Sample assessment — fictional Contoso example. This illustrates the report format. These are not customer results, a certification or proof of live coverage. Start your own assessment.
MS
MS Cloud Support
Deliver Trust.
Public example · fictional tenant
Report ID · SAMPLE-CONTOSO-001
Fictional example
Microsoft 365 Security Posture Assessment

Contoso Ltd

Tenant contoso.onmicrosoft.com Data Illustrative data Licensing Intune, MDO Purpose Report demonstration · no tenant connected
47%
Secure Score
D+High risk

14 sample findings have critical or high severity — 3 critical, 11 high.

This fictional example puts identity findings first: multi-factor authentication, administrator access and legacy sign-in policies. The evidence and suggested next steps below illustrate how a report supports review. They do not describe your tenant or establish that any change is safe to apply without validation.

Fictional data, explained The 47% Microsoft Secure Score is an illustrative input, separate from this report's control counts. There is no peer benchmark or promised score improvement. Your results depend on collected evidence, permissions and licences.
Critical 3 High 11 Medium 15 Low 20 Passed 11 Not verified 14 Not assessed 27
14 of the 74 controls with illustrative evidence are not verified. The example contains 49 failing controls, 11 passing controls, 14 unverified controls and 27 not assessed: 101 in total. Unverified and unassessed results are not passes; they do not determine the separate illustrative Microsoft Secure Score.
At a glance

The numbers that matter

47%
Microsoft Secure Score
3
Critical findings
11
High findings
0
Tenant changes performed
74/101
Controls with illustrative evidence
Scope
Fictional M365 configuration · illustrates read-only application assessment
Method
101-control catalogue; evidence and framework references shown separately from Microsoft Secure Score
Not assessed
27 controls need higher SKUs (Entra P2 / Purview / Power Platform) not licensed on this tenant
Re-scan trend
No comparison in this example; real drift requires two attributable assessments
Executive summary

What this means for Contoso Ltd

This fictional example puts identity findings first: multi-factor authentication, administrator access and legacy sign-in policies. The evidence and suggested next steps below illustrate how a report supports review. They do not describe your tenant or establish that any change is safe to apply without validation.

Review the 14 critical and high findings first. Validate the evidence, licence prerequisites and business impact before planning work. Implementation needs separately agreed scope and approval, followed by verification. This example promises neither a target score nor a completion time.

Reference fields

How to read framework references

Control identifiers beneath the fictional findings illustrate reference fields for Microsoft Secure Score, CIS, CISA SCuBA and NIST. They are contextual references, not measured compliance percentages or a certified benchmark assessment. A real assessment must disclose its actual evidence and any unverified mappings.

Cyber-insurance readiness

Example insurance evidence questions

These 12 fictional answers illustrate the presentation: 1 yes, 8 no, 1 partial and 2 not assessed. They do not determine insurability or coverage. A real answer requires the relevant evidence and the insurer's own questions.

No Is multi-factor authentication (MFA) enforced for all users?
No Is MFA required for all administrative / privileged accounts?
No Is MFA required for remote and web/email access?
No Are legacy authentication protocols blocked?
No Do you have email filtering / anti-phishing protection?
No Are externally-originated emails visibly tagged?
No Is automatic external mail forwarding restricted?
Not assessed Do you enforce least-privilege / limited Global Admins?
Partial Is security audit logging enabled and retained?
Yes Are SPF, DKIM and DMARC published for your domains?
No Are external file-sharing controls in place?
Not assessed Do you have data loss prevention (DLP) policies?
Detailed findings

What needs action, and how to fix it

Below: all 49 failing controls, ordered by severity. Passing, unverified and not-assessed example controls follow.

Showing all 49 failing findings.

