Identity & Entra ID
Who holds administrative control, whether that control is standing or granted just in time, and whether emergency access is governed rather than improvised.

Schedule a Security AssessmentScheduleMicrosoft 365 & Entra ID security assessments
Atlas Secure Solutions assesses your Microsoft 365 and Entra ID security configuration, identifies the issues creating the most business risk, and delivers a prioritized remediation plan that your technical team and your leadership can both act on.
A consultant-delivered engagement. There is no software for you to log into and no agent to install.
Organizations of roughly 50 to 500 people running Microsoft 365 and Entra ID, where something has made security posture a real question rather than a background concern:
Microsoft 365 tenants rarely become exposed all at once. They drift. An administrator is granted permanent rights for a project that ended two years ago. A legacy protocol stays enabled for one scanning application. A sharing default is relaxed to get a file to a customer and never set back. Each decision was reasonable on the day it was made.
The result is risk spread thinly across identity, access policy, administrative control, sharing, and threat protection — visible in a dozen different admin centers, and in none of them as a single picture. Microsoft will tell you what is misconfigured. It will not tell you which three things an attacker would actually use, which ones your licensing already covers, or what to do on Monday.
The hard part is not producing a list of problems. It is knowing which ones matter, in what order, and why.
Seven areas of your Microsoft environment, assessed against checks with defined pass and fail criteria — so two consultants reach the same verdict, and a reassessment a year from now is directly comparable to this one.
Who holds administrative control, whether that control is standing or granted just in time, and whether emergency access is governed rather than improvised.
Not whether multi-factor authentication is enabled, but whether it is actually registered and enforced for the accounts that matter most.
The policies that decide whether your identity controls are genuinely enforceable — including the gaps, exclusions, and legacy protocols that quietly bypass them.
Whether the threat protection you are licensed for is deployed, covering the whole organization, and attached to a human process when it raises an alert.
What can leave your tenant, how, and to whom — anonymous link behavior, default permissions, and expiration across SharePoint and OneDrive content.
Treated as a claim to verify rather than a grade to report: we check whether the actions Microsoft believes are resolved actually hold up against independent findings.
Which protections you already pay for and are not using, and which findings are genuinely blocked by licensing rather than by oversight.
Checks that depend on premium licensing you do not hold are recorded as not applicable, with the reason stated — not failed. A legitimate licensing decision is not a security finding, and the licensing gap itself is reported separately where it is the real root cause.
Every control assessed, reconciled: passed, failed, needs review, not applicable, not assessed. The numbers add up, so nothing is quietly dropped.
Ordered by severity, not by the order in which we happened to find them. Each finding is a decision you can act on, not a configuration dump.
What each finding means in operational terms — what an attacker gains, what it would take to recover — written for leadership, not only for engineers.
The specific export, report, or log sample behind each finding, with the date it was collected. You can verify our conclusions, or hand them to a third party who will.
Prioritized and sequenced, with the effort involved, what each one depends on, and how to confirm the fix worked. We separate what costs money from what only costs attention.
One document carrying the scope, executive summary, posture overview, findings, results for every control assessed, our methodology, and a plain statement of what the assessment did not cover.
A live walkthrough of what we found, what we recommend, and the order to tackle it in — with your technical staff and your decision-makers in the same conversation.
One methodology, two depths. The Rapid Security Assessment runs a selected subset of the same checks the Comprehensive Security Assessment runs in full — not a lighter product held to a lower standard.
Start here
A focused engagement that answers one question honestly: how exposed are we, and what should we fix first?
Go deeper
The full methodology at depth, built to be defensible to a board, an underwriter, or a customer asking hard questions.
| Rapid | Comprehensive | |
|---|---|---|
| Checks executed | 20 of 33 | All 33 |
| Depth | Overall posture and coverage | Full validation, backed by evidence |
| Findings detail | Summary list with one-line remediation | Full written analysis per check |
| Evidence documentation | Recorded per finding | Documented in full |
| Remediation plan | Quick wins and strategic work | 30-60-90-day roadmap |
| Interviews | Kickoff only | Process and per-area walkthroughs |
| Findings review | About 60 minutes | About 90 minutes, plus a technical deep-dive |
| Typical fit | A first independent review, or a fast and defensible baseline | Compliance pressure, or a larger and more complex environment |
Engagements are quoted per organization, based on your user count and the complexity of your environment. A scoping conversation comes before any number.
