GreenPoint365

Assessment services

A structured view of the Microsoft 365 tenant

We combine automated evidence gathering with engineer review. The result is designed to be more useful than a raw scan: findings are explained, prioritised and connected to practical remediation.

Microsoft 365 CIS Controls Assessment

A structured assessment against the CIS Microsoft 365 Foundations Benchmark. Each applicable control is tested and recorded as pass, fail or not applicable, with supporting evidence and context.

What we deliver

  • Control-by-control results
  • Evidence captured for tested controls
  • Risk- and effort-prioritised findings
  • Identification of controls that could not be tested
  • Executive summary for business leaders, brokers and underwriters
  • Remediation recommendations

Tenant Configuration Scanning

A read-only scan of Microsoft 365 configuration using the permissions the client grants. Designed to surface weak settings and misconfigurations quickly, with repeat scans available to demonstrate progress and identify configuration drift.

What we deliver

  • Entra ID and identity configuration review
  • Exchange Online and Microsoft 365 configuration
  • Device and endpoint settings
  • Engineer review to remove noise and add context
  • Repeat scans to track progress
  • Before-and-after verification

From findings to fixes

Choose the level of support you need

01

Assessment

A focused assessment that gives your team a documented picture of the current environment.

Includes

  • Defined scope and test coverage
  • Security assessment
  • Evidence-backed findings
  • Prioritised recommendations
  • Results walkthrough
02

Assessment + Remediation

Assessment plus engineering support to address agreed findings.

Includes

  • Everything in Assessment
  • Remediation planning
  • Configuration changes or engineering guidance
  • Change documentation
  • Re-testing
  • Verification evidence
03

Ongoing Assurance

Recurring reviews designed to catch configuration drift and keep security controls aligned as the environment changes.

Includes

  • Scheduled reassessments
  • Configuration drift detection
  • Progress tracking
  • Verification of remediation
  • Updated evidence
  • Ongoing engineering support where agreed
Layered glass and metal forms representing structured security review

Assurance services

Because a policy is only useful when the control exists.

Security posture is more than configuration. GreenPoint365 helps organisations connect what they say they do with what is actually configured and operating in Microsoft 365.

Email backup & retention verification

Retention is not the same as backup. We review how Exchange Online data is protected, retained and recoverable, including third-party backup coverage where applicable.

We can verify

  • Retention policies, labels and holds
  • Deleted and recoverable items
  • Archive configuration
  • Third-party backup coverage
  • Backup frequency and last successful run
  • Sample restore results
  • Identified gaps and recommended actions

Policy review & creation

We review security policies for currency, ownership and practical fit. Where policies are missing or generic, we can develop them around the organisation's operating environment, industry and security requirements.

Typical areas include

  • Access control
  • MFA
  • Acceptable use
  • Email security
  • Backup and retention
  • Incident response
  • Joiner, mover and leaver processes

Policy-to-control mapping

Policies should connect to technical controls. Technical controls should be traceable to what the organisation has committed to doing. We create that connection — a traceability view showing where policy, configuration and evidence align, and where they do not.

Typical mappings include

  • MFA policy → Conditional Access
  • Device policy → Intune compliance
  • Retention policy → Microsoft Purview
  • Email security policy → SPF, DKIM and DMARC

High-assurance tenant security configuration

For organisations that need more than a baseline review, we can design and implement a hardened Microsoft 365 configuration based on the organisation's risk profile and available licensing.

Areas can include

  • Conditional Access
  • MFA and legacy authentication controls
  • Privileged access and break-glass accounts
  • Least privilege
  • Email protection, SPF, DKIM and DMARC
  • Anti-phishing controls
  • Audit logging and alerting
  • External sharing
  • Post-change verification

Policy drafting supports, and does not replace, legal advice. These services do not certify regulatory compliance or guarantee an insurance outcome.

Recognised frameworks. Engineering judgement.

Baselines provide structure. Context makes them useful.

We use recognised security references as part of our assessment methodology, while interpreting findings in the context of the organisation and its environment.

CIS Microsoft 365 Foundations Benchmark

A structured benchmark for Microsoft 365 security configuration.

CISA SCuBA

Secure Cloud Business Applications guidance for cloud environments, including Microsoft 365.

Microsoft Secure Score

A Microsoft-native security signal used alongside deeper configuration assessment.

Client and MSP standards

Where an MSP or organisation has its own security standard, we can incorporate it into the assessment scope.

Referencing a framework or benchmark does not imply certification, endorsement or accreditation by its publisher.

Start the conversation

Let's strengthen the security story.

Whether you are an MSP looking for specialist Microsoft 365 engineering, a business preparing for a security review, or an insurance professional supporting a client's cyber risk conversation, we can start with a focused assessment.

Tell us about the environment, the objective and what needs to be demonstrated. We'll help define a practical scope.