IAM-001 Require MFA for all users Critical Expert-assisted — not auto-applied
EvidenceNo CA policy requires MFA; 120 accounts can sign in with a password only.
FixCreate a Conditional Access policy requiring MFA for all users / all apps.
SCuBA MS.AAD.3.2v1Secure ScoreCIS 1.1.1NIST PR.AC-7
IAM-002 Block legacy authentication Critical Expert-assisted — not auto-applied
EvidenceNo Conditional Access policy blocks legacy authentication.
FixCreate a CA policy blocking legacy authentication protocols.
SCuBA MS.AAD.1.1v1Secure ScoreCIS 1.2.1NIST PR.AC-7
EXO-001 External mailbox auto-forwarding blocked Critical Expert-assisted — not auto-applied
Evidence1 mailbox(es) forward mail to an external address; the outbound spam policy permits it tenant-wide.
Affected‹CONTOSO_USER_09›
FixSet AutoForwardingMode to Off in the outbound anti-spam policy and remove forwarding rules.
SCuBA MS.EXO.1.1v2Secure ScoreCIS 4.2.1NIST PR.DS-5
IAM-003 MFA registered for all active users High Expert-assisted — not auto-applied
EvidenceStrong MFA registered for 82% of users — 22 accounts have no second factor.
FixDrive registration via the Authentication Methods policy + a registration campaign.
Secure ScoreNIST PR.AC-1
ADM-004 Admins require phishing-resistant MFA High Expert-assisted — not auto-applied
EvidenceNo Conditional Access policy requires phishing-resistant MFA for administrative roles.
FixCA policy scoping admin roles to phishing-resistant authentication strength.
SCuBA MS.AAD.3.6v1Secure ScoreCIS 1.1.2NIST PR.AC-7
APP-001 User consent to apps restricted High Expert-assisted — not auto-applied
EvidenceAny user may grant third-party OAuth apps access to organizational data.
FixRestrict user consent + enable the admin consent request workflow.
SCuBA MS.AAD.5.2v1Secure ScoreCIS 5.1.5NIST PR.AC-4
EXO-006 SMTP AUTH disabled tenant-wide High Expert-assisted — not auto-applied
EvidenceSMTP AUTH is enabled tenant-wide (legacy protocol that bypasses MFA).
FixDisable SMTP AUTH tenant-wide; enable per-mailbox only for legacy line-of-business needs.
SCuBA MS.EXO.5.1v1NIST PR.AC-7
DEF-001 Microsoft Secure Score baseline High Expert-assisted — not auto-applied
EvidenceMicrosoft Secure Score is 47% (282/600).
FixWork the top Secure Score improvement actions by impact.
Secure ScoreNIST ID.RA-1
DEF-002 Preset security policies (Standard or Strict) enabled High Expert-assisted — not auto-applied
EvidenceNo preset security policy (Standard/Strict) is enabled.
FixEnable the Standard (or Strict) preset security policy for all users.
SCuBA MS.DEFENDER.1.1v1NIST PR.IP-1
DEF-003 Safe Attachments enabled High Expert-assisted — not auto-applied
EvidenceSafe Attachments is not enabled.
FixEnable Safe Attachments (Block action) and Safe Docs for O365.
SCuBA MS.DEFENDER.3.1v1NIST DE.CM-4
DEF-004 Safe Links enabled High Expert-assisted — not auto-applied
EvidenceSafe Links is not enabled.
FixEnable Safe Links for email/Teams/Office with URL rewrite + click tracking.
NIST DE.CM-4
DEF-005 Anti-phishing impersonation protection configured High Expert-assisted — not auto-applied
EvidenceAnti-phishing impersonation/mailbox-intelligence protection is incomplete.
FixConfigure user/domain impersonation protection and mailbox intelligence in the anti-phish policy.
SCuBA MS.DEFENDER.2.1v1NIST DE.CM-4
SHR-001 External sharing not set to "Anyone" High Expert-assisted — not auto-applied
