Technical security and privacy assessment
Microsoft 365 Security and Privacy Assessment
A technical review of Microsoft 365 identity, privilege, device, sharing, logging and recovery controls.
This is a technical review supporting security, privacy and applicable Quebec regulatory obligations—not legal advice or certification.
Useful outcomes
A clearer decision after the review.
Identify material risks
See which identity, access, device and sharing settings deserve attention.
Prioritize corrections
Separate practical fixes from licensing, process or management decisions.
Receive a usable roadmap
Give your team a findings summary and a sequenced next-step list.
Fit and boundaries
A defined review for a defined situation.
For Quebec organizations
Useful when a team is preparing an internal review, migration, ownership change or improvement to security and privacy governance.
Not legal certification
It is not legal advice, a Law 25 certification, a penetration test or a promise that future incidents or interruptions will not occur.
Evidence and context
What we need before drawing conclusions.
The problem we address
Risk often sits in identities, administrator roles, Conditional Access exceptions, unmanaged devices, guests, sharing links, mailbox rules, logging and recovery. The review provides prioritized technical findings instead of assuming a license or default setting is sufficient.
Information and access required
Depending on scope, the customer provides approximate users and domains, licenses, administrator roles, existing policies, sensitive-data types, important devices and applications, work constraints and known retention requirements. We prefer read-only access or approved exports; emergency-access accounts remain under customer control.
Areas examined
Identity, access and recovery controls
Identity and administrators
User accounts, emergency-access accounts, workload identities, MFA and privileged roles.
Policies and devices
Conditional Access, legacy authentication, devices, applications and licensing dependencies.
Sharing and recovery
Guests, external sharing, mailbox rules, logging, retention and recovery mechanisms.
The review may cover user and administrator accounts, emergency-access accounts, service and workload identities, MFA, legacy authentication, Conditional Access, devices, roles, OAuth applications, guests, external sharing, mailbox rules, audit logs, retention and recovery mechanisms. Available features depend on licensing, configuration and logging.
How the engagement works
A transparent path from scope to priorities.
Confirm scope
Agree the tenant, samples, evidence and customer authorizations.
Review evidence
Examine approved exports or read-only access and note material exceptions.
Prioritize findings
Relate observations to risk, dependencies and the organization’s stated needs.
Discuss next work
Confirm optional remediation or implementation work separately.
Work performed
We confirm objectives, inspect authorized exports or access, check a sample of policies and identities, identify material exceptions, assess sharing on a risk basis and compare controls with stated needs. We do not change policies, delete accounts or promise an interruption-free outcome without separate authorization.
Customer deliverables
Useful material your team can act on.
The customer receives a technical findings summary, a map of risks and exceptions, prioritized corrections, licensing and process dependencies, questions for the privacy lead and an implementation roadmap. The report identifies the evidence actually examined.
Commercial clarity
A clearly bounded engagement.
Engagement type
Technical security and privacy assessment
What affects scope and fee
Environment
- Users, domains and tenants
- Administrator and service identities
- Devices, applications and policies sampled
Evidence and licensing
- Licensing available
- Exports versus authorized access
- Logging and retention available
Requested outcome
- Technical findings only
- Reporting for management or privacy discussions
- Optional implementation assistance
Included, separately scoped and excluded
Included
- Scope confirmation
- Agreed technical review
- Findings and prioritized recommendations
Separately scoped
- Remediation or configuration changes
- Policy implementation
- Training or broader testing
Excluded
- Legal advice or certification
- Penetration testing unless authorized separately
- Guaranteed compliance or incident prevention
Scope and timing are confirmed after the initial conversation. This is not a legal audit, Law 25 certification, penetration test or validation of every device, application or historical event. Conclusions are limited to the settings, samples and licenses examined and may change after configuration changes.
The scope, deliverables and fee are confirmed before work begins. Additional work is performed only after approval.
Access, confidentiality and limitations
Review only what is authorized and necessary.
Information is used for the requested review and shared only with authorized people. Exports should exclude unnecessary messages, files and personal data. Temporary access is limited, recorded where practical and revoked by the customer when work ends.
Next step
Start with your situation, not a generic package.
Bring your team’s questions, known licenses and controls of concern. Request the Microsoft 365 technical assessment to confirm scope and required access.