Skip to content
Independent IT security review - Canada Français
Secure M365 Scope a review
Contents

Independent IT security review

Confirm what Defender for Business is actually protecting.

Licensing Defender for Business is not the same as having every device onboarded, policy enforced, and alerts triaged. The review separates what is configured from what is only available.

Start from onboarding coverage, not licence coverage.

A licence count does not describe which devices actually report to Defender for Business. The review compares the licensed population against devices that are onboarded and actively reporting.

Device population

Separate managed Windows and macOS endpoints from unmanaged, personal, or unenrolled devices that may sit outside onboarding.

Sensor health

Confirm the onboarding profile is actually delivered, not only assigned, and that sensors report recent activity rather than a stale check-in.

Coverage gaps

Identify servers, kiosk devices, or contractor equipment that licensing and deployment processes commonly miss.

Read protection policy as layered controls.

Attack surface reduction, next-generation protection, and firewall settings can each be enabled, running in audit mode, or silently absent. The review reads the applied state, not the template name.

Attack surface reduction

Confirm whether rules run in block mode or audit-only, and which exclusions weaken them.

Next-generation protection

Check real-time protection, cloud-delivered protection, and sample submission settings against the organization’s risk tolerance.

Policy targeting

Trace which device groups a policy actually reaches, including exclusions inherited from other tools.

Decide who owns an alert before one arrives.

Defender for Business can generate alerts and automated investigations without a defined human response. The review checks whether that responsibility is assigned, not only whether alerting is switched on.

Alert routing

Confirm where alerts and automated investigation results are actually reviewed, and by whom.

Response boundary

Distinguish an endpoint protection review from managed detection and response or 24/7 monitoring, which are separate services.

Escalation path

Document what happens when an automated action needs a human decision, such as an isolated device or a blocked file.

Match findings to what the licence allows.

Defender for Business is scoped for small and medium organizations; some controls assumed from larger Defender for Endpoint plans are not present. Recommendations are checked against the actual subscription.

Licence boundary

Confirm which capabilities are included in the current subscription before recommending a change that depends on a higher plan.

Compensating context

Where a control is unavailable, document the gap plainly rather than implying it is already covered.

Sequencing

Connect onboarding, policy, and response findings to a remediation order instead of a single combined score.

Next step

Define the review before sharing evidence.

Start with the trigger, decision, and known boundaries. Do not send passwords, recovery codes, or tenant exports.