Independent Microsoft 365 review

The only people assessing your Microsoft 365 are the people who built it.

Separation of duties is standard everywhere else: the party that configures an environment is not the party that assesses it. We assess yours from the outside, and tell you which findings actually deserve your week.

Scroll to open the file
NC-AUDIT / 2026 · the review, from first question to finished report Skip the film ↓
01 · 07 · The review, in seven scenes

Control requires evidence.

Are you in control of your Microsoft 365 environment? Could you prove it? Microsoft 365 does not live in one place. Each admin portal shows one part of the story, and risk does not respect product boundaries.

  • Entra
  • Intune
  • Defender
  • Exchange
  • SharePoint
  • Teams

Every source, brought together into one overview.

Your review

You get the reports. Your team reads them and acts on them, at your own pace.

Read-only Graph access · daily refresh · your tempo
Our review

We walk you through the findings: what they mean, and what to put right first.

The same reports · a specialist alongside · a prioritised plan
What happens next

From first question to a plan you can act on.

An independent review touches your tenant, so it should be obvious what you are agreeing to. Five steps, what each one costs you, and how little of it is waiting. Consent in the morning, your first report the same afternoon.

  1. 0130–60 min

    Plan a review

    You bringThirty minutes to an hour, and the questions you actually want answered.

    You getA demo on those questions, and a decision on the route: you read the reports yourself, or a specialist reads them with you. A short scoping conversation settles the rest before anything is granted.

  2. 02same morning

    Grant read-only consent

    You bringOne administrator grants read-only consent on the app registration. No agents, no changes to your configuration.

    You getOnboarding starts straight away, in an environment created for your tenant and nothing else. No shared database, no pooled index, no other customer sitting next to you.

  3. 03same afternoon

    The first report is there

    You bringNothing. This part is on us.

    You getEvery Microsoft 365 domain in one view, hours after consent rather than weeks, with the findings ranked instead of listed.

  4. 04your route

    Read it, or read it together

    You bringYour own time, or an hour with the people who can act on it.

    You getOn your own: the reports are yours to work through at your pace. With us: a specialist talks you through what the findings mean, what to put right first, and hands over a prioritised action list.

  5. 05every day after

    It keeps up with you

    You bringNothing again.

    You getThe report refreshes daily, so you see what moved, what was fixed, and what is new, not a snapshot that ages.

The long version, step by step

Why we started

We had all seen the same blind spot.

We are Microsoft 365 consultants. Between us we have built, migrated, secured and run these environments from the inside, in enterprises and at managed service providers, across very different sizes and industries. Each one began as a functional need that somebody had to translate into Microsoft 365. That translation is most of the job, and it is where environments drift from what anyone intended.

What none of us ever saw was someone allowed to look at the whole of it from the outside. Not out of ill will. There is more Microsoft 365 to run than ever, and it changes every month. Identity is one engineer, endpoints another, collaboration a third, each right about their own piece. The admin portals follow that split; the environment does not. So the work gets done, and nobody reads the whole of it.

Doing that read by hand takes weeks, and it is the same questions every time. Which accounts bypass MFA. Which links are still open. Whose owner left. So we built the platform that answers them, and kept the part that needs a person: what it means, what deserves your week, and who needs to be in the room.

A report is the easy part. The value is a specialist who has seen the pattern before, telling you which three of forty findings actually matter.

Whether you run Microsoft 365 yourself or have handed it over, a review here is never only a document. Every one comes with a conversation, and it starts with what a single account actually looks like.

What we assess

One account, read across everything it touches.

Which teams is she in? What can she reach in SharePoint, and in tenants that are not yours? Which devices are hers, and are they compliant? Which groups, which roles, which licences? Microsoft 365 answers each of those somewhere. It answers none of them together.

One account

Start with a single user.

Nothing stands out about her. She works in finance, she has been here four years, and every admin centre you open says she is fine. Read them one at a time and they are right.

Entra

Who she is, and what she may do.

Entra shows the account, the roles attached to it, and whether multi-factor authentication applies. It applies. It also shows that this account sits in the group excluded from it, and that it carries a directory admin role.

Intune

What she works on.

Two devices reach company data. The laptop is compliant and encrypted. The phone last checked in forty days ago, and nothing has asked about it since.

Read with Entra: an unmanaged phone, on an account that never has to answer for a second factor.

Defender

Whether something already happened.

