Key takeaways

Owning Microsoft security licences is not the same as being protected.
Identity, endpoint and device controls must work as one connected system.
Secure Score is useful, but it is not a complete measure of security.
A review should prioritise risk and practical improvements, not just settings.

What is a Microsoft 365 security review?

A Microsoft 365 security review is a structured assessment of the controls that protect users, devices, applications, email, collaboration services, business data and privileged access across the Microsoft environment.

It should not be treated as a simple checklist of whether individual features are switched on. Effective security depends on the relationship between the controls. A compliant device policy has limited value if it is not enforced through Conditional Access. Multifactor authentication is less effective when legacy authentication, weak methods or broad exclusions remain available.

A useful review identifies where risk exists, why it exists and what should be done next. It should distinguish between urgent exposure, sensible improvements and lower-priority optimisation.

Microsoft provides a capable security platform. The organisation is still responsible for designing, configuring, monitoring and maintaining it.

Why Australian businesses need regular Microsoft 365 security reviews

Microsoft environments change continuously. New employees join, former employees leave, devices are replaced, applications are introduced, administrators create temporary exclusions and Microsoft releases new capabilities. A configuration that was reasonable twelve months ago may no longer reflect the organisation’s risk, operating model or compliance needs.

A formal security review helps confirm whether the environment still reflects current business requirements. It is particularly valuable after a merger, migration, security incident, licensing change, cyber insurance renewal or major increase in remote work.

Microsoft 365 security works in layers

Identity and access Entra ID, multifactor authentication, Conditional Access and privileged access
Devices and endpoints Intune enrolment, compliance, configuration, Defender and operating-system health
Email, collaboration and data Exchange Online, Teams, SharePoint, phishing protection and information protection
Monitoring and governance Secure Score, alerts, audit logs, incident response and ongoing improvement

Common Microsoft 365 security gaps we regularly find

Most weaknesses are not caused by the absence of advanced technology. They are usually created by incomplete deployment, inconsistent configuration, old exclusions or controls that were designed but never fully enforced.

MFA is not enforced consistently

Administrators may use weaker methods, legacy authentication may remain available, or exclusions may allow some users to bypass stronger controls.

Conditional Access is incomplete

Policies may protect only some users, exclude important applications or fail to address unmanaged devices, risky sign-ins and privileged roles.

Devices are enrolled but not governed

Intune may be present, but compliance settings, configuration profiles, update controls and access enforcement may be incomplete.

Defender is only partially deployed

Endpoint onboarding, attack-surface reduction, tamper protection, remediation and alert ownership may not be fully implemented.

Privileged access is too broad

Too many users may hold permanent administrator roles, daily accounts may also be privileged, or emergency access accounts may be unmanaged.

Email protection is assumed rather than verified

Anti-phishing, impersonation protection, Safe Links, Safe Attachments and domain authentication may not be configured to suit the organisation.

What a proper Microsoft 365 security review should assess

A comprehensive review should examine the environment as a connected system. The goal is to understand how controls behave in real scenarios, not simply whether a setting exists.

Identity security

Authentication methods, MFA registration, legacy authentication, password policies, risky sign-ins, guest access and account lifecycle.

Conditional Access

Policy coverage, exclusions, report-only policies, location rules, device requirements, administrator protection and authentication strength.

Intune and device management

Enrolment, compliance, configuration profiles, application deployment, update rings, platform restrictions and mobile application protection.

Endpoint protection

Defender onboarding, endpoint detection and response, antivirus, attack-surface reduction, firewall, encryption and remediation.

Email and collaboration

Anti-phishing, spoofing controls, external sharing, Teams policies, SharePoint access and protection against malicious links and attachments.

Data and governance

Sensitivity labels, retention, audit logging, data loss prevention, eDiscovery readiness and the handling of sensitive information.

Microsoft Secure Score explained

Microsoft Secure Score is a useful way to identify recommended improvements and track progress over time. It can help reveal incomplete controls and provide a shared improvement backlog for internal teams and external advisors.

However, a high score does not automatically prove that an organisation is secure. Some recommendations may not suit the business, while other important risks may sit outside the score. Secure Score also cannot determine whether policies have been tested properly or whether exceptions create practical gaps.

Secure Score is useful for Secure Score does not replace
Identifying recommended security improvements A risk assessment based on business context
Tracking progress over time Testing whether controls work in practice
Creating a prioritised improvement backlog Reviewing architecture, exclusions and dependencies
Supporting security conversations with leadership Incident response planning and operational ownership

What to review in Microsoft Intune

Microsoft Intune can provide strong device management and compliance capabilities, but enrolment alone does not create a secure environment. Policies must be appropriate, consistently deployed and enforced through access controls.

A Microsoft Intune review should confirm which device platforms are allowed, how devices are enrolled, whether compliance is meaningful, how updates are managed and what happens when a device becomes non-compliant.

Confirm all expected corporate devices are enrolled and actively reporting.
Review compliance policies for encryption, operating-system version, password requirements and threat level.
Verify non-compliant devices are restricted through Conditional Access.
Review configuration profiles, security baselines and policy conflicts.
Confirm update rings and feature-update policies support timely patching.
Review application protection for personally owned mobile devices.
Check device cleanup, retirement and former-employee processes.

Conditional Access best practices

Conditional Access is one of the most important controls in a Microsoft 365 environment because it determines the circumstances under which users can access cloud services.

