Identity baseline
Check administrative roles, authentication coverage, legacy access concerns and Conditional Access scope. Identify excluded users or applications and document why each exception exists.
Compare tenant settings with an agreed security baseline. Prioritize configuration gaps and document changes, exceptions and responsible owners.
Plan your solution
A Microsoft 365 baseline assessment compares tenant settings with an agreed configuration target. Digital Cloud can review identity, messaging and collaboration controls alongside the licenses and business exceptions that shape your environment. The result is a traceable configuration gap list, with evidence and change priorities that administrators can use to plan an improvement phase.
Identity protection determines who can reach which resources and under what conditions. Multifactor authentication, least privilege and conditional access can form part of a Zero Trust approach. Emergency access and legitimate exceptions must be considered so stronger controls do not prevent necessary recovery. Security controls should support the way the organization works while reducing avoidable exposure. Identities, devices, email and networks need coordinated policies, maintenance and accountable response ownership.
Check administrative roles, authentication coverage, legacy access concerns and Conditional Access scope. Identify excluded users or applications and document why each exception exists.
Review relevant mail protection policies, guest access and external sharing settings. Look for inconsistent treatment of comparable users or sites rather than assuming one tenant-wide setting suits every workload.
Record observed settings, target values and affected services. Use Secure Score recommendations as one input, validate business impact and specify rollback requirements for proposed changes.
After rapid growth, different teams have configured sharing and access independently. The assessment can identify inconsistent controls and establish an approved target before administrators standardize the tenant.
The final deliverables, licensing and responsibilities are agreed for your environment before implementation.
Identify important systems and information, current controls and exceptions. Agree change approval, coverage and escalation. A configuration review does not by itself establish legal compliance or eliminate every risk.
We begin with a conversation about the task, the people involved and the systems already in place. Together we identify what a useful result would look like and which dependencies need attention first. The agreed proposal sets the delivery boundaries, responsibilities and acceptance criteria.
| Project phase | What happens |
|---|---|
| 01Establish the baseline | Confirm the systems, evidence and access needed for the review. Record the current configuration and relevant business constraints before drawing conclusions. |
| 02Prioritize findings | Explain findings in terms of impact and practical effort. Separate confirmed issues from assumptions and identify the owner who can validate each recommendation. |
| 03Plan corrective action | Agree on a prioritized action plan, identify dependencies and define how improvements will be verified. Changes are implemented only within the agreed scope and authorization. |
No. The assessment is a configuration review against the chosen target. It does not prove complete security or regulatory compliance, and findings can change as settings and products evolve.
The starting environment, integrations, user groups and agreed outputs determine the effort. We confirm scope and commercial terms before work begins. Software licenses, infrastructure consumption and ongoing support may be separate items.
The proposal identifies the deliverables: these may include findings, a prioritized roadmap, a tested configuration, a prototype, documentation or training. We agree what is included and how completion will be assessed.
We review the actual applications, data sources and access requirements before recommending an integration. Dependencies and compatibility limits are recorded so the delivery plan reflects your environment.
You can use the findings to guide your own team or discuss a follow-on phase. Any maintenance, monitoring or support includes separately agreed service hours, responsibilities and response targets.