https://store-images.s-microsoft.com/image/apps.40812.8eb60ddf-ac34-40c8-a8ce-4c27d8c076d2.7184f90c-2574-4312-bf45-a67e9a197ac6.99873484-1d0a-45de-8cf8-526146564a53

Microsoft 365 Security Assurance Service: Assessment

Performanta

The Microsoft 365 Security Assurance Service focuses on validating that your Microsoft 365 controls are effectively and appropriately deployed, and that nothing has been missed.

The Microsoft 365 Security Assurance Service focuses on validating that your Microsoft 365 controls (including the Defender suite) are effectively and appropriately deployed, and that nothing has been missed. It is an ongoing service with regular checks carried out, and periodic reviews, ensuring that you can be assured that your Microsoft 365 is always up to date and configured correctly.

Whilst Microsoft takes responsibility and ownership for most of the layers of your Microsoft 365 environment, organisations are still responsible for their own SaaS configuration. It is therefore critical that organisations not only review and check that their environment is optimally configured but also that it is continuously reviewed to both address the latest threats and take advantage of new controls when they're released. Keeping on top of the ever-evolving complex range of controls presents a challenge to IT and security teams.

Performanta’s Security Assurance service addresses this gap by working to understand organisations’ threats, needs and risk appetites and then working with them to iteratively improve their security posture and configuration, through a blend of reviews, assessments and targeted support.

The Microsoft 365 SAS service is built on the ISO model of iterative improvement. Performanta will take an initial baseline of the current Microsoft 365 security posture at the start of the year. Performanta will then:

  • Provide an annual roadmap of improvements based on business need, risk and complexity
  • Perform additional reviews for the year, based on the above report and current security posture
  • Support roadmap defined improvements
  • Carry out regular reviews of key reports (e.g. elevated privilege or Conditional Access change)
  • Deliver appropriate Microsoft workshops to supplement the service.

Controls and checks consider the following key areas:

  • Identity
  • Application
  • Data
  • Email
  • Storage
  • Mobile Device Management

At a glance

https://store-images.s-microsoft.com/image/apps.34747.8eb60ddf-ac34-40c8-a8ce-4c27d8c076d2.7184f90c-2574-4312-bf45-a67e9a197ac6.8fbf6e5c-2d4d-4b6b-a34d-443fbba69d31
https://store-images.s-microsoft.com/image/apps.58724.8eb60ddf-ac34-40c8-a8ce-4c27d8c076d2.7184f90c-2574-4312-bf45-a67e9a197ac6.6713a944-f7f3-4965-b3bb-5a7a03c74e25
https://store-images.s-microsoft.com/image/apps.62156.8eb60ddf-ac34-40c8-a8ce-4c27d8c076d2.7184f90c-2574-4312-bf45-a67e9a197ac6.41523afc-4c81-4e44-9f8e-0aa25bea3bd8
https://store-images.s-microsoft.com/image/apps.42166.8eb60ddf-ac34-40c8-a8ce-4c27d8c076d2.500a9f26-b8f3-40b9-b27a-3c3f629a5ba0.05f0be4b-366c-44f8-868a-31b23231fa7c