Skip to content
Independent IT security review - Canada Français
Secure M365 Scope a review
Contents

Initial scoping

Start with the decision that needs evidence.

Share only the non-sensitive context needed to determine whether a point-in-time review fits.

Email the review context directly.

Include the trigger, areas to examine, and decision to support. Do not attach evidence yet.

contact@securem365.ca

What to bring

Four details are enough to begin.

Nothing polished is required here - a few plain sentences are enough for a first look.

  1. The change, concern, or deadline that prompted the review.

  2. The users, workloads, or access paths that matter most.

  3. The decision and people who need to use the result.

  4. Known licensing, device, application, or timing constraints.

For example

“We’re onboarding a new HR platform before year-end and need to confirm which Conditional Access exclusions still apply before we grant it access.”

Do not attach evidence yet

Do not send passwords, recovery codes, tenant exports, customer names, or regulated information. The evidence method comes after authorization and written scope.

Define the review request

Describe the trigger, areas in question, and decision the review should support. A request starts preparation; it does not confirm scope, price, or timing.

Email the trigger, areas to examine, and decision to support. Keep evidence and sensitive information out of the initial message.

After contact

A request is not an engagement.

  1. Confirm whether the need fits.

  2. Name the reviewer and confirm relevant experience.

  3. Agree scope, exclusions, access, deliverables, and terms.

  4. Authorize the work in writing before evidence collection.

Related reading: the Mirage practice in Quebec.