Microsoft 365 Security Assessment

Microsoft 365 Security Assessment

Assess your Microsoft 365 tenant’s security posture in minutes — Secure Score, identity and access, third-party app consent and email authentication — then get a prioritized list of exactly what to fix. Read-only, and free to run.

Connects through Microsoft’s own admin-consent screen. No password ever reaches us.

A Microsoft 365 security assessment reviews the security-relevant parts of a tenant — its Microsoft Secure Score, identity and access hygiene, third-party app consent, and email authentication — and turns what it finds into a prioritized list of fixes. M365 Health Score performs this assessment read-only, using Microsoft Graph, and scores the result as part of an overall Health Score out of 100.

What it checks

The security checks it runs

Each area below maps to a real check. Nothing here is aspirational — it is what the scan actually inspects.

AreaWhat’s assessed
Microsoft Secure ScoreIngests your tenant’s live Secure Score and per-control profiles, translating Microsoft’s recommendations into plain-language fixes.
Identity & accessUsers with no MFA, a dedicated flag for Global Admins with no MFA, Global Administrator role sprawl, dormant admins, stale guests, and never-expiring passwords paired with no MFA.
App-consent exposureThird-party applications holding high-risk Microsoft Graph permissions in your tenant — the shadow-IT consent risk most admins never review.
Email authenticationSPF and DMARC record checks by direct DNS lookup, so spoofed mail is caught.

How it relates to Microsoft Secure Score

Microsoft Secure Score measures your Microsoft security posture and gives Microsoft’s recommended improvements. A M365 Health Score security assessment complements it: it reads your Secure Score and adds tenant-health checks — identity hygiene, app-consent exposure, email authentication and license efficiency — in one place. If you already use Secure Score, this shows what a broader read adds. See Secure Score vs M365 Health Score.

Doing it by hand

Reproducing this manually means cross-referencing the Microsoft 365 admin center, the Defender portal’s Secure Score, Entra ID sign-in and role data, Enterprise Applications consent grants, and public DNS for each domain — then judging severity yourself. The assessment does that pass in minutes and ranks the results.

Scope, stated plainly

This assessment does not review Conditional Access policies, DLP, sensitivity labels, retention or Intune device compliance, and it never opens mail, files or messages. It reads only what’s needed to score the areas above.

Questions, answered plainly

Microsoft 365 security assessment FAQ

What is a Microsoft 365 security assessment?

A Microsoft 365 security assessment reviews the security-relevant parts of a tenant — its Microsoft Secure Score, identity and access hygiene, third-party app consent, and email authentication — and produces a prioritized list of weaknesses to fix. M365 Health Score runs this read-only, in minutes.

Is the security assessment free?

Yes. Running the scan and seeing your overall Health Score is free. The full itemized report, with every finding and a remediation roadmap, is a paid upgrade.

Does a security assessment replace Microsoft Secure Score?

No. It complements Secure Score. M365 Health Score ingests your actual Secure Score and adds checks around identity, app consent and email authentication that round out the picture of tenant health.

What does the assessment not cover?

It does not analyze Conditional Access policies, Data Loss Prevention, sensitivity labels, retention or device compliance, and it never reads mail, files or messages. It is strictly read-only.

Run a free Microsoft 365 security check

See your Health Score and where your tenant is exposed — read-only, in minutes.