MetisShield
MenuClose

Microsoft 365 posture

The tenant settings insurers ask about, read on a schedule.

M365 security posture is a recurring review of the Microsoft 365 tenant. ScubaGear and Maester run the Microsoft checks. Prowler covers cloud posture and Google Workspace. The output is a written drift report, sometimes shaped in CISO Assistant. None of that is a certification.

Bundles
Pro and Complete, for firms on Microsoft 365. A Google-only firm is not billed for this checklist.
Coverage
Continuous automated monitoring, with on-call response
Price status
Proposed — pending validation of hosting and staffing cost

What we watch

  • Multi-factor authentication for users and for admins.
  • Legacy authentication, external forwarding, and inbox rules that send mail outside the firm.
  • How many global admins exist, whether auditing is on, and how sharing and guest access are set.
  • Drift since the last review: what changed, and whether anyone meant it to.

What runs it

  • ScubaGear and Maester for Microsoft 365 and Entra, read-only. A settings change is a separate written request.
  • Prowler for Google Workspace and for cloud accounts in scope. ScubaGear does not scan Google.
  • CISO Assistant when we turn findings into a report the firm can file. The report is not an attestation.
  • OpenVAS and Nuclei only inside a scan scope the order names. They are not how this review starts.

What a person does

  • Writes the baseline in language a partner can read.
  • Checks it on the schedule in the order. Planning rhythm: monthly, with the letter.
  • Separates “fix this week” from “this needs a license you may not own.”

What you decide

  • Own the tenant. We recommend; we change settings only when asked.
  • Tell us which licenses you already pay Microsoft for. Conditional Access advice depends on that. We will not assume Entra ID P2.
  • Decide which exceptions are real. A shared mailbox for court filings may need a different rule than a partner’s mailbox.

Limits

  • Google Workspace posture is a Prowler review, not the ScubaGear baseline. We will not pretend those are the same document. A Google-only firm is not billed the Microsoft checklist line.
  • We do not certify the tenant against CIS, NIST, HIPAA, SOC 2, or a bar opinion.
  • A checklist does not see a mailbox forward that auditing cannot see. Identity monitoring is the other half, and it is a separate line in the bundle.
  • We do not inherit your Microsoft agreement, and we do not resell Microsoft licenses.

We are not affiliated with or endorsed by the open-source projects named on this page.

The other services

Tell us how the firm is set up.

An assessment is a conversation and a short written note. It is not a penetration test, and it is not a contract. Nothing on this site takes payment.

Book an assessment