Microsoft 365 Security Assessment
Assess your Microsoft 365 tenant’s security posture in minutes — Secure Score, identity and access, third-party app consent and email authentication — then get a prioritized list of exactly what to fix. Read-only, and free to run.
Connects through Microsoft’s own admin-consent screen. No password ever reaches us.
A Microsoft 365 security assessment reviews the security-relevant parts of a tenant — its Microsoft Secure Score, identity and access hygiene, third-party app consent, and email authentication — and turns what it finds into a prioritized list of fixes. M365 Health Score performs this assessment read-only, using Microsoft Graph, and scores the result as part of an overall Health Score out of 100.
The security checks it runs
Each area below maps to a real check. Nothing here is aspirational — it is what the scan actually inspects.
| Area | What’s assessed |
|---|---|
| Microsoft Secure Score | Ingests your tenant’s live Secure Score and per-control profiles, translating Microsoft’s recommendations into plain-language fixes. |
| Identity & access | Users with no MFA, a dedicated flag for Global Admins with no MFA, Global Administrator role sprawl, dormant admins, stale guests, and never-expiring passwords paired with no MFA. |
| App-consent exposure | Third-party applications holding high-risk Microsoft Graph permissions in your tenant — the shadow-IT consent risk most admins never review. |
| Email authentication | SPF and DMARC record checks by direct DNS lookup, so spoofed mail is caught. |
How it relates to Microsoft Secure Score
Microsoft Secure Score measures your Microsoft security posture and gives Microsoft’s recommended improvements. A M365 Health Score security assessment complements it: it reads your Secure Score and adds tenant-health checks — identity hygiene, app-consent exposure, email authentication and license efficiency — in one place. If you already use Secure Score, this shows what a broader read adds. See Secure Score vs M365 Health Score.
Doing it by hand
Reproducing this manually means cross-referencing the Microsoft 365 admin center, the Defender portal’s Secure Score, Entra ID sign-in and role data, Enterprise Applications consent grants, and public DNS for each domain — then judging severity yourself. The assessment does that pass in minutes and ranks the results.
This assessment does not review Conditional Access policies, DLP, sensitivity labels, retention or Intune device compliance, and it never opens mail, files or messages. It reads only what’s needed to score the areas above.
Microsoft 365 security assessment FAQ
What is a Microsoft 365 security assessment?
A Microsoft 365 security assessment reviews the security-relevant parts of a tenant — its Microsoft Secure Score, identity and access hygiene, third-party app consent, and email authentication — and produces a prioritized list of weaknesses to fix. M365 Health Score runs this read-only, in minutes.
Is the security assessment free?
Yes. Running the scan and seeing your overall Health Score is free. The full itemized report, with every finding and a remediation roadmap, is a paid upgrade.
Does a security assessment replace Microsoft Secure Score?
No. It complements Secure Score. M365 Health Score ingests your actual Secure Score and adds checks around identity, app consent and email authentication that round out the picture of tenant health.
What does the assessment not cover?
It does not analyze Conditional Access policies, Data Loss Prevention, sensitivity labels, retention or device compliance, and it never reads mail, files or messages. It is strictly read-only.
Run a free Microsoft 365 security check
See your Health Score and where your tenant is exposed — read-only, in minutes.