EvidenceOrganization sharing is set to 'Anyone' — anonymous links are permitted across all sites.
FixSet org sharing to 'New and existing guests' or stricter.
SCuBA MS.SHAREPOINT.1.1v1Secure ScoreCIS 7.2.xNIST PR.DS-5
ADM-011 Privileged users use finer-grained roles instead of Global Administrator High Expert-assisted — not auto-applied
Evidence7 Global Administrator(s) exceed the 2 member(s) in finer-grained roles — over-provisioned on GA.
FixReassign day-to-day admins from Global Administrator to least-privilege roles (User/Exchange/SharePoint/Security Administrator, etc.).
SCuBA MS.AAD.7.2v1NIST PR.AC-4
IAM-008 Phishing-resistant MFA available/enforced for all users Medium Expert-assisted — not auto-applied
EvidenceNo phishing-resistant authentication method is enabled.
FixEnable phishing-resistant methods; pilot an auth-strength CA policy before enforcing tenant-wide.
SCuBA MS.AAD.3.1v1Secure ScoreNIST PR.AC-7
IAM-009 SMS/Voice is not an allowed primary MFA method Medium Expert-assisted — not auto-applied
EvidenceSMS or Voice is still enabled as an MFA method.
FixDisable SMS/Voice as a primary method in the Authentication Methods policy after migrating users to Authenticator/FIDO2.
SCuBA MS.AAD.3.5v1NIST PR.AC-7
IAM-010 Microsoft Authenticator shows login context (number matching) Medium Expert-assisted — not auto-applied
EvidenceAuthenticator number matching is not enabled.
FixEnable number matching + app/geo context in the Authenticator method configuration.
SCuBA MS.AAD.3.3v2NIST PR.AC-7
IAM-013 Guest sign-ins require MFA Medium Expert-assisted — not auto-applied
EvidenceNo Conditional Access policy requires MFA for guest / external users.
FixAdd a CA policy requiring MFA for guest and external users.
NIST PR.AC-7
ADM-005 Privileged users are cloud-only accounts Medium Expert-assisted — not auto-applied
Evidence1 privileged account(s) are synced from on-premises, not cloud-only.
Affected‹CONTOSO_USER_03›
FixMove privileged assignments to dedicated cloud-only admin identities.
SCuBA MS.AAD.7.3v1NIST PR.AC-4
APP-003 Admin consent request workflow enabled Medium Expert-assisted — not auto-applied
EvidenceThe admin consent request workflow is disabled.
FixEnable the admin consent request workflow and assign reviewers.
SCuBA MS.AAD.5.3v1NIST PR.AC-4
APP-005 App registration restricted to admins Medium Expert-assisted — not auto-applied
EvidenceAny user can register applications.
FixDisable users' ability to register applications.
SCuBA MS.AAD.5.1v1CIS 5.1.2NIST PR.AC-4
APP-006 No stale or long-lived app credentials Medium Expert-assisted — not auto-applied
Evidence1 app credential(s) are expired-but-present or valid > 12 months.
Affected‹CONTOSO_USER_08›
FixRotate/remove stale secrets; move to certificate credentials with short lifetimes.
NIST PR.AC-1
EXO-005 DMARC policy enforced (p=reject) Medium Expert-assisted — not auto-applied
EvidenceDMARC is not at p=reject on 1 domain(s) — failures are reported, not blocked.
FixProgress DMARC p=none -> p=quarantine -> p=reject after monitoring aggregate reports.
SCuBA MS.EXO.4.2v1CIS 2.1.xNIST PR.DS-2
DEF-006 Common attachment / malware filter configured Medium Expert-assisted — not auto-applied
EvidenceThe common attachment types filter is not enabled.
FixEnable the common attachment types filter and malware ZAP.
NIST DE.CM-4
SHR-002 Guest access restrictions configured Medium Expert-assisted — not auto-applied
EvidenceGuest users inherit broad (member-equivalent) directory access.
