Security
Microsoft 365 security assessment
Find out exactly where you stand, in a report you can hand to your board, your insurer or your customer. Valto assesses your Microsoft 365 and Entra ID environment against Microsoft's recommended baselines, CIS benchmarks and Cyber Essentials requirements, covering identity, privileged access, devices, email, data protection and monitoring. You get a scored, prioritised findings report with each item weighed by impact and effort, and a clear view of what your existing licences already cover. Available through G-Cloud.

TRUSTED BY ORGANISATIONS LIKE YOURS













A straight answer about your current security position
Most organisations running Microsoft 365 have a rough sense that their security could be better and no clear view of where the gaps actually are. Secure Score gets checked occasionally. A previous assessment produced a spreadsheet nobody could act on. Somebody remembers that MFA has exceptions, without remembering who holds them. Valto's assessment replaces that with a documented position. We review your tenant against Microsoft's recommended baselines, the CIS Microsoft 365 Foundations Benchmark and Cyber Essentials technical controls, covering identity, privileged access, conditional access, devices, email, data protection, monitoring and audit retention. What you get back is not a raw export. It is a scored, prioritised report that tells you what is exposed, what it would take to fix, which items your existing licences already cover, and which ten things to do first. Whether the remediation happens with us, with your internal team or with somebody else is genuinely your decision. The assessment is useful either way, and it is priced and scoped as a standalone piece of work.
Our security assessments
Most organisations start with a workshop and decide from there. All three are scoped and priced as standalone engagements, with no obligation to take the remediation work with us.
Assessments against a specific framework
Where you are being measured against a specific standard, we map your environment directly against its controls and give you the evidence as well as the gap list.
Cyber Essentials readiness
We assess your Microsoft environment against the five Cyber Essentials technical controls: user access control, secure configuration, malware protection, security update management and firewalls. You get the gap list, a remediation plan and the evidence needed to certify. Certification itself is carried out by an accredited certification body; we get you ready to pass first time.
CIS Microsoft 365 Foundations Benchmark
A structured audit against the CIS benchmark, scoring your tenant control by control and identifying failures by severity. This is the assessment to choose where an auditor, insurer or customer has asked for a recognised independent standard rather than a supplier's own opinion.
Customer and supply chain security questionnaires
Where a customer has sent a security questionnaire that has to be returned before a contract is awarded or renewed, we work through it against your actual environment, establish what is true today, close what needs closing and document the rest.
NIS2 readiness
For organisations with EU operations, EU customers, or a place in an in-scope EU supply chain, we assess governance, controls, monitoring and reporting against NIS2 requirements.
Hear from our experts
Watch: From reactive to proactive: Securing Microsoft 365 for AI
In this episode, Rob Thomas (Head of Modern Work), Will Jones (Senior Consultant) and James Belsey (Project Manager) discuss why a proactive security strategy is becoming essential, how Microsoft 365 security has evolved, and what organisations should consider before rolling out AI tools like Microsoft Copilot.
Focused assessments
Where you already know roughly where the problem is, or where a specific area needs to stand up to scrutiny on its own.
Entra ID security assessment
MFA coverage and exceptions, global administrator exposure, privileged access, risky sign-ins, Identity Protection configuration, guest access.
Conditional access review
Existing policy coverage and gaps, device compliance requirements, location and risk-based controls, and whether the policies protect what they appear to.
Microsoft Purview assessment
Data classification, sensitivity labels, DLP policies, retention, and the regulatory position they are meant to support.
Intune and endpoint security assessment
Device compliance, security baselines, Autopilot configuration, BYOD controls, application protection policies, and which devices no policy currently reaches.
Microsoft Defender assessment
Defender for Endpoint, Office 365, Identity and Cloud Apps: configuration, coverage and whether the detections are reaching anybody.
What the report actually contains
A scored current position
Your Secure Score, benchmark scoring and a maturity position by area, so you have a number to compare against next year.
Findings prioritised by impact and effort
Every finding scored, so a two-hour change that closes real exposure is not buried alphabetically beneath something that would take a quarter.
What your licences already cover
Each recommendation marked according to whether it is included in what you already pay for, or whether it needs additional licensing. In most assessments the majority is already covered.
A remediation roadmap
Sequenced into quick wins, planned work and longer-term change, with an indication of effort and any user impact to plan around.
Evidence you can hand over
Documented configuration positions in a form that can be attached to a questionnaire, taken to an insurer, given to an auditor or presented to a board.
A walkthrough with the consultant who did the work
The report is presented rather than emailed. The value is in the conversation about what to do first, and that conversation should be with the person who looked at your tenant.
Why work with Valto's security specialists?
The assessment stands on its own
It is scoped, priced and delivered as a standalone piece of work. Whether the remediation happens with us, your own team or another supplier is your decision, and the report is written to be useful either way.
We start with what you already own
Every recommendation is marked according to whether your existing licences cover it. Most of the time they do, and we have no product of our own to sell you.
Mapped to standards somebody else recognises
Microsoft's recommended baselines, the CIS Microsoft 365 Foundations Benchmark and Cyber Essentials technical controls, so the findings carry weight with auditors, insurers and customers rather than being one supplier's view.
Prioritised, not exhaustive
Every tenant has dozens of possible improvements. We tell you which ten matter most for your organisation rather than handing over a two-hundred-item export.
Available through G-Cloud
Public sector organisations and others buying through the Digital Marketplace can procure the assessment directly, without running a separate tender process.
Delivered by the people who do the remediation
The assessment is carried out by consultants who configure these environments daily, which is why the effort estimates are realistic and the roadmap is sequenced in an order that actually works.

