see it.

Real cases

Compromised accounts nobody knew about

At a services company we found automatic forwarding rules to external addresses in three mailboxes: someone had been reading their email for months. We removed the rules, forced MFA and credential resets, enabled Defender alerts and closed the legacy authentication they had come in through.

Client data reachable with a link

A professional practice shared SharePoint folders with "anyone with the link", including folders with case files. We restricted external sharing to identified guests, applied sensitivity labels and a data loss prevention policy for national IDs and IBANs.

Unencrypted laptops at a company with a field sales team

With Intune we enrolled the devices, turned on BitLocker and set compliance requirements: a lost laptop is no longer a data breach.

A Copilot that could see too much

Before enabling Copilot at a 60-person company we measured what each user could reach: payslips and contracts in a library shared with everyone. We fixed permissions, applied sensitivity labels and a DLP policy, and only then enabled Copilot for the pilot group. The oversharing report went from hundreds of documents to zero.

Frequently asked questions

Does the audit disrupt work?

No. It is read-only: we review configuration and logs. Changes happen in the hardening phase, planned and announced.

What is Secure Score?

The score Microsoft gives to your tenant's security. It is a useful reference to measure improvement, not a goal in itself: some points are not worth chasing in an SMB.

Does it help with ISO 27001 or similar frameworks?

The audit covers the Microsoft 365 technical controls those frameworks require and the report can be used as evidence. It does not replace certification.

How often should it be repeated?

Once a year, or after major changes (growth, merger, new tools). If we manage your tenant, it is part of the ongoing review.

Do I need extra licences?

It depends on what you have. Business Premium covers most of it; we tell you exactly what would be needed and what would not before touching anything.

What does Zero Trust mean in practice?

Three principles: always verify identity and device (MFA, conditional access, compliant devices), grant the least privilege needed (permissions, admins, guests) and assume a breach will happen (detection, alerts, response). The audit checks, control by control, how far your tenant meets them.

Do you audit Copilot too?

Yes. Copilot does not bypass permissions, but permissions are usually wrong: the audit measures which data each user would reach through the AI and what must be fixed before switching it on. It also covers Copilot Studio agents and Power Platform connectors.

Knowing where you stand is the first step

Tell us which licences you have and how many users you are, and we will tell you what we would review and how long it takes.

Request a security audit