Skip to main content
Valto — Keep ahead of tomorrow

Security

Microsoft 365 security assessment

Find out exactly where you stand, in a report you can hand to your board, your insurer or your customer. Valto assesses your Microsoft 365 and Entra ID environment against Microsoft's recommended baselines, CIS benchmarks and Cyber Essentials requirements, covering identity, privileged access, devices, email, data protection and monitoring. You get a scored, prioritised findings report with each item weighed by impact and effort, and a clear view of what your existing licences already cover. Available through G-Cloud.

Security assessments
Microsoft Solutions Provider

TRUSTED BY ORGANISATIONS LIKE YOURS

Mind
Greene King
Grosvenor
City of London logo
Chester Zoo
ABM
Human Appeal
John Deere
UKTV
Astrazenica
Money Supermarket
Princes
Sony
Shell
BBC
OVERVIEW

A straight answer about your current security position

Most organisations running Microsoft 365 have a rough sense that their security could be better and no clear view of where the gaps actually are. Secure Score gets checked occasionally. A previous assessment produced a spreadsheet nobody could act on. Somebody remembers that MFA has exceptions, without remembering who holds them. Valto's assessment replaces that with a documented position. We review your tenant against Microsoft's recommended baselines, the CIS Microsoft 365 Foundations Benchmark and Cyber Essentials technical controls, covering identity, privileged access, conditional access, devices, email, data protection, monitoring and audit retention. What you get back is not a raw export. It is a scored, prioritised report that tells you what is exposed, what it would take to fix, which items your existing licences already cover, and which ten things to do first. Whether the remediation happens with us, with your internal team or with somebody else is genuinely your decision. The assessment is useful either way, and it is priced and scoped as a standalone piece of work.

Our security assessments

Most organisations start with a workshop and decide from there. All three are scoped and priced as standalone engagements, with no obligation to take the remediation work with us.

Assessments against a specific framework

Where you are being measured against a specific standard, we map your environment directly against its controls and give you the evidence as well as the gap list.

Cyber Essentials readiness

We assess your Microsoft environment against the five Cyber Essentials technical controls: user access control, secure configuration, malware protection, security update management and firewalls. You get the gap list, a remediation plan and the evidence needed to certify. Certification itself is carried out by an accredited certification body; we get you ready to pass first time.

CIS Microsoft 365 Foundations Benchmark

A structured audit against the CIS benchmark, scoring your tenant control by control and identifying failures by severity. This is the assessment to choose where an auditor, insurer or customer has asked for a recognised independent standard rather than a supplier's own opinion.

Customer and supply chain security questionnaires

Where a customer has sent a security questionnaire that has to be returned before a contract is awarded or renewed, we work through it against your actual environment, establish what is true today, close what needs closing and document the rest.

NIS2 readiness

For organisations with EU operations, EU customers, or a place in an in-scope EU supply chain, we assess governance, controls, monitoring and reporting against NIS2 requirements.

Three men around a table

Hear from our experts

Watch: From reactive to proactive: Securing Microsoft 365 for AI

In this episode, Rob Thomas (Head of Modern Work), Will Jones (Senior Consultant) and James Belsey (Project Manager) discuss why a proactive security strategy is becoming essential, how Microsoft 365 security has evolved, and what organisations should consider before rolling out AI tools like Microsoft Copilot.

Focused assessments

Where you already know roughly where the problem is, or where a specific area needs to stand up to scrutiny on its own.

Entra ID security assessment

MFA coverage and exceptions, global administrator exposure, privileged access, risky sign-ins, Identity Protection configuration, guest access.

Conditional access review

Existing policy coverage and gaps, device compliance requirements, location and risk-based controls, and whether the policies protect what they appear to.

Microsoft Purview assessment

Data classification, sensitivity labels, DLP policies, retention, and the regulatory position they are meant to support.

Intune and endpoint security assessment

Device compliance, security baselines, Autopilot configuration, BYOD controls, application protection policies, and which devices no policy currently reaches.

Microsoft Defender assessment

Defender for Endpoint, Office 365, Identity and Cloud Apps: configuration, coverage and whether the detections are reaching anybody.

What the report actually contains

A scored current position

Your Secure Score, benchmark scoring and a maturity position by area, so you have a number to compare against next year.

Findings prioritised by impact and effort

Every finding scored, so a two-hour change that closes real exposure is not buried alphabetically beneath something that would take a quarter.