WHAT ASSESSMENTS TYPICALLY FIND
The gaps that are easy to miss and hard to explain
Very little of what we find is a missing product. It is settings left at default, access granted for a reason that no longer applies, and policies applied to part of the estate and never finished. These are the findings that recur across almost every assessment we run:
- Multi-factor authentication covering most people, with exceptions nobody has revisited
- More permanent global administrators than anyone would approve today
- Privileged access held standing rather than granted when needed
- Accounts belonging to people who left, still licensed and still enabled
- Sharing links and "everyone" permissions making internal content far more available than intended
Turn findings into business value
An assessment is only worth commissioning if something happens as a result. These are the outcomes the findings usually unlock.
How we deliver security assessments
From a first conversation about what you are being asked to prove, through to a scored position, a prioritised roadmap and a walkthrough with the consultant who carried out the work.
1Scoping
Establish what you need to prove and to whom
A short conversation, or the workshop, to establish your obligations, deadlines, licensing position and which framework you are being measured against. This determines the assessment scope and avoids paying for depth you do not need.
2Access
Read-only, and time-limited
We need read-only access to your tenant for the assessment period. No configuration is changed, nothing is deployed, and access is removed when the assessment completes.
3Assessment
Automated collection, human interpretation
Configuration data is collected systematically, then reviewed by a consultant against Microsoft's baselines, the CIS benchmark and your own risk position. The collection is the easy part; deciding which findings matter for your organisation is the work.
4Reporting
Scored, prioritised and licence-aware
You get a scored current position, findings ranked by impact and effort, what your existing licences already cover, and a sequenced remediation roadmap.
5Walkthrough
Presented, not emailed
We present the findings to your team, agree what to do first, and answer the questions the report will inevitably raise. What happens next is your decision.
We're one of the UK's few Microsoft partners to hold all Microsoft Solution Partner designation badges, across all Solution Partner designation pathways. For our clients, that means working with specialists who understand how identity, devices, data and applications fit together rather than treating security as a separate technical exercise. Whether you're preparing for certification, responding to a customer questionnaire or simply want a straight answer about where you stand, we assess the Microsoft platform you already run against standards other people recognise.
WHY ORGANISATIONS CHOOSE VALTO


CONNECTED, ACROSS MICROSOFT
A tenant cannot be assessed one product at a time
Identity sits in Entra ID. Devices sit in Intune. Email sits in Defender. Content sits in SharePoint and OneDrive. Classification sits in Purview. Infrastructure sits in Azure. A gap in any one of them is reachable through the others, which is why an assessment that looks at each in isolation misses the findings that matter most. Valto brings together expertise across Microsoft 365, Azure, identity, endpoints, data and Microsoft 365 Copilot. That lets our consultants see how a conditional access decision affects collaboration, how a sharing setting affects Copilot, and how a licensing decision affects what security capability is available at all. The result is a single assessed position across the estate rather than six separate opinions about six products.

“Valto recently delivered an excellent Azure Virtual Desktop environment, expertly project managed by Kerina, while the team has also supported us with security hardening across our Microsoft environment. Having worked with a number of Microsoft partners over the years, I can genuinely say that Valto are the best in the business.”
The team driving you forward




You may also be interested in
Questions, answered plainly
Practical answers on what the assessment covers, what access we need, what it costs, how it maps to Cyber Essentials and CIS, and what happens once you have the report.
BOOK A SECURITY WORKSHOP
Find out where you actually stand
Whether you are responding to a customer questionnaire, preparing for Cyber Essentials, working through an insurance renewal, getting ready for Microsoft 365 Copilot, or you simply want a straight answer to take to your board, start with a conversation rather than a purchase.
Microsoft security specialists
Speak directly with consultants who assess and configure these environments every day.
A report you can act on
Scored, prioritised, licence-aware, and presented by the person who carried out the work.
No obligation to remediate with us
The assessment is scoped and priced as standalone work, and written to be useful whoever does the fixing.