Defender holds a password-spray campaign against this account. Two alerts, both triaged, neither closed. They have been open for three weeks.

This is where the exclusion stops being paperwork. Someone is trying passwords on the one account that does not have to answer for a second factor, so the finding above just changed colour.

Exchange

Where her mail can go.

A forwarding rule sends a copy of everything to an address outside the tenant. It was created eleven months ago, by someone who no longer works here.

A way out that predates every alert above it, on an account somebody may already be able to reach.

SharePoint

What she has shared, and what she can reach.

Nine documents sit behind anonymous links, four of them older than a year and still opening without a sign-in. Her effective access runs well past her own department: inherited permissions reach three site collections nobody would have named for her.

Effective access, not assigned access. Nobody granted this on purpose; it accumulated, one inheritance at a time.

Teams

Where she is left in charge.

She owns three teams, one of them without a second owner. Two include guests from outside the tenant, and through those teams she reaches files that have nothing to do with finance.

Now put the admin role from the first source back on top. The blast radius of this one account is not the finance department, and the forwarding rule now leads out of all of it.

Licensing

What she costs.

Two licences are assigned to this account and their entitlements almost entirely overlap. One of them has not been touched in five months.

Not a security finding, and the one your finance director asks about first. The same single pass that found the exclusion found this.

One view

Every answer, in one place.

Each of these is defensible on its own, and each lives in a different admin centre with a different owner. Read in order they escalate each other: the exclusion became urgent when the spray appeared, the forwarding rule became urgent once the reach was known. Two findings changed priority while you scrolled, and nothing about them changed, only what we knew alongside them.

j.dekker@contoso.com Microsoft 365 independent oversight
Illustrative example data One account 0 of 7 sources

What one account looks like when every admin portal is read together instead of one at a time.

0 Open findings across every source read
0 Ways in access that should not be there
0 Ways out data that can leave unseen
0 Unwatched nobody following up
Findings by source read-only · configuration and metadata
  1. Entra Identity Admin role, MFA enforced but the account sits in the exclusion group attention
  2. Intune Devices Laptop compliant, phone not seen for 40 days attention
  3. Defender Detection Password spray, two alerts open for 21 days attention
  4. Exchange Mail Forwarding rule to an external domain open
  5. SharePoint Files Nine anonymous links, and inherited access to three unexpected sites open
  6. Teams Collaboration Owns three teams, one without a second owner, two with external guests attention
  7. Licensing Cost Two overlapping licences, one unused for five months open
Read together

An admin account that can skip MFA, under active attack, forwarding a copy of everything out of the building. This is the one you fix on Monday.

Across all of them

Microsoft Secure Score

Taken as a reference point, not as the verdict, with our own judgement on which recommendations actually deserve your time.

Licensing

Licences assigned but barely used, and licences heavier than the role calls for.

Applications

Enterprise and OAuth applications holding far-reaching permissions, or holding them with nobody responsible.

Configuration and metadata. Never content.

We read how things are set up, who can reach what, and when something happened. We never read the body of a message or the contents of a document. And that is not only a promise we make: we request the narrowest Microsoft Graph scopes that answer these questions, an administrator sees the full list on the consent screen before approving it, and it can be withdrawn in one click.

After the review

And if you would rather not work through it yourself.

Every review conversation ends with a prioritised list. Putting that list into practice is separate work. We can take it on, by the same specialists who read the report with you. It is arranged per engagement rather than folded into a subscription, so the review stays independent of who does the fixing.

That is worth more than it sounds, because of where the reports come from. They are not software we resell. We built them ourselves, as Microsoft 365 specialists who spent years building, migrating, securing and running these environments from the inside, in enterprises and at managed service providers. The judgement that decides which three of forty findings matter, and the hands that put those three right, come from the same place.

So a review does not have to end with a list of things you now know about. One party reads the environment, tells you what genuinely deserves your week, does the work if you want it done, and the report the next morning shows that it moved. That is the whole of your Microsoft 365 environment accounted for, end to end, by people who can answer for both halves of it.

  1. We read it together
  2. We get the right people in the room
  3. We prioritise
  4. We put it right
  5. The next report shows it moved
This picks up exactly where the timeline above left off.
Talk it through

Want an independent view of Microsoft 365?

Plan a review conversation. We discuss your Microsoft 365 environment, the role of your operating partner and where independent assessment adds value.

Plan an independent review
One public inbox · info@nowcloud.nl