Accounts and email
Microsoft 365 and account security
A compromised work account can lead to fraud, data leaks and disruption. We review your Microsoft 365 settings: who holds admin rights, whether sign-in is protected, what is shared externally and what is logged. Then we agree and carry out the improvements.
Scope and price are confirmed in writing before work starts.
Discuss your caseWhen you need this service
- You use Microsoft 365 and have not reviewed its security settings.
- You do not know how many people hold admin rights.
- You had a compromised account, a fraudulent email or suspicious mail forwarding.
The benefit for your organisation
- It becomes harder to take over a work account and send fraudulent emails in your name.
- You know who holds admin rights and what is shared externally.
- We plan the changes in stages to limit disruption.
Microsoft 365 review
Admin rights, multi-factor sign-in and access policies, legacy sign-in methods, external sharing and guests, mail forwarding rules, phishing protection and activity logging.
from €1 900up to 100 users · 1–2 weeks
Agreed improvements
We carry out the selected changes in stages, with verification and a way back, to limit disruption.
by quotationdepending on the changes chosen
Sample output
Illustration with fictional data — not a real client.
| Setting | Found | Risk | Proposed change |
|---|---|---|---|
| Global administrators | 7 accounts, 2 without multi-factor sign-in | high | Fewer day-to-day admin rights; at least two separate, strongly protected emergency access accounts |
| External mail forwarding | Allowed for everyone | high | Blocked with approved exceptions |
| External sharing | Anonymous links with no expiry | medium | Sign-in links only, with expiry |
Why it matters
- NIS2 (EU cybersecurity directive) requires access control and multi-factor authentication where appropriate (Art. 21(2)(i) and (j)).
- A compromised admin account or automatic mail forwarding is how many payment frauds and data leaks happen.
- Default settings often do not match how the organisation actually works.
What you receive
- Findings ranked by risk, with the specific setting and why it matters.
- A change plan: what, in which order, with what impact on people and how it is verified.
- After implementation: a verification record for each change.
Base scope and what you provide
- One Microsoft 365 tenant, up to 100 users.
- Read-only access for the review (for example a global reader role); rights for changes are granted separately for implementation.
- Google Workspace and other email services are quoted separately.
- One presentation meeting and one round of corrections to the plan.
Mail delivery problems or domain impersonation? See the email and domain review.
Boundaries
- We do not guarantee accounts will not be attacked; we reduce the risks found.
- Microsoft licences are not included.
General information, not a legal opinion.