What we check
- Licensing: over-allocated SKUs, assignment errors, disabled accounts holding licences, users missing UsageLocation
- Identity: Conditional Access coverage, MFA and legacy authentication
- Privileged access: Global Administrator count and standing assignments
- Applications: expired and expiring app credentials
- Multi-Geo and Preferred Data Location, where they apply
- Collection quality: anything we could not read is listed, never reported as clean
What you get
- An HTML report your leadership can read
- A findings register with evidence and a recommended action for each finding
- Licence and data-location extracts your engineers can work from
- A risk-classified 30/60/90-day roadmap you own, whether or not you work with us next
How it works
We run our open, read-only M365 Tenant Readiness assessment with delegated read scopes only. It sends GET requests and Get-* cmdlets and nothing else, so the tenant is never changed. Typically 5–10 business days, fixed price.
Questions buyers ask
Will the assessment change anything in our tenant?
No. It only reads. No write permission is requested under any configuration.
What access do you need?
Delegated read scopes such as Organization.Read.All, User.Read.All and Policy.Read.All, approved by your admin. The full list is published in our white paper.
Is this the same as a Secure Score?
No. There is no score. Each finding comes with its evidence, and anything that needs human judgement is marked for review instead of being guessed.