Skip to content
Independent IT security review - Canada Français
Secure M365 Scope a review
Contents

Independent IT security review

Know which licence a recommendation actually depends on.

A security recommendation that assumes the wrong licence is not useful advice. The review reads current subscriptions before connecting a finding to a specific control.

Read the subscription before the recommendation.

Microsoft 365 plans bundle identity, device, and information-protection capabilities differently. The review starts from what is actually licensed, not a generic best-practice list.

Plan inventory

Identify which combination of Business Premium, E3, E5, Entra ID, and Defender add-ons the organization currently holds.

Per-user variation

Check whether every user actually holds the licence a policy assumes, since mixed licensing is common after growth or acquisitions.

Trial and add-on drift

Confirm whether a capability depends on a trial, a promotional add-on, or a licence that may lapse.

Map common controls to their licence dependency.

Capabilities referenced elsewhere on this site-Conditional Access, compliance policy, Defender protection, and data retention-depend on specific licence tiers.

Identity controls

Confirm which Conditional Access, risk-based policy, and privileged identity features require Entra ID P1 or P2.

Device and endpoint controls

Check which Intune and Defender for Business or Defender for Endpoint capabilities the current plan actually includes.

Information protection

Identify whether sensitivity labels, data loss prevention, and extended retention require an add-on beyond the base plan.

Decide between upgrading and a compensating control.

A missing capability does not always require an upgrade. The review documents the trade-off so the organization decides deliberately.

Upgrade justification

State the specific risk or requirement an upgrade would address, not licensing for its own sake.

Compensating measures

Where an upgrade is not chosen, document what interim control or process reduces the gap.

Review trigger

Set a condition-growth, a new regulatory requirement, or an incident-that should prompt revisiting the decision.

Keep findings honest about what is actually available.

A finding that recommends an unlicensed feature without saying so creates false confidence. The review states licence dependency plainly next to every relevant recommendation.

Explicit dependency

Attach the required licence tier directly to any recommendation that depends on one.

No assumed upgrade

Avoid treating a licence change as already decided; it remains the organization’s commercial decision.

Traceable rationale

Keep the mapping between finding, licence requirement, and decision available for the next reviewer or renewal cycle.

Next step

Define the review before sharing evidence.

Start with the trigger, decision, and known boundaries. Do not send passwords, recovery codes, or tenant exports.