AegentraNew Zealand

Harden / New Zealand

Microsoft 365 security assessment

Aegentra reviews the agreed Microsoft 365 environment and turns configuration evidence into prioritised security actions. The assessment considers identity, email, information access and operational responsibilities for your New Zealand organisation.

On this page

Start with the boundary

Define the work that is needed.

For organisations needing a baseline, a prioritised uplift plan or evidence to support a security programme.

  • Tenant boundary, licences and administrative roles
  • Identity, authentication and access settings
  • Email and collaboration protection
  • Logging, recovery and ongoing ownership

Keep the responsibilities distinct

An assessment is not a penetration test or a guarantee that the environment is secure. Changes require separate approval, suitable access, impact planning and verification.

What the engagement can produce

Useful outputs, agreed in advance.

  • An evidence-led assessment of the agreed tenant scope
  • Findings with risk, context and practical priorities
  • Licence or configuration dependencies
  • An agreed action plan; implementation separately scoped

Service pricing is provided by scoped quote, not the Academy’s per-learner course prices. The proposal identifies deliverables, assumptions, exclusions, responsibilities and commercial terms. No fixed price or completion date is promised before the scope is understood.

How we work

From evidence to a practical next step.

Agree

Confirm the objective, authority, systems, criteria, access and exclusions. Establish how information will be shared and handled.

Examine

Gather the records and context required by the scope. Distinguish what evidence supports from what is still uncertain.

Act or report

Carry out the agreed consulting, audit, assessment or implementation task. Obtain approval before operational changes.

Verify and hand over

Document outcomes, limitations, owners and follow-up. Retesting or ongoing work is included only when expressly scoped.

We deliver online and arrange visits by appointment where agreed. Scope, assigned competence, timing, access requirements and any travel are confirmed before an engagement.

An illustrative starting point

What a useful first decision looks like.

Fictional example to explain the service, not a New Zealand client case study or a promised outcome.

A tenant has many security features available, but some are unconfigured and others are covered by overlapping policies. The review should explain the effective outcome, not merely count enabled switches.

Questions for the first discussion

  • Which tenant, users and services are in scope?
  • Which licences and integrations are currently used?
  • Is the request an assessment, implementation or both?

Before you begin

Your questions, answered.

Will you change settings during the assessment?

Not without an agreed implementation scope and approval. We first establish the evidence and recommendations. Changes that can affect access, mail delivery or collaboration need an owner, a safe rollout and a recovery plan.

What can be included in microsoft 365 security assessment?

The agreed scope can include tenant boundary, licences and administrative roles; identity, authentication and access settings; email and collaboration protection; logging, recovery and ongoing ownership. We confirm the exact deliverables and exclusions before work begins, rather than treating every organisation as the same project.

How much does this service cost?

Service pricing is provided by scoped quote, not the Academy’s per-learner course prices. The proposal identifies deliverables, assumptions, exclusions, responsibilities and commercial terms. No fixed price or completion date is promised before the scope is understood.

How do you deliver the work in New Zealand?

We deliver online and arrange visits by appointment where agreed. Scope, assigned competence, timing, access requirements and any travel are confirmed before an engagement.

What should we provide before a proposal?

Bring answers to these starting questions: Which tenant, users and services are in scope? Which licences and integrations are currently used? Is the request an assessment, implementation or both? A short initial discussion should establish the boundary and next evidence needed. Do not email secrets or detailed personal records before secure handling has been agreed.

Reference points

Check the underlying guidance.

Page prepared and source references checked . References explain the relevant standard or technology; they are not endorsements of Aegentra.

Discuss your requirement

Start with your business.

Start with the requirement, the systems involved and the outcome you need. Please do not send passwords, sensitive records or unrestricted tenant access in an initial enquiry.