Week 1
Review Microsoft 365 Secure Score for a Client Tenant
Client Background
Pacific Trust Bank (1,200 employees, M365 E5 tenant) adopted Microsoft 365 two years ago and relies on it for Email, Teams, SharePoint, and endpoint security via Microsoft Defender. The bank's CISO wants an independent review of the tenant against Microsoft's own Secure Score recommendations ahead of a forthcoming FFIEC IT examination.
Business Environment
Pacific Trust runs a single M365 E5 tenant with Intune-managed endpoints for back-office staff and Conditional Access for ~200 remote users. The IT team manages security manually via the Defender portal but has never formalized a Secure Score improvement roadmap; the board now requires measurable security-baseline evidence for the upcoming regulator review.
Security Incident
No incident; the engagement is a preventive posture review. The trigger is a recent FFIEC IT examination letter requesting the bank evidence its M365 security configurations meet documented baselines, with an explicit reference to Microsoft Secure Score as an accepted benchmark.
Scope
Microsoft 365 Secure Score improvement-action backlog review covering Entra ID Conditional Access, Defender for Office 365, Defender for Endpoint, Teams and SharePoint external-sharing controls, and Power Platform/BI governance. Excludes cloud workload posture outside M365.
Objectives
- Full objectives coming soon
Required Deliverables