M365 Security Posture Kit
Assess what a compromised Microsoft 365 account can actually reach, and close the gaps, before an insurer or auditor asks. Licence-tier-aware blast-radius scoring, a CIS-aligned hardening baseline, and one identity review covering Conditional Access, Entra ID Protection and PIM.
What this actually gives you
- Licence-tier-aware blast-radius scoring. Advanced Audit, risk policies, PIM, auto-labelling and single-pane correlation are each gated behind E5, Entra ID P2 or a Purview add-on — so the same settings score differently on E3 and E5. Confirming the tier is step one, and the tool changes its arithmetic when you do.
- One compromised standard-user account, thirteen control questions across five surfaces — mailbox, file & collaboration, app consent, identity, detection — resolving to a single score, a band, and a closure list ranked by risk-weighted points.
- Conditional Access, Entra ID Protection and PIM in one identity review instead of three disconnected checklists: 19 weighted controls rolling into one posture score.
- A CIS Microsoft 365 Foundations Benchmark-aligned hardening baseline scored gap-to-target rather than pass/fail, so partial progress shows.
- The commonest data-governance gap, named: DLP live on Exchange and never extended to Teams, which now carries the same sensitive content without the same guardrails.
"If one account were compromised right now, what could the attacker reach, and how would we know?" Every M365 tenant owner eventually gets asked that — by a board, an insurer, an auditor or an incident responder — and rarely has a ready answer. This kit is the answer, structured and defensible, in five modules and one page.
The score depends on what you are licensed for, and nobody else scores it that way. Advanced Audit, Identity Protection risk policies, PIM, auto-labelling, Defender XDR's single-pane correlation — each is gated behind E5, Entra ID P2 or a Purview add-on. Two tenants with identical settings have different blast radii if one cannot see what the compromised account did. So the first step of every module is to confirm the tier, and the flagship scoring tool changes its arithmetic when you do. Confirming the tier is also the single most common source of a wrong assessment, which is why it is step one.
What you get
01 Assessment Methodology (DOCX) — the five modules, who it is for and is not for, the run order, cross-links, and the assumptions that bound the scoring.
02 Identity & Access Review Workbook (XLSX) — Conditional Access coverage, Entra ID Protection risk policies, PIM assignment and activation, and guest access, as 19 weighted controls across four tabs that roll into one identity posture score with a rating. One review instead of three disconnected checklists.
03 Blast Radius Scoring Tool (XLSX) — the flagship module. Select the tenant's core licence and add-ons, answer thirteen control questions across mailbox, file & collaboration, app consent, identity and detection, and get a single blast-radius score, a band from Low to High, and a closure list ranked by risk-weighted points with owner and target date. If time is short, this is the module to present on its own.
04 CIS-Aligned Hardening Baseline Checklist (XLSX) — Identity, Data, App Governance and Endpoint families structured after the CIS Microsoft 365 Foundations Benchmark, scored gap-to-target rather than pass/fail, so partial progress is visible and a hardening percentage per family rolls up to the summary.
05 Data Governance Review (DOCX) — sensitivity label coverage, DLP scope across all four surfaces, and retention against a defined baseline, with the gap that turns up most often named: DLP live on Exchange and never extended to Teams.
06 Detection Readiness Matrix (XLSX) — activity type to log source to minimum tier to default retention to whether it is single-pane in Defender XDR. The direct answer to "could you see that from one view, or would you need several tools".
07 Executive Summary Template (DOCX) — one page: the four module scores, the top five findings ranked across every module, what they mean in plain terms, a remediation timeline and the next review date. Built to slot into a board pack.
m36501.json — scoring bands, licence-tier components, surfaces and the module map.
A worked example throughout. Meridian Faber Group, a fictional mid-market manufacturer on E3 with a Purview add-on, is filled into the scoring tool and the data governance review so you can see what a finding looks like before you write your own.
Where it sits. This is the assessment layer. It tells you where you stand and what to fix. Build Series vol. 06 — Identity & Access is where you implement what it flags, and vol. 01 — Detection & Monitoring goes further than file 06. The IR Runbook Library is the response layer — its runbook 03 is M365 account takeover — and the pair is cheaper than buying both. Run it against a vendor's tenant with the TPRM Program Kit; hand file 07 to the Director's Cyber Oversight Kit. For a client on Google Workspace, the Google Workspace Security Posture Kit is the same five modules on the other platform; the Okta / Identity Provider Security Posture Kit is the front door in front of both; the Salesforce Security Posture Kit covers the CRM behind it; the GitHub / GitLab Security Posture Kit covers the pipeline that ships the code; and the set of five covers the whole estate.
Written against Microsoft 365 and Entra ID names and licensing as of Q3 2026 for a standard commercial tenant — not GCC, GCC High or DoD, and not on-premises AD or hybrid identity. Microsoft re-tiers features regularly, so the licence logic is marked verify. Scores are a prioritisation aid, not a certification, an audit opinion or an insurance-underwriting determination. Not legal advice.
Also available in 2 bundles
This product is sold on its own and as part of a set. If you need more than this one, the set is cheaper than buying the parts.
M365 Posture + Response
The M365 Security Posture Kit plus the IR Runbook Library. Know what a compromised account can reach, and have the runbook ready when one is. 15% off buying separately.
Cloud Identity Posture Bundle
The M365, Google Workspace, Okta, Salesforce and GitHub / GitLab security posture kits together, for the vCISO or MSP whose clients run any mix of them. One mental model, five platforms: the front door, both suites, the CRM and the pipeline. 25% off buying separately.
What's included
- Complete Library (.zip) — all formats included — fully editable
- Instant download after purchase
- Free updates — re-download when we release new versions
- Practitioner License: unlimited client use (vCISO / MSP)
More from the CISO Marketplace ecosystem
Choose your license:
- Secure checkout via Stripe
- All major cards accepted
- 30-day satisfaction guarantee