Skip to content
Sunrise Digital Labs

Assessment

Microsoft 365 Security Assessment

A bounded review of how your Microsoft 365 tenant is actually configured, measured against a published baseline, with findings ordered by what to do about them.

It examines the estate rather than the organization — the identity model, the access policies, the mail posture, what is shared outside, and what is being logged.

When this usually comes up

  • A client or prospect has sent a security questionnaire that has to be answered accurately
  • An insurer is asking questions at renewal that nobody can currently answer from the tenant
  • A migration surfaced findings, and somebody now wants the whole picture rather than the parts that were in the way
  • New leadership has inherited an environment that has never been assessed
  • Something happened, or nearly did, and the question is what else is open

What is examined

Identity and Conditional Access
The policy set as a whole rather than one policy at a time: what is actually enforced, who is exempt, and whether the exclusions that were meant to be temporary are still in place.
Administrative privilege
Who holds standing admin rights, how many accounts have them, whether they are separate from day-to-day accounts, and what re-approves them.
Defender configuration
What is switched on, what is in report-only mode, and what was configured once and never revisited.
Mail security
Anti-phishing and anti-spoofing posture, the domain records that support it, and the transport rules that quietly override it.
External and guest access
Guest accounts and what they can still reach, sharing defaults, and links that outlived the documents they were created for.
Logging and retention
What is being recorded, for how long, and whether it would answer a question asked three months from now.

What is not examined

The scope is narrow on purpose. It is what makes the engagement quotable, deliverable and checkable — and it is worth knowing before you commission it rather than after.

The network
Firewalls, segmentation, VPN and edge devices are not in scope of this engagement.
On-premises servers and infrastructure
Where hybrid identity reaches into Active Directory the identity question is in scope, because it is the same system. The servers themselves are not.
Non-Microsoft SaaS
Applications authenticating against Entra ID are examined as part of the tenant. What happens inside those applications is not.
Penetration testing
This is a configuration review. Nothing is exploited and nothing is attacked.
Incident response
This does not include monitoring, detection or response — those describe an operational capability Sunrise does not provide.

The baseline it is measured against

CISA publishes the Secure Cloud Business Applications baselines: a specific, documented set of recommended Microsoft 365 configurations. It also publishes an open-source tool, ScubaGear, that reports how a tenant compares to them.

The assessment uses both, and hands you the output. That is why the raw report is one of the things you receive. A finding you can re-run is a different kind of statement from a finding you have to take on trust.

Published by CISA: Secure Cloud Business Applications (SCuBA) project · ScubaGear

What the result is, and what it is not

It is a description of how the tenant is configured today, against a document anybody can read. It is not a certification, an accreditation or an attestation, and Sunrise is not in a position to issue any of those.

Closing every finding does not make an organization compliant with anything, and it is not an outcome any insurer or regulator has agreed to accept. Using a public baseline creates no relationship with the agency that published it.

What you receive

Findings against the baseline
Every control the baseline covers, the tenant’s current state for each, and where the two differ.
Prioritized remediation list
What to change and in what order, with what each change affects — because some of them are visible to every user on the morning they land.
Privilege and access picture
Administrative accounts, standing rights, MFA coverage, and who is currently exempt from which policy.
External exposure summary
Guest accounts, sharing defaults, and what is reachable from outside the tenant today.
The raw tool output
The unedited report the open-source tooling produced, so any finding can be re-run and checked by someone who was not involved in producing it.

What happens with the findings

They are yours. Most are things an in-house team or an existing provider can action, and the list is ordered so that is possible without further involvement.

Where remediation is wanted from Sunrise, it is scoped separately once the findings exist — because what it involves is not knowable until they do.

All Microsoft 365 work

Questions people ask before committing

Do we get a certificate?

No. This is an assessment, not an attestation — Sunrise measures your tenant against a published baseline and tells you where the two differ.

Where a certification or an attestation is required, it comes from an independent party who did not perform the remediation. A firm that assesses and then fixes cannot also be the one attesting to the result. That is a permanent boundary here, not a stage Sunrise is working toward.

What access do you need?

Read access to the tenant's configuration. The assessment examines how the environment is set up — policies, privileges, sharing defaults, logging — and none of that requires the ability to change anything.

Will this disrupt anything?

It reads configuration and changes nothing. Users are not affected, policies are not altered, and nothing is switched on or off during the assessment.

The remediation is where disruption lives, which is why the findings list orders changes by what each one affects — some are visible to every user on the morning they land.

Is this a penetration test?

No. A penetration test attacks the environment to find what an intruder could reach; this reads how the environment is configured and compares it to a baseline.

They answer different questions and neither substitutes for the other. If what you need is someone attempting to break in, that is a different engagement with a different firm.

What happens if you find something serious?

You are told immediately rather than at the end. Anything that represents active exposure — a standing administrative account without MFA, a mailbox forwarding externally, a site shared to the open internet — is raised as it is found.

The finding is still yours to act on. Most are actionable by an in-house team or an existing provider, and where remediation is wanted from Sunrise it is scoped once the findings exist.

Answer the questionnaire from the tenant, not from memory.

Most organizations can describe how their environment is meant to be configured. The assessment describes how it is.