Skip to content
Independent IT security review - Canada Français
Secure M365 Scope a review
Contents

Independent IT security review

Check what actually stops a convincing phishing email.

Email remains the most common path into a tenant. The review reads anti-phishing, authentication, and mail flow settings together instead of trusting default protection alone.

Read anti-phishing and impersonation policy together.

Default protection is a starting point, not a finished configuration. The review checks what is actually enforced for the organization’s specific domains and executives.

Impersonation protection

Confirm whether key executives and the organization’s own domain are protected against look-alike display-name and domain attacks.

Spoof intelligence

Review how spoofed senders are handled and whether legitimate third-party senders are documented rather than blanket-allowed.

Policy scope

Confirm anti-phishing policies actually apply to the intended recipients, not only a default tenant-wide policy left unmodified.

Verify domain authentication is complete, not partial.

SPF, DKIM, and DMARC only work as a system. A gap in any one weakens the others and can leave spoofed mail simply unflagged.

SPF and DKIM

Confirm records are published correctly for every sending source the organization actually uses, including third-party services.

DMARC policy

Check whether DMARC exists only in monitoring mode or is actually enforcing rejection or quarantine as intended.

Third-party senders

Inventory marketing, invoicing, and other services sending as the organization’s domain, since an overlooked one breaks alignment.

Confirm attachment and link protections match real usage.

Safe Attachments and Safe Links, where licensed, only help if their scope and exceptions match how the organization actually works.

Coverage scope

Confirm which mailboxes and applications (mail, Teams, SharePoint) are actually covered where these protections are licensed.

Exceptions

Review trusted sender and URL exceptions for ones that quietly reopen the exact path the policy was meant to close.

Licence dependency

Document plainly when a protection depends on a licence tier the organization may not currently hold.

Decide who owns a reported or quarantined message.

A detection with no owner does not protect anyone. The review checks the human process behind the technical controls.

Reporting path

Confirm how employees report suspicious mail and whether that path is actually monitored.

Quarantine ownership

Identify who releases or confirms quarantined messages, and how false positives are handled without normalizing risky releases.

Incident boundary

Distinguish this review from active incident response; a confirmed compromise needs containment, not a configuration review.

Next step

Define the review before sharing evidence.

Start with the trigger, decision, and known boundaries. Do not send passwords, recovery codes, or tenant exports.