Microsoft 365 Identity Security Assessment
A fixed-fee, read-only review of your Microsoft 365 tenant for Texas organizations. Evidence for every finding, a prioritized fix plan, and approved remediation options.
Most Microsoft 365 breaches start with identity.
A sign-in that should have been challenged. An account with more access than it needs. A setting nobody has looked at since the tenant was created. This assessment reviews those controls setting by setting and shows you exactly what to fix first. The controls reviewed map to the CISA SCuBA baseline for Microsoft Entra ID and the derived NIST SP 800-53 Rev. 5 controls.
What you get
A written report with evidence
Evidence for every finding, not a scanner printout.
A prioritized fix plan
What is exposed, why it matters, and the order to fix it.
A 90-minute readout
The findings walked through with your team or your IT provider.
Approved remediation options
If you want the fixes done for you, scoped and agreed in writing.
At a glance
- Fixed fee, scoped after the discovery call
- Read-only access you grant and can revoke
- No software installed on your devices
- One 90-minute readout against prepared deliverables
- Written so your IT provider can act on it
Four steps, no surprises.
Discovery call
A 30-minute conversation to confirm scope and quote a fixed fee. No obligation.
Access
You grant read-only access to your tenant. No software touches your devices, and you can revoke the access at any time.
Review
We examine your identity and access configuration setting by setting and collect evidence as we go.
Findings
When collection is complete, you receive the report, the fix plan, and the scorecard, then one 90-minute readout with your team or your IT provider.
Organizations that need a clear answer.
Organizations that run on Microsoft 365 and need a clear answer, from lean nonprofits to multi-site companies: for a cyber insurance questionnaire, a board or leadership question, a customer security review, or a concern about account compromise. If you have an IT provider, the report is written so they can act on it directly.
For businesses and organizations only. We do not provide consumer or personal account support.
Who delivers it
Mount Xion Technologies is a veteran-owned firm in San Antonio, Texas. Its founder directed IT and cybersecurity for a $1B+ organization and served in the USAF. Every engagement is principal-led, from first call to final report. When extra hands are needed, we bring in vetted senior practitioners we have worked with directly.
Credentials across the practice include CISSP, PMP, SSCP, CompTIA CySA+, CompTIA Security+, CompTIA Project+, and ITIL 4. We treat credentials as table stakes: the deliverables stand on evidence collected from your tenant, not on letters after names.
Pricing
Fixed fee, scoped after the discovery call. You will know the full cost before any work begins.
Common triggers
- A cyber insurance questionnaire you cannot answer confidently
- A board or leadership request for a security picture
- A customer security review
- A concern that an account was compromised
- A general posture check before something goes wrong
Request a 30-minute discovery call.
Tell us a little about your organization and we will confirm scope and quote a fixed fee on the call.