What your licences already cover

Each recommendation marked according to whether it is included in what you already pay for, or whether it needs additional licensing. In most assessments the majority is already covered.

A remediation roadmap

Sequenced into quick wins, planned work and longer-term change, with an indication of effort and any user impact to plan around.

Evidence you can hand over

Documented configuration positions in a form that can be attached to a questionnaire, taken to an insurer, given to an auditor or presented to a board.

A walkthrough with the consultant who did the work

The report is presented rather than emailed. The value is in the conversation about what to do first, and that conversation should be with the person who looked at your tenant.

Why work with Valto's security specialists?

The assessment stands on its own

It is scoped, priced and delivered as a standalone piece of work. Whether the remediation happens with us, your own team or another supplier is your decision, and the report is written to be useful either way.

We start with what you already own

Every recommendation is marked according to whether your existing licences cover it. Most of the time they do, and we have no product of our own to sell you.

Mapped to standards somebody else recognises

Microsoft's recommended baselines, the CIS Microsoft 365 Foundations Benchmark and Cyber Essentials technical controls, so the findings carry weight with auditors, insurers and customers rather than being one supplier's view.

Prioritised, not exhaustive

Every tenant has dozens of possible improvements. We tell you which ten matter most for your organisation rather than handing over a two-hundred-item export.

Available through G-Cloud

Public sector organisations and others buying through the Digital Marketplace can procure the assessment directly, without running a separate tender process.

Delivered by the people who do the remediation

The assessment is carried out by consultants who configure these environments daily, which is why the effort estimates are realistic and the roadmap is sequenced in an order that actually works.

Expertise
Microsoft security and identity specialists
Clarity
A scored position, not a raw export
Value
Built on licences you already own
Power Apps Envisioning Workshop

WHAT ASSESSMENTS TYPICALLY FIND

The gaps that are easy to miss and hard to explain

Very little of what we find is a missing product. It is settings left at default, access granted for a reason that no longer applies, and policies applied to part of the estate and never finished. These are the findings that recur across almost every assessment we run:

  • Multi-factor authentication covering most people, with exceptions nobody has revisited
  • More permanent global administrators than anyone would approve today
  • Privileged access held standing rather than granted when needed
  • Accounts belonging to people who left, still licensed and still enabled
  • Sharing links and "everyone" permissions making internal content far more available than intended

Turn findings into business value

An assessment is only worth commissioning if something happens as a result. These are the outcomes the findings usually unlock.

Supply chain security questionnaires and certification requirements increasingly decide who is eligible to bid. A documented, evidenced position turns that from an obstacle into a same-day answer.
Cyber insurance questionnaires have become specific about MFA coverage, privileged access and endpoint protection. Answering accurately affects the premium and, in the event of a claim, whether it is paid.
Removing standing administrative privilege, closing legacy authentication and tightening sharing does not prevent every compromise, but it limits what a compromised account can do, which is the difference between an incident and a crisis.
Copilot surfaces whatever your permissions and content structures allow. Remediating oversharing and stale permissions is the most common preparation work we do before a Copilot deployment.
Many organisations hold Business Premium, E3 or E5 with a substantial part of the included security capability unconfigured. The assessment tells you which, and turning it on is usually better value than adding a third-party product.
"Where are we on security?" is a question most IT leads cannot currently answer with anything except reassurance. A scored position, a prioritised roadmap and an annual comparison is an answer.

How we deliver security assessments

From a first conversation about what you are being asked to prove, through to a scored position, a prioritised roadmap and a walkthrough with the consultant who carried out the work.

  1. Man looking into clouds
    1

    Scoping

    Establish what you need to prove and to whom

    A short conversation, or the workshop, to establish your obligations, deadlines, licensing position and which framework you are being measured against. This determines the assessment scope and avoids paying for depth you do not need.

  2. Woman working at a computer
    2

    Access

    Read-only, and time-limited

    We need read-only access to your tenant for the assessment period. No configuration is changed, nothing is deployed, and access is removed when the assessment completes.

  3. SharePoint Consultant hosting a requirements workshop
    3

    Assessment

    Automated collection, human interpretation

    Configuration data is collected systematically, then reviewed by a consultant against Microsoft's baselines, the CIS benchmark and your own risk position. The collection is the easy part; deciding which findings matter for your organisation is the work.

  4. Share Power BI Reports - Valto
    4

    Reporting

    Scored, prioritised and licence-aware

    You get a scored current position, findings ranked by impact and effort, what your existing licences already cover, and a sequenced remediation roadmap.