FixSet guest user access to the most restrictive role.
SCuBA MS.AAD.8.1v1Secure ScoreCIS 1.xNIST PR.AC-4
TMS-001 External access (federation) restricted Medium Expert-assisted — not auto-applied
EvidenceTeams external federation is open to all domains.
FixRestrict federation to an allow-list of partner domains.
SCuBA MS.TEAMS.2.1v2NIST PR.AC-3
TMS-005 Third-party and custom app usage governed Medium Expert-assisted — not auto-applied
EvidenceThird-party and custom Teams apps are globally allowed by default.
FixRestrict third-party and custom app permission policies.
SCuBA MS.TEAMS.5.2v2NIST PR.IP-1
DEV-002 Conditional Access requires a compliant / hybrid-joined device Medium Expert-assisted — not auto-applied
EvidenceNo Conditional Access policy requires a compliant or hybrid-joined device.
FixAdd a device-based Conditional Access grant control.
SCuBA MS.AAD.3.7v1NIST PR.AC-3
DEF-008 Security alerts routed to a monitored address / SIEM Medium Expert-assisted — not auto-applied
EvidenceSecurity alerts are not routed to a monitored address or SIEM.
FixSet alert notification recipients and/or forward to the SIEM.
SCuBA MS.DEFENDER.5.2v1NIST DE.CM-1
IAM-011 Migrated off legacy per-user MFA to the Authentication Methods policy Low Expert-assisted — not auto-applied
EvidenceStill managing MFA via the legacy per-user portal (migration incomplete).
FixComplete the Authentication Methods policy migration.
SCuBA MS.AAD.3.4v1NIST PR.AC-7
IAM-012 Cloud account password expiration disabled Low Expert-assisted — not auto-applied
Evidence1 domain(s) still expire passwords (NIST advises never-expire + MFA).
FixSet password policy to never expire for cloud accounts (pair with MFA + risk-based detection).
SCuBA MS.AAD.6.1v1Secure ScoreNIST PR.AC-1
IAM-014 Self-service password reset with strong verification Low Expert-assisted — not auto-applied
EvidenceSSPR is enabled but weak (security questions on, or <2 strong methods).
FixEnable SSPR with two strong methods; disable security questions.
Secure ScoreNIST PR.AC-1
IAM-015 Device registration/join requires MFA Low Expert-assisted — not auto-applied
EvidenceDevice join/registration does not require MFA.
FixRequire MFA to join or register devices.
NIST PR.AC-7
EXO-008 External sender identification enabled Low Expert-assisted — not auto-applied
EvidenceExternal-sender identification (the [External] tag) is not enabled.
FixEnable native external sender identification.
SCuBA MS.EXO.7.1v1NIST PR.AT-1
EXO-010 Additional storage providers disabled in Outlook on the web Low Expert-assisted — not auto-applied
EvidenceThird-party storage providers (Box/Dropbox/…) are available in OWA.
FixDisable additional storage providers in the OWA mailbox policy.
NIST PR.DS-5
TMS-002 Contact with unmanaged / Skype consumer users blocked Low Expert-assisted — not auto-applied
EvidenceContact with Teams consumer / unmanaged accounts is allowed.
FixDisable federation with consumer/unmanaged accounts.
SCuBA MS.TEAMS.2.2v2NIST PR.AC-3
TMS-004 Meeting lobby admits authenticated users only Low Expert-assisted — not auto-applied
EvidenceThe meeting lobby auto-admits everyone (external/anonymous included).
FixSet the lobby to admit organization/trusted users automatically only.
SCuBA MS.TEAMS.1.3v1NIST PR.AC-3
TMS-006 Teams email integration disabled Low Expert-assisted — not auto-applied
EvidenceEmail-into-channel is enabled.
