Microsoft 365 Identity Security Assessment

A fixed-fee, read-only review of your Microsoft 365 tenant. Evidence for every finding, a prioritized fix plan, and approved remediation options. Delivered virtually or on site, anywhere in the US.

Why identity

Most Microsoft 365 breaches start with identity.

A sign-in that should have been challenged. An account with more access than it needs. A setting nobody has looked at since the tenant was created. This assessment reviews those controls setting by setting and shows you exactly what to fix first. The controls reviewed map to the CISA SCuBA baseline for Microsoft Entra ID and the derived NIST SP 800-53 Rev. 5 controls.

What you get

  • A written report with evidence

    Evidence for every finding, not a scanner printout.

  • A prioritized fix plan

    What is exposed, why it matters, and the order to fix it.

  • A 90-minute readout

    The findings walked through with your team or your IT provider.

  • Approved remediation options

    If you want the fixes done for you, we shape that together and you approve it before anything starts.

At a glance

  • Fixed fee, scoped after the discovery call
  • Read-only access you grant and can revoke
  • No software installed on your devices
  • One 90-minute readout against prepared deliverables
  • Written so your IT provider can act on it
What you receive

The executive scorecard, page by page.

Written for an owner or a board, not for the help desk. Two pages from a sample scorecard prepared for an invented company.

Sample executive scorecard · Fictional company data
Page one of the sample executive scorecard for Kestrel Ridge Manufacturing (SAMPLE), an invented company: what is at stake, then the first business scenario connected to the findings, fraudulent instructions through impersonation, which ties the missing MFA safeguard to about 3.1 million dollars in annual vendor payments (a fictional figure) and states that financial systems were not tested.
Page 1. What is at stake, and the first business scenario connected to the findings.
Page two of the sample executive scorecard: the second scenario, delayed detection and Microsoft 365 recovery, then six safeguard areas scored as bars, from Authentication at 58 percent to Recovery and monitoring at 50 percent, and the first five priorities of the remediation plan.
Page 2. The second scenario, where you stand by area, and what to do first.
01

What is at stake

Your operating model in plain language: what the organization depends on, and what the findings expose.

02

Business scenarios

Each scenario ties a finding to a business outcome, with the source and date of every figure and a stated boundary.

03

Where you stand

Six areas scored on safeguard coverage. Not a compliance certification.

04

What to do first

The first steps in order, sequenced so recovery lands before any change that could lock anyone out.

From the executive scorecard prepared for Kestrel Ridge Manufacturing (SAMPLE), an invented company. The score tiles and issue details are omitted. Scores describe safeguard coverage; they are not a compliance certification.
How it works

Four steps, no surprises.

01

Discovery call

A 30-minute conversation to confirm scope and quote a fixed fee. No obligation.

02

Access

You grant read-only access to your tenant. No software touches your devices, and you can revoke the access at any time.

03

Review

We examine your identity and access configuration setting by setting and collect evidence as we go.

04

Findings

When collection is complete, you receive the report, the fix plan, and the scorecard, then one 90-minute readout with your team or your IT provider.

Who this is for

Organizations that need a clear answer.

Organizations that run on Microsoft 365 and need a clear answer, from lean nonprofits to multi-site companies: for a cyber insurance questionnaire, a board or leadership question, a customer security review, or a concern about account compromise. If you have an IT provider, the report is written so they can act on it directly.

For businesses and organizations only. We do not provide consumer or personal account support.

Who delivers it

Mount Xion Technologies is a veteran-owned cybersecurity firm in San Antonio, Texas. Our principal directed IT and cybersecurity for a $1B+ organization and served in the USAF, and every engagement is principal-led, from first call to final report. A bench of vetted senior practitioners works alongside on delivery and peer-reviews the findings, so every report reflects more than one set of experienced eyes.

Credentials across the practice include CISSP, PMP, SSCP, CompTIA CySA+, CompTIA Security+, CompTIA Project+, and ITIL 4. We treat credentials as table stakes: the deliverables stand on evidence collected from your tenant, not on letters after names.

Pricing

Fixed fee, scoped after the discovery call. You will know the full cost before any work begins.

Common triggers

  • A cyber insurance questionnaire you cannot answer confidently
  • Your payment processor's annual PCI self-assessment questionnaire
  • A board or leadership request for a security picture
  • A customer security review
  • A concern that an account was compromised
  • A general posture check before something goes wrong
Request a discovery call

Request a 30-minute discovery call.

Tell us a little about your organization and we will confirm scope and quote a fixed fee on the call.

All fields help scope the conversation. Nothing here is a commitment.

We respond within one business day. Your information, plus any campaign attribution you accepted, is used only to schedule and scope the conversation. See the privacy policy for details and your choices.

Pick a time on the calendar.

Same 30 minutes, same straight answer. No pitch, no obligation.