Skip to content
Independent IT security review - Canada Français
Secure M365 Scope a review
Contents

Independent IT security review

A trusted network condition is only as honest as the network behind it.

Conditional Access can name a location or network as trusted, but that label is a promise made by the firewall, VPN, and Wi-Fi configuration-not by the policy itself. This review checks whether the promise still holds.

Start from the named locations, not the policy that references them.

A Conditional Access named location is a list of IP ranges someone entered at some point. The policy trusts that list completely; the review checks whether the list still matches reality.

Named location accuracy

Compare configured IP ranges against the organization’s actual current egress points, including any recently added office or provider.

Egress IP change monitoring

Confirm whether anyone is notified when an ISP-assigned public IP changes, since a stale entry can silently stop granting-or silently keep granting-trust.

VPN and office overlap

Check whether a VPN exit range is treated the same as an office network, and whether that equivalence still reflects who is allowed to use the VPN.

Test whether ‘trusted network’ still means what it did when configured.

A new ISP, an SD-WAN redesign, a branch office, or a shift to remote work can all change what actually sits behind a trusted range-without anyone touching the Conditional Access policy itself.

VPN tunneling behavior

Distinguish full-tunnel from split-tunnel VPN configurations, since split tunneling can let untrusted local traffic sit alongside a trusted session.

SD-WAN and multi-site egress

Confirm that every site’s actual internet breakout point is reflected in the trusted list, especially after a network redesign changes how branches reach the internet.

Wi-Fi segmentation

Verify that guest and corporate Wi-Fi are actually separated at the network layer, not only by a different SSID name.

Separate a compliant network from a compliant device.

‘Trusted network’ and ‘compliant device’ are two different signals that are sometimes treated as interchangeable. A policy that leans on network location alone can be satisfied by a personal device that happens to be on the right Wi-Fi.

Where policy leans on network alone

Identify Conditional Access policies that grant access based on network location without also requiring a managed or compliant device.

Guest Wi-Fi reaching trusted ranges

Confirm that a guest or visitor network cannot, through misconfiguration, share an IP range the tenant treats as trusted.

Firewall rule drift versus location drift

Compare firewall and routing changes against the named-location list on a cadence, since the two are maintained by different people on different schedules.

Decide what a network-trust finding changes.

A finding here can mean updating a named-location list, redesigning firewall or Wi-Fi segmentation, or deciding that a policy should stop relying on network signal at all.

Update versus redesign

Distinguish a quick correction to a stale IP list from a larger network-segmentation project that needs its own plan and owner.

Coordinating with the network provider

Recognize that firewall, VPN, and ISP changes belong to whoever manages that infrastructure; the review identifies the gap and hands off the network change itself.

Recheck cadence tied to network change

Set a trigger-a new office, a new ISP, an SD-WAN change-that should prompt revisiting the trusted-location list rather than waiting for a scheduled review.

Next step

Define the review before sharing evidence.

Start with the trigger, decision, and known boundaries. Do not send passwords, recovery codes, or tenant exports.