FixDisable email-into-channel.
SCuBA MS.TEAMS.4.1v1NIST PR.DS-5
LOG-003 Audit log retention adequate Low Expert-assisted — not auto-applied
EvidenceAudit log retention is only 90 days (< 1 year).
FixCreate an audit-log retention policy for the required window.
SCuBA MS.DEFENDER.6.3v1NIST PR.PT-1
DEV-004 Mobile app protection (MAM) policies configured Low Expert-assisted — not auto-applied
EvidenceNo mobile app protection (MAM) policies exist.
FixCreate MAM app protection policies for mobile platforms.
NIST PR.DS-5
EXO-011 Contact folders not shared with all domains Low Expert-assisted — not auto-applied
EvidenceA sharing policy shares contact folders with all domains.
FixRestrict contact-folder sharing to specific domains.
SCuBA MS.EXO.6.1v1NIST PR.DS-5
EXO-012 Calendar details not shared with all domains Low Expert-assisted — not auto-applied
EvidenceA sharing policy shares calendar details with all domains.
FixRestrict calendar sharing to specific domains / free-busy only.
SCuBA MS.EXO.6.2v1NIST PR.DS-5
SHR-012 Guest invitations restricted to inviters Low Expert-assisted — not auto-applied
EvidenceAny user can invite guests (allowInvitesFrom=everyone).
FixSet guest-invite permission to admins and Guest Inviter role holders.
SCuBA MS.AAD.8.2v1NIST PR.AC-4
TMS-007 External participants cannot request control of shared desktop Low Expert-assisted — not auto-applied
EvidenceExternal participants can request control of a shared desktop.
FixDisable external participant give/request control.
SCuBA MS.TEAMS.1.1v1NIST PR.AC-3
TMS-008 Internal users cannot initiate contact with unmanaged users Low Expert-assisted — not auto-applied
EvidenceInternal users can start chats with unmanaged users.
FixDisable internal-to-unmanaged outbound contact.
SCuBA MS.TEAMS.2.3v2NIST PR.AC-3
TMS-009 Only agency-approved Microsoft apps installable Low Expert-assisted — not auto-applied
EvidenceAll Microsoft Teams apps are installable by default.
FixRestrict the Microsoft-app permission policy to approved apps.
SCuBA MS.TEAMS.5.1v2NIST PR.IP-1
TMS-010 Meeting recording restricted Low Expert-assisted — not auto-applied
EvidenceMeeting cloud recording is enabled.
FixDisable or scope cloud recording in the meeting policy.
SCuBA MS.TEAMS.1.6v1NIST PR.DS-5
TMS-011 Dial-in (PSTN) users cannot bypass the meeting lobby Low Expert-assisted — not auto-applied
EvidenceDial-in (PSTN) users can bypass the meeting lobby.
FixSet AllowPSTNUsersToBypassLobby to false in the meeting policy.
SCuBA MS.TEAMS.1.5v1NIST PR.AC-3
TMS-012 Live events are not forced to always record Low Expert-assisted — not auto-applied
EvidenceLive events are forced to always record (BroadcastRecordingMode=AlwaysEnabled).
FixChange the live-event broadcast recording mode away from Always record (use organizer choice).
SCuBA MS.TEAMS.1.7v2NIST PR.DS-5
Controls that passed — 11
IAM-004Security Defaults OR Conditional Access in forcePassed
EXO-002SPF record publishedPassed
EXO-003DKIM signing enabled for all domainsPassed
EXO-004DMARC record publishedPassed
LOG-001Unified audit log enabledPassed
EXO-007Mailbox auditing enabledPassed
EXO-009Connector/IP allow-list not used to bypass filteringPassed
DEF-007Security alerts enabledPassed
DEV-001Intune compliance policies existPassed
DEV-003Disk encryption (BitLocker/FileVault) enforcedPassed
TMS-003Anonymous users cannot start meetingsPassed
Not verified — mapping pending reconciliation (14)

