Microsoft 365 posture
The tenant settings insurers ask about, read on a schedule.
M365 security posture is a recurring review of the Microsoft 365 tenant. ScubaGear and Maester run the Microsoft checks. Prowler covers cloud posture and Google Workspace. The output is a written drift report, sometimes shaped in CISO Assistant. None of that is a certification.
- Bundles
- Pro and Complete, for firms on Microsoft 365. A Google-only firm is not billed for this checklist.
- Coverage
- Continuous automated monitoring, with on-call response
- Price status
- Proposed — pending validation of hosting and staffing cost
What we watch
- Multi-factor authentication for users and for admins.
- Legacy authentication, external forwarding, and inbox rules that send mail outside the firm.
- How many global admins exist, whether auditing is on, and how sharing and guest access are set.
- Drift since the last review: what changed, and whether anyone meant it to.
What runs it
- ScubaGear and Maester for Microsoft 365 and Entra, read-only. A settings change is a separate written request.
- Prowler for Google Workspace and for cloud accounts in scope. ScubaGear does not scan Google.
- CISO Assistant when we turn findings into a report the firm can file. The report is not an attestation.
- OpenVAS and Nuclei only inside a scan scope the order names. They are not how this review starts.
What a person does
- Writes the baseline in language a partner can read.
- Checks it on the schedule in the order. Planning rhythm: monthly, with the letter.
- Separates “fix this week” from “this needs a license you may not own.”
What you decide
- Own the tenant. We recommend; we change settings only when asked.
- Tell us which licenses you already pay Microsoft for. Conditional Access advice depends on that. We will not assume Entra ID P2.
- Decide which exceptions are real. A shared mailbox for court filings may need a different rule than a partner’s mailbox.
Limits
- Google Workspace posture is a Prowler review, not the ScubaGear baseline. We will not pretend those are the same document. A Google-only firm is not billed the Microsoft checklist line.
- We do not certify the tenant against CIS, NIST, HIPAA, SOC 2, or a bar opinion.
- A checklist does not see a mailbox forward that auditing cannot see. Identity monitoring is the other half, and it is a separate line in the bundle.
- We do not inherit your Microsoft agreement, and we do not resell Microsoft licenses.
We are not affiliated with or endorsed by the open-source projects named on this page.
The other services
- Managed EDRAn agent on the computers people work on, and a person who reads what it finds.
- Managed ITDRSign-ins, inbox rules, and admin changes in Microsoft 365 and Google Workspace.
- Managed SIEMLog sources the endpoint agent does not already cover, kept and reviewed.
- Security Awareness TrainingShort simulations and a debrief a managing partner can read in a staff meeting.