Assessment
A focused assessment that gives your team a documented picture of the current environment.
Includes
- Defined scope and test coverage
- Security assessment
- Evidence-backed findings
- Prioritised recommendations
- Results walkthrough
Assessment services
We combine automated evidence gathering with engineer review. The result is designed to be more useful than a raw scan: findings are explained, prioritised and connected to practical remediation.
A structured assessment against the CIS Microsoft 365 Foundations Benchmark. Each applicable control is tested and recorded as pass, fail or not applicable, with supporting evidence and context.
What we deliver
A read-only scan of Microsoft 365 configuration using the permissions the client grants. Designed to surface weak settings and misconfigurations quickly, with repeat scans available to demonstrate progress and identify configuration drift.
What we deliver
From findings to fixes
A focused assessment that gives your team a documented picture of the current environment.
Includes
Assessment plus engineering support to address agreed findings.
Includes
Recurring reviews designed to catch configuration drift and keep security controls aligned as the environment changes.
Includes

Assurance services
Security posture is more than configuration. GreenPoint365 helps organisations connect what they say they do with what is actually configured and operating in Microsoft 365.
Retention is not the same as backup. We review how Exchange Online data is protected, retained and recoverable, including third-party backup coverage where applicable.
We can verify
We review security policies for currency, ownership and practical fit. Where policies are missing or generic, we can develop them around the organisation's operating environment, industry and security requirements.
Typical areas include
Policies should connect to technical controls. Technical controls should be traceable to what the organisation has committed to doing. We create that connection — a traceability view showing where policy, configuration and evidence align, and where they do not.
Typical mappings include
For organisations that need more than a baseline review, we can design and implement a hardened Microsoft 365 configuration based on the organisation's risk profile and available licensing.
Areas can include
Policy drafting supports, and does not replace, legal advice. These services do not certify regulatory compliance or guarantee an insurance outcome.
Recognised frameworks. Engineering judgement.
We use recognised security references as part of our assessment methodology, while interpreting findings in the context of the organisation and its environment.
Referencing a framework or benchmark does not imply certification, endorsement or accreditation by its publisher.
Start the conversation
Whether you are an MSP looking for specialist Microsoft 365 engineering, a business preparing for a security review, or an insurance professional supporting a client's cyber risk conversation, we can start with a focused assessment.
Tell us about the environment, the objective and what needs to be demonstrated. We'll help define a practical scope.