Accounts and email

Microsoft 365 and account security

A compromised work account can lead to fraud, data leaks and disruption. We review your Microsoft 365 settings: who holds admin rights, whether sign-in is protected, what is shared externally and what is logged. Then we agree and carry out the improvements.

Scope and price are confirmed in writing before work starts.

Discuss your case

When you need this service

  • You use Microsoft 365 and have not reviewed its security settings.
  • You do not know how many people hold admin rights.
  • You had a compromised account, a fraudulent email or suspicious mail forwarding.

The benefit for your organisation

  • It becomes harder to take over a work account and send fraudulent emails in your name.
  • You know who holds admin rights and what is shared externally.
  • We plan the changes in stages to limit disruption.

Microsoft 365 review

Admin rights, multi-factor sign-in and access policies, legacy sign-in methods, external sharing and guests, mail forwarding rules, phishing protection and activity logging.

from €1 900up to 100 users · 1–2 weeks

Agreed improvements

We carry out the selected changes in stages, with verification and a way back, to limit disruption.

by quotationdepending on the changes chosen

Sample output

Illustration with fictional data — not a real client.

SettingFoundRiskProposed change
Global administrators7 accounts, 2 without multi-factor sign-inhighFewer day-to-day admin rights; at least two separate, strongly protected emergency access accounts
External mail forwardingAllowed for everyonehighBlocked with approved exceptions
External sharingAnonymous links with no expirymediumSign-in links only, with expiry

More sample outputs →

We can implement them too. The Microsoft 365 changes can be carried out by your team with our guidance, by Dyasol or by a suitable partner. Implementation is quoted separately. Security improvements.

Why it matters

  • NIS2 (EU cybersecurity directive) requires access control and multi-factor authentication where appropriate (Art. 21(2)(i) and (j)).
  • A compromised admin account or automatic mail forwarding is how many payment frauds and data leaks happen.
  • Default settings often do not match how the organisation actually works.

What you receive

  • Findings ranked by risk, with the specific setting and why it matters.
  • A change plan: what, in which order, with what impact on people and how it is verified.
  • After implementation: a verification record for each change.
Base scope and what you provide
  • One Microsoft 365 tenant, up to 100 users.
  • Read-only access for the review (for example a global reader role); rights for changes are granted separately for implementation.
  • Google Workspace and other email services are quoted separately.
  • One presentation meeting and one round of corrections to the plan.

Mail delivery problems or domain impersonation? See the email and domain review.

Boundaries

  • We do not guarantee accounts will not be attacked; we reduce the risks found.
  • Microsoft licences are not included.

General information, not a legal opinion.

Discuss your case