Skip to main content
All services

SERVICE 04 · STRACE MODERN

Secure the Microsoft cloud your business runs on.

We assess configuration, access, and detection coverage across Microsoft 365, Azure, and cloud identity. Findings give your IT team or MSP a prioritized plan for remediation.

THE PROBLEM

Cloud security depends on who can sign in, what they can reach, and whether suspicious activity is visible. An assessment examines those controls together, including email, sharing permissions, administrator access, and logging.

FLAGSHIP ASSESSMENT

Microsoft 365 & Azure Security Assessment

A fixed-scope review against current Microsoft and CISA hardening guidance. Receive a prioritized findings report and a 60-minute executive readout. Typical timeline: 2–3 weeks, confirmed during scoping.

Request the assessment

Starting at $5,000

BEST FOR

  • Microsoft 365 or Azure tenants that have not been formally reviewed since provisioning
  • An upcoming cyber insurance renewal that requires evidence of M365 or Azure hardening
  • Recent suspicious activity in identity logs, mailbox rules, or admin actions
  • An audit or compliance requirement that touches the cloud tenant

WHAT WE OFFER

Five productized assessments.

CLD-A

Cloud Security Posture Assessment

A broad review of your cloud security posture across configuration, exposed services, secrets management, default-deny gaps, and account hygiene. Vendor-agnostic: covers Microsoft 365, Azure, AWS, and Google Workspace as relevant. Deliverable: a scored posture report with prioritized remediation steps and a clear picture of what attackers see versus what you have assumed.

CLD-B

Microsoft 365 & Azure Security Assessment

The flagship engagement. Fixed-scope assessment of your Microsoft 365 and Azure tenants against current Microsoft and CISA hardening guidance. See the featured section above for full scope and deliverables.

CLD-C

Cloud Identity & Access Risk Assessment

Deep review of identity infrastructure across Entra ID and cloud IAM: MFA enforcement, conditional access policies, privileged role assignments, legacy authentication exposure, federation, and break-glass account hygiene.

CLD-D

Cloud Security Control Alignment

Cloud posture mapped against applicable control requirements: SOC 2, ISO 27001, HIPAA, cyber insurance carrier controls, or other agreed requirements where supported. Deliverable: a written gap report showing exactly which controls your current cloud configuration satisfies, which it does not, and what implementation work would close the remaining gaps.

CLD-E

Cloud Detection & Response Readiness Assessment

A review of logging coverage, alert tuning, and IR runbook readiness in cloud environments. Covers Microsoft 365 audit log retention, Sentinel or third-party SIEM configuration, alert rules, and gaps in incident investigation and escalation procedures.

WHO THIS IS FOR

Small and mid-sized businesses running Microsoft 365 with no in-house security team · Professional services firms with sensitive client data in OneDrive and SharePoint · Healthcare and behavioral health practices with HIPAA obligations · Nonprofits and associations with limited IT staff · Defense and government contractors with framework-driven security obligations · Any organization told by their insurance carrier to harden their cloud · MSPs needing senior security depth on cloud assessments

HOW WE WORK

Inventory, assess, report, handoff.

01 · INVENTORY

Identify what is in scope, who has access, and what is actually configured versus assumed.

02 · ASSESS

Review against current Microsoft, CISA, and industry hardening guidance, with severity tiered to your business risk.

03 · REPORT

Written findings with concrete remediation steps, not vendor-speak.

04 · HANDOFF

Findings handed to your IT team or MSP for implementation, or scoped as a separate engagement.

WHAT'S INCLUDED — M365 & AZURE SECURITY ASSESSMENT

  • Tenant configuration review across identity, email, and collaboration
  • Azure subscription and resource posture review
  • MFA and conditional access policy review
  • Privileged role and admin account audit
  • Mailbox rule and forwarding configuration review
  • SharePoint and OneDrive external sharing review
  • Email security and anti-phishing configuration review
  • Legacy authentication and protocol exposure check
  • Audit logging and alerting readiness review
  • Written report with prioritized findings
  • 60-minute executive readout

ENGAGEMENT STRUCTURE

The Microsoft 365 & Azure Security Assessment is offered as a fixed-scope engagement starting at $5,000. Final pricing depends on tenant size, complexity, number of users, and Azure subscription scope. Identity-focused, posture, control-alignment, and detection-readiness assessments are scoped during the initial consultation. The practice is assessment-led; implementation is handed back to your IT or MSP, or scoped as a separate engagement.

MSP PARTNERSHIPS

White-label and co-engagement assessments are available for MSPs needing security support on Microsoft 365, Azure, and cloud identity.

FAQ

READY WHEN YOU ARE

Tell us what you need reviewed.