A strong design should protect all users and applications unless a documented reason exists not to. Policies should be tested carefully, exclusions should be minimal, and emergency access accounts should be handled separately.

Key areas to verify

  • All users are covered by baseline access policies.
  • Administrators have stronger requirements than standard users.
  • Legacy authentication is blocked.
  • Unmanaged or non-compliant devices are restricted appropriately.
  • Risky sign-ins and risky users trigger additional controls.
  • Authentication strength is appropriate for privileged or sensitive access.
  • Report-only policies are reviewed and either implemented or retired.
  • Break-glass accounts are protected, monitored and tested.

What to review in Microsoft Defender

Microsoft Defender capabilities can protect endpoints, identities, email and cloud applications, but coverage is often uneven. Some devices may not be onboarded, alerts may not have an owner, or recommended hardening controls may remain in audit mode indefinitely.

A useful review should confirm coverage, configuration and operational response. It should answer whether the organisation can detect suspicious activity, investigate it efficiently and contain affected accounts or devices.

Area Questions to answer
Endpoint onboarding Are all supported devices onboarded, healthy and reporting?
Hardening Are attack-surface reduction, tamper protection, firewall and antivirus controls enforced?
Alerts Who reviews alerts, how quickly and with what escalation process?
Remediation Are vulnerabilities and security recommendations tracked to completion?
Testing Has the organisation confirmed that detections and response procedures work?

Microsoft 365 and Essential Eight alignment

Microsoft technologies can support several elements of the Australian Essential Eight, particularly multifactor authentication, application control, patching, administrative privileges, operating-system hardening and backup-related governance.

Alignment is not achieved by purchasing a particular licence. It depends on the organisation’s operating systems, application estate, identity design, device ownership model, backup architecture and the maturity level it is seeking to achieve.

A security review should map current Microsoft controls to the organisation’s Essential Eight objectives, clearly identify limitations and avoid claiming compliance based on product availability alone.

Cyber insurance readiness and Microsoft 365

Cyber insurance applications often ask about multifactor authentication, endpoint protection, privileged access, patching, backups, email security and incident response. Microsoft 365 can support many of these controls, but insurers may expect evidence that they are implemented consistently.

A review can help an organisation prepare accurate responses, identify gaps before renewal and avoid relying on assumptions that may not withstand closer examination following an incident.

Fedelta’s Cyber Insurance Readiness capability is designed to help organisations understand and strengthen the controls commonly considered during the insurance process.

Microsoft 365 security review checklist

The following checklist provides a practical starting point. The exact scope should be adapted to the organisation’s licences, risk profile and operating model.

Review identity configuration, MFA registration and authentication methods.
Confirm legacy authentication is blocked.
Review Conditional Access coverage, exclusions and report-only policies.
Assess permanent administrator roles and privileged account separation.
Review Intune enrolment, compliance and configuration policy coverage.
Confirm non-compliant devices are prevented from accessing sensitive services.
Verify Defender onboarding, hardening controls and alert ownership.
Review email authentication, anti-phishing and impersonation protection.
Assess external sharing across SharePoint, OneDrive and Teams.
Review audit logging, retention, information protection and data loss prevention.
Compare current controls with Essential Eight and cyber insurance requirements.
Create a prioritised remediation roadmap with owners and target dates.

What a good review process looks like

Understand the organisation

Confirm business priorities, sensitive information, user groups, compliance expectations, licences and known operational constraints.

Assess configuration and coverage

Review the Microsoft environment across identity, access, endpoints, devices, email, collaboration, data and administration.

Validate how controls work together

Identify dependencies, exclusions and scenarios where a control exists but is not actually enforced.

Prioritise risk

Separate urgent exposure from planned improvements so the organisation can act on the most important issues first.

Create an achievable roadmap

Document recommended actions, ownership, dependencies and realistic implementation stages.

Do you need more Microsoft licensing?

Sometimes additional licensing is justified, particularly when the organisation requires advanced identity protection, endpoint detection, information protection or compliance capabilities.

However, many organisations can make substantial improvements using features they already own. The first step should be to understand what is licensed, what is deployed and what is configured effectively.

Buying a higher Microsoft licence does not automatically improve security. Correct design and implementation do.

Questions every organisation should be able to answer

  • Could a stolen password still provide access to company data?
  • Are unmanaged or non-compliant devices restricted?
  • Do all administrators use strong authentication and separate accounts?
  • Can former employees or dormant accounts still authenticate?
  • Are Conditional Access exclusions documented and regularly reviewed?
  • Are all supported endpoints visible in Microsoft Defender?
  • Who owns security alerts and how are incidents escalated?
  • Can the organisation demonstrate Essential Eight or insurance-related controls?
  • Are Microsoft Secure Score recommendations assessed rather than ignored?
  • Is there a prioritised security improvement roadmap?

Frequently asked questions

Final thoughts

Microsoft provides one of the most capable security ecosystems available to modern organisations. The difficult part is not purchasing the technology. It is understanding how the services should work together and maintaining them as the business changes.

A well-executed Microsoft 365 security review provides clarity. It identifies what is working, exposes hidden gaps and creates a practical roadmap for improving security without automatically defaulting to more products or more licensing.

Need help reviewing your Microsoft 365 security?

Fedelta helps Australian organisations assess, secure and optimise Microsoft environments through practical, specialist advice.

Book a Security Review