Below is an excerpt from a Rapid Security Assessment report, in the format you would receive it.
Example assessment. “Cascade Precision Works” is a fictional company created to illustrate the deliverable. It is not an Atlas client, and every number, finding, and observation below is invented for this example.
This tenant is in reasonable shape for its size: multi-factor authentication is enforced for all users through Conditional Access, Entra Password Protection is enabled, and Safe Links and Safe Attachments cover the whole organization. Two issues account for most of the practical risk. Nine accounts hold standing Global Administrator rights, and legacy authentication is still permitted tenant-wide. Together, these mean a single phished credential could reach full tenant control without ever encountering an MFA prompt. Neither issue requires new licensing to fix.
| Assessed | Passed | Failed | Needs review | Not applicable | Not assessed |
|---|---|---|---|---|---|
| 20 | 11 | 4 | 2 | 2 | 1 |
Nine accounts hold permanent Global Administrator rights, and four of those are also used for everyday work. There is no just-in-time elevation, no approval step, and no periodic access review.
Business impact — a single successful phishing attack against any of the four dual-purpose accounts yields complete control of the tenant: all mail, all files, and the ability to disable the logging that would show it happened.
Evidence — directory role assignment export, plus a sign-in log sample for the four dual-purpose accounts across a 30-day window.
Remediation — reduce standing assignments to two governed emergency-access accounts, move named administrators to separate privileged accounts, and introduce a recurring access review. Premium licensing would allow just-in-time elevation and is reported separately as the root cause.
Legacy protocols cannot present an MFA challenge, and they are still accepted, so an attacker can bypass the tenant’s universal MFA policy from the public internet. Sign-in logs show 1,184 successful legacy sign-ins in the preceding 30 days, predominantly from one shop-floor application.
Business impact — the MFA control this company already pays for, and believes is protecting the tenant, does not stop an attacker who chooses a legacy endpoint. Password-spray attacks against these endpoints succeed silently and resemble ordinary mail traffic.
Remediation — the cheapest meaningful improvement available: one Conditional Access policy and a change to one application, with no new licensing.
Anonymous links are permitted, default to Edit permission, and have no expiration configured. Links created years ago are still live, and anyone holding the URL can change the content — including through a forwarded message or a departed employee’s device.
Straightforward improvements the company is already licensed for remain unimplemented, and there is no way to show a customer or an insurer that security posture is actively managed rather than merely measured. The cost of fixing this is process, not product.
The full report also carries the scope statement, the result of every check executed, the methodology and severity definitions, and a plain statement of what the assessment did not cover.
A short call to confirm what is in and out of scope, your tenant's size and licensing, and who needs to see the result.
We collect configuration evidence from your Microsoft environment through read-only access, and record where each piece came from.
Each control is assessed against objective pass/fail criteria, then cross-checked so findings are prioritized relative to one another rather than in isolation.
Findings, business impact, evidence, and remediation guidance are written up as one document, ready to share with your leadership.
We walk your team through the findings and the remediation order, and answer the questions that always come up once results are real.
Every check has a defined pass or fail condition decided in advance. A verdict does not depend on who performed the assessment or what mood the environment put them in.
Each finding names the specific export, report, or log sample behind it, and when it was collected. Our conclusions are reproducible, not just asserted.
An assessment observes your environment; it does not alter it. We make no changes to your tenant.
Every report states what was out of scope and what could not be collected. An assessment is a security posture review — it is not a certification, an attestation, an audit opinion, or a claim that you comply with any framework.
Tell us a little about your environment and we will get back to you to arrange a scoping conversation. There is no obligation, and nothing is quoted before we understand what you are running.