Sample deliverable, redacted
Microsoft 365 security gap analysis
Read this before the table. The controls, their identifiers, their severity, their remediation lines and their public sources are real and are rendered from the same module the free Microsoft 365 Security Scorecard uses, so they cannot drift from the product. The verdicts, the evidence sentences and the effort tags are illustrative: a composite of what a first pass typically finds. No customer's tenant, posture or identity is published here, and none was used to produce this page.
- Prepared for
- Redacted. 180-seat operator, professional services
- Baseline
- ITSailor Microsoft 365 Security Baseline (ITS-M365) v0.1.0-draft
- Scope
- Entra ID, Exchange Online, Intune, external sharing
- Method
- Read-only. Live session plus delegated Microsoft Graph and public DNS
- Sampled window
- 30 days of sign-in and audit data
- Status
- Draft diagnostic subset, 38 controls
Findings, in remediation order
Ordered by what unblocks the next item, not by severity. Fixing standing administrator count before legacy authentication is blocked moves the problem rather than closing it.
| Control | Severity | Verdict | Evidence | Effort |
|---|---|---|---|---|
| ITS-M365-ID-001Is MFA enforced for all admin accounts? | critical | Partly met | Conditional Access requires MFA for Global Administrator. Four other privileged roles, including Exchange Administrator, are not in the policy scope. | Under an hour, one policy edit |
| ITS-M365-ID-003Is Basic and other legacy authentication blocked tenant-wide? | critical | Not met | No policy blocks legacy authentication. Sign-in logs show legacy client attempts against three mailboxes in the sampled window. | Half a day, report-only first |
| ITS-M365-PA-003Does your tenant have fewer than 5 permanent Global Administrators? | high | Not met | Nine standing Global Administrators, of which two are shared accounts and one has no sign-in recorded in the sampled window. | One to two weeks, owner per assignment |
| ITS-M365-EM-001Is DMARC configured with p=quarantine or p=reject (not p=none)? | high | Not met | DMARC record present at p=none with no rua address, so nothing is enforced and nothing is being reported. | One hour, then weeks of monitoring |
| ITS-M365-EP-001Are end-user devices enrolled in Microsoft Intune for device management? | high | Partly met | Laptops enrolled. Personally owned mobile devices access mail without enrolment or an app protection policy. | One to two weeks, needs a user comms plan |
| ITS-M365-ID-004Is guest (external) user access reviewed and time-bound? | medium | Not met | Guest accounts present with no expiry and no review. The oldest predates the current tenant administrator. | Half a day to review, ongoing to keep |
One finding, worked through
Every row in the table above is expanded like this in the delivered document. One is expanded here so you can see what the expansion contains rather than being told it is thorough.
ITS-M365-PA-003 · essential profile · high
Does your tenant have fewer than 5 permanent Global Administrators?
What we read
Delegated Microsoft Graph, read-only, during the session with you watching the screen. Directory role assignments and their activation type.
What it returned
Nine standing Global Administrators, of which two are shared accounts and one has no sign-in recorded in the sampled window.
Why it matters
ITS-M365 uses fewer than five standing Global Administrators as a diagnostic threshold. Every assignment still needs an owner and reason.
What to do
Reduce standing Global Administrators below five and move other eligible assignments to PIM.
Effort
One to two weeks, owner per assignment
Sources for this control
Directional crosswalk, not a compliance opinion: DORA Art. 9 · NIST CSF PR.AA. A crosswalk says which obligation a control speaks to. It does not say you satisfy that obligation, and nothing on this page certifies anything.
What this page is, exactly
- One page of a longer document. The delivered gap analysis covers the control families agreed with you at the start of the session, not six rows.
- Read-only throughout. The session uses delegated Microsoft Graph and public DNS. Nothing in the workshop changes a setting in your tenant. Changes are yours to make, in your own order.
- The baseline is a draft diagnostic subset. 38 controls, version 0.1.0-draft. It is not a certification, not an audit opinion, and not the complete ITSailor baseline.
- The findings are illustrative and the controls are not. Said twice on purpose, because this is the sentence a reader skips.