Entra ID & access
Admin roles, MFA coverage, Conditional Access, legacy auth, guest access, and privileged-account hygiene.
Every security gap in Entra ID, Intune, Exchange, SharePoint, and Defender: found, ranked by real risk, and mapped to a remediation plan. In five business days, for a fixed fee.
WHAT WE EXAMINE
Admin roles, MFA coverage, Conditional Access, legacy auth, guest access, and privileged-account hygiene.
Enrollment, compliance policies, BitLocker, Defender configuration, and unmanaged-device exposure.
Mail-flow rules, forwarding abuse, shared mailboxes, anti-phish/anti-spoof posture, SPF/DKIM/DMARC.
External sharing, anonymous links, data sprawl, and sensitive-content exposure.
Alert policies, unattended detections, Secure Score gaps, and audit-log configuration.
Unused licenses, over-licensed users, stale accounts, and features you already pay for but don't use.
THE PROCESS / FIVE DAYS
Read-only access, zero disruption to your team, and findings presented in language your leadership can act on.
A 30-minute call, then read-only auditor access, we never touch production settings.
Automated baselining plus manual review by a senior engineer across all six areas.
Every gap documented with evidence, ranked by exploitability and business impact.
A live walkthrough for leadership: what's urgent, what can wait, what it costs to fix.
WHAT YOU WALK AWAY WITH
The report is yours. Fix it with your own IT, another vendor, or us, the assessment stands on its own either way. If you choose KOMARSH for remediation within 90 days, the full assessment fee is credited.
COMMON QUESTIONS
No. The review uses read-only access and runs entirely in the background. Your staff will not notice it happening; nothing in the tenant is changed.
It's common, and healthy. An independent assessment either confirms your provider is doing well or surfaces what's been missed. Many clients share the report with their provider as a work list.
User count, primarily. Smaller tenants land near $1,500; most 20–150 user organizations are $2,500 flat; complex multi-domain tenants are quoted before we start. The number is fixed in writing either way.
Directly. For government contractors, the findings are mapped against the Microsoft-side controls those frameworks expect, so the roadmap doubles as compliance groundwork, not a separate exercise.