  5. Valto team at Microsoft London
    5

    Walkthrough

    Presented, not emailed

    We present the findings to your team, agree what to do first, and answer the questions the report will inevitably raise. What happens next is your decision.

We're one of the UK's few Microsoft partners to hold all Microsoft Solution Partner designation badges, across all Solution Partner designation pathways. For our clients, that means working with specialists who understand how identity, devices, data and applications fit together rather than treating security as a separate technical exercise. Whether you're preparing for certification, responding to a customer questionnaire or simply want a straight answer about where you stand, we assess the Microsoft platform you already run against standards other people recognise.

WHY ORGANISATIONS CHOOSE VALTO

Microsoft Solutions Partner
Apps on a phone

CONNECTED, ACROSS MICROSOFT

A tenant cannot be assessed one product at a time

Identity sits in Entra ID. Devices sit in Intune. Email sits in Defender. Content sits in SharePoint and OneDrive. Classification sits in Purview. Infrastructure sits in Azure. A gap in any one of them is reachable through the others, which is why an assessment that looks at each in isolation misses the findings that matter most. Valto brings together expertise across Microsoft 365, Azure, identity, endpoints, data and Microsoft 365 Copilot. That lets our consultants see how a conditional access decision affects collaboration, how a sharing setting affects Copilot, and how a licensing decision affects what security capability is available at all. The result is a single assessed position across the estate rather than six separate opinions about six products.

Girl with trophy

Valto recently delivered an excellent Azure Virtual Desktop environment, expertly project managed by Kerina, while the team has also supported us with security hardening across our Microsoft environment. Having worked with a number of Microsoft partners over the years, I can genuinely say that Valto are the best in the business.

Matt Gibson · IT Support Technician, Krysalis Consultancy

The team driving you forward

Rob Thomas
Rob ThomasMS365 & Azure Business Unit Lead
SharePoint Consultant hosting a requirements workshop
Harry BarnettPre-Sales Consultant
Girl with trophy
Will JonesSenior Cloud Consultant
James BelseySenior Project Manager

Questions, answered plainly

Practical answers on what the assessment covers, what access we need, what it costs, how it maps to Cyber Essentials and CIS, and what happens once you have the report.

Identity and conditional access, privileged and administrative access, device compliance and endpoint policy, email and collaboration protection, data protection and sharing, monitoring and audit retention, and your current Secure Score and licensing position. We map findings against Microsoft's recommended baselines, the CIS Microsoft 365 Foundations Benchmark and, where relevant, Cyber Essentials technical controls.
Read-only access for the assessment period. We do not change configuration, we do not deploy anything, and access is removed when the assessment completes. If you would prefer to run the collection yourself under our guidance, that can be arranged.
A scored current position, findings prioritised by impact and effort rather than listed alphabetically, an indication of which recommendations your existing licences already cover, and a sequenced remediation roadmap. It is presented to your team by the consultant who carried out the work rather than emailed over.
Secure Score is a useful signal and it is free, so start there. What it will not do is tell you which items matter for your organisation, what effort each one takes, what your users will notice, whether your licences cover it, or how you compare against a recognised external standard. It also scores some things you may have deliberately decided against. The assessment is the interpretation layer.
In almost every case, yes. Copilot surfaces whatever your permissions and content structures allow, so oversharing, stale permissions and orphaned content turn a useful tool into an unreliable one. The assessment identifies exactly that, and the remediation improves search and governance whether or not Copilot goes ahead.
Because we do the remediation as well, which makes the effort estimates realistic and the roadmap sequenced in an order that works in practice. A firm that only assesses tends to produce findings that are technically correct and operationally unhelpful. If what you need is penetration testing or 24/7 monitoring, that is a different discipline and we will tell you so.

BOOK A SECURITY WORKSHOP

Find out where you actually stand

Whether you are responding to a customer questionnaire, preparing for Cyber Essentials, working through an insurance renewal, getting ready for Microsoft 365 Copilot, or you simply want a straight answer to take to your board, start with a conversation rather than a purchase.

  • Microsoft security specialists

    Speak directly with consultants who assess and configure these environments every day.

  • A report you can act on

    Scored, prioritised, licence-aware, and presented by the person who carried out the work.

  • No obligation to remediate with us

    The assessment is scoped and priced as standalone work, and written to be useful whoever does the fixing.

  1. 1
  2. 2
What is your enquiry about?*