These controls were evaluated, but their framework mapping / check is not yet reconciled against the pinned baseline, so their result is shown as Not verified rather than a pass or fail, and is not counted in the headline grade. They are verified during the live calibration pass.

ADM-001Global Administrator count right-sizedNot verified
BasisdirectoryRole members; ScubaGear v1.8.0 MS.AAD.7.1 (fetched)
ADM-002Break-glass emergency account exists and is CA-excludedNot verified
BasisBreak-glass is an operational concept, not a Graph property
SHR-009OneDrive external sharing limitedNot verified
BasisGraph v1.0 sharepointSettings (fetched); MS.SHAREPOINT.1.2v1
SHR-003"Anyone" link expiration and permission limitedNot verified
BasisGraph v1.0 sharepointSettings (fetched); MS.SHAREPOINT.3.1v1
SHR-006SharePoint custom scripts disabledNot verified
BasisGraph v1.0 sharepointSettings (fetched)
LOG-002Sign-in and audit logs exported to durable storage / SIEMNot verified
BasisAzure Monitor diagnostic settings (Lighthouse), not a tenant M365 Graph read; MS.AAD.4.1v1
IAM-016Device code authentication flow blockedNot verified
BasisCA conditions.authenticationFlows.transferMethods (deviceCodeFlow); MS.AAD.3.9v1
APP-004Group owner consent restrictedNot verified
BasisGraph v1.0 authorizationPolicy (fetched)
SHR-004Default sharing link scope is specific peopleNot verified
BasisGraph v1.0 sharepointSettings (fetched); MS.SHAREPOINT.2.1v1
SHR-005Reauthentication required for external usersNot verified
BasisGraph v1.0 sharepointSettings (fetched); MS.SHAREPOINT.3.3v2
APP-007Application password (secret) credential addition blockedNot verified
BasisGraph BETA appManagementPolicy / defaultAppManagementPolicy (not re-fetched); MS.AAD.5.5v1
SHR-010Default file/folder sharing permission is view-onlyNot verified
BasisGraph v1.0 sharepointSettings (fetched); MS.SHAREPOINT.2.2v1
SHR-011"Anyone" link permission is view-onlyNot verified
BasisGraph v1.0 sharepointSettings (fetched); MS.SHAREPOINT.3.2v1
APP-002No over-privileged / illicit OAuth grantsNot verified
BasisGraph v1.0 oauth2PermissionGrants + servicePrincipals (not re-fetched)
Not assessed on this tenant — licensing / no data (27)
IAM-007High-risk users are blocked or remediatedNot assessedrequires EntraP2, not licensed on this tenant
IAM-005Sign-in risk policy enabledNot assessedrequires EntraP2, not licensed on this tenant
IAM-006User risk policy enabledNot assessedrequires EntraP2, not licensed on this tenant
ADM-003Privileged roles are PIM-eligible, not permanently activeNot assessedrequires EntraP2, not licensed on this tenant
ADM-006Privileged role activation requires approvalNot assessedrequires EntraP2, not licensed on this tenant
ADM-007Privileged role activation/assignment alertingNot assessedrequires EntraP2, not licensed on this tenant
PWR-001Environment creation restricted to adminsNot assessedrequires PowerPlatform, not licensed on this tenant
PWR-003DLP policy on the default environmentNot assessedrequires PowerPlatform, not licensed on this tenant
PWR-004Power Platform tenant isolation enabledNot assessedrequires PowerPlatform, not licensed on this tenant
DLP-001DLP policies protect sensitive informationNot assessedrequires Purview, not licensed on this tenant
ADM-009Privileged role provisioning restricted to PIM/PAMNot assessedrequires EntraP2, not licensed on this tenant
PWR-005Non-default environments covered by a DLP policyNot assessedrequires PowerPlatform, not licensed on this tenant
DLP-004Custom DLP policy scoped to Exchange, OneDrive, SharePoint, Teams, and DevicesNot assessedrequires Purview, not licensed on this tenant
DLP-005DLP policy blocks sharing sensitive information with everyoneNot assessedrequires Purview, not licensed on this tenant
PWR-007Content Security Policy enforced for Power AppsNot assessedrequires PowerPlatform, not licensed on this tenant
PWR-009Share with Everyone disabled in Power AppsNot assessedrequires PowerPlatform, not licensed on this tenant
ADM-008Access reviews for privileged roles and guestsNot assessedrequires EntraP2, not licensed on this tenant
PWR-002Trial environment creation restrictedNot assessedrequires PowerPlatform, not licensed on this tenant
DLP-002Sensitivity labels publishedNot assessedrequires Purview, not licensed on this tenant
DLP-003Retention policy configuredNot assessedrequires Purview, not licensed on this tenant
IAM-017Admin notification on high-risk usersNot assessedrequires EntraP2, not licensed on this tenant
ADM-010Alert on Global Administrator activationNot assessedrequires EntraP2, not licensed on this tenant
PWR-006Power Platform connection allow-list configuredNot assessedrequires PowerPlatform, not licensed on this tenant
DLP-006DLP policy notifies and educates usersNot assessedrequires Purview, not licensed on this tenant
DLP-007Restricted-apps list defined for endpoint DLPNot assessedrequires Purview, not licensed on this tenant
DLP-008Endpoint DLP blocks restricted apps and unwanted Bluetooth transfersNot assessedrequires Purview, not licensed on this tenant
PWR-008Power Pages site creation restricted to adminsNot assessedrequires PowerPlatform, not licensed on this tenant
What happens next

From evidence to an agreed next step

Your tenant

Start your assessment

Sign in with Microsoft and review the read-only application consent. This public fixture has not connected or scanned a tenant.

Human review

Talk to an engineer

Discuss findings and priorities. We confirm the scope and access needed before proposing managed work.

Managed service

Review managed plans

Changes require agreed scope, appropriate access, approval and verification. This demonstration cannot apply changes or activate service.