MICROSOFT 365 SECURITY ASSESSMENT
GARRISON
READINESS
ASSESSMENT.
Know where your defenses stand.
Know what to strengthen next.
We assess your existing, customer-owned Microsoft 365 environment. You receive human-verified findings and a clear plan your team can act on.
Your existing cloud-only tenant · Up to 50 users
THE DEFENSIVE LINES
Walk the
perimeter.
Every stronghold has more than one way in. We review the Microsoft 365 settings that help control access, protect communication, and keep your data in trusted hands.
Each area is checked against your licensing and the scope we agree before work begins.
01The gatesIdentity & administrator access
Review MFA coverage, administrator roles, and relevant sign-in and access settings. Identify where a compromised account could gain more access than it should.
IDENTITY02The wallsEmail protection & forwarding
Review available email-protection settings and forwarding configurations, with attention to preventable exposure and ways business email could leave your environment.
EMAIL03The keepData sharing & guest access
Review tenant-level sharing and guest-access settings, plus an agreed sample of sites. Understand who can reach shared information and where access deserves a closer look.
COLLABORATION04The keysApplication permissions
Review consent settings and an agreed sample of application permissions. Highlight access that may be excessive, unclear, or worth validating with its owner.
APPLICATIONS05The watchtowerAudit & alert configuration
Review available audit and alert configurations to show what visibility you have today and where licensing or configuration may limit it. This is a configuration review, not ongoing monitoring.
VISIBILITYTHE FIELD REPORT
Your battle plan.
In plain English.
Findings are only useful if you know what to do with them. You leave with priorities for the business and practical instructions for the people making changes.
Your top five priorities
A concise view of the issues that deserve attention first, with business context and a clear order of action.
Evidence. Then instructions.
Human-verified technical findings, supporting evidence, and remediation instructions your internal team or IT provider can use.
A sequenced action plan
A practical 30/60/90-day plan that separates immediate priorities from improvements you can schedule.
One hour to walk through it together.
A findings readout to discuss priorities and answer your team's questions.
One focused follow-up check.
Up to five priority findings, when requested within 30 days.
A DEFINED MISSION
Clear boundaries.
No guesswork.
A focused security assessment of the Microsoft 365 environment your business already owns and uses. We confirm fit, access, and the sample of sites and apps together before starting.
One-time service fee · Microsoft licenses not included
Included in the fixed scope
- Security review of one existing, customer-owned cloud-only Microsoft 365 tenant
- Up to 50 users
- An agreed, bounded sample of sites and apps
- The findings package, one-hour readout, and one follow-up check
Larger or hybrid environment? We can discuss a separate scope.
Outside this engagement
Microsoft 365 licenses or subscriptions, new tenant setup, migration, remediation implementation, penetration testing, incident response, ongoing monitoring, hybrid Active Directory, device-by-device review, and an exhaustive file audit.
This assessment is a point-in-time review. Recommendations reflect available licensing; it does not certify compliance or guarantee security.
BEFORE WE BEGIN
A few good
questions.
Does the $1,500 include Microsoft 365?
No. The fee covers a security assessment of the Microsoft 365 tenant your business already owns, with up to 50 users. You keep your existing Microsoft subscription. New tenant setup, licensing, migration, and remediation implementation are not included.
Is this a penetration test?
No. It is a scoped Microsoft 365 security-configuration assessment. Penetration testing and active exploitation are outside this package.
Do you make the recommended changes?
The package includes remediation instructions. Your team or IT provider implements the changes. Implementation help would be a separate engagement.
What if our licenses don't include a control?
We account for the licenses you have. Findings distinguish configuration issues from licensing limitations, so you can make an informed decision about your next steps.
How does the follow-up check work?
Request the included check within 30 days. We review up to five priority findings after your team has addressed them. This is one focused check, rather than a new assessment of the entire tenant.
KNOW WHAT TO STRENGTHEN NEXT
Ready to inspect
your defenses?
Talk to the GarrisonStart with a conversation about your Microsoft 365 environment.

