Fixed fee · Read-only · Principal-led

Microsoft 365 Identity Security Assessment

A fixed-fee, read-only review of your Microsoft 365 tenant for Texas organizations. Evidence for every finding, a prioritized fix plan, and approved remediation options.

Why identity

Most Microsoft 365 breaches start with identity.

A sign-in that should have been challenged. An account with more access than it needs. A setting nobody has looked at since the tenant was created. This assessment reviews those controls setting by setting and shows you exactly what to fix first. The controls reviewed map to the CISA SCuBA baseline for Microsoft Entra ID and the derived NIST SP 800-53 Rev. 5 controls.

What you get

  • A written report with evidence

    Evidence for every finding, not a scanner printout.

  • A prioritized fix plan

    What is exposed, why it matters, and the order to fix it.

  • A 90-minute readout

    The findings walked through with your team or your IT provider.

  • Approved remediation options

    If you want the fixes done for you, scoped and agreed in writing.

At a glance

  • Fixed fee, scoped after the discovery call
  • Read-only access you grant and can revoke
  • No software installed on your devices
  • One 90-minute readout against prepared deliverables
  • Written so your IT provider can act on it
How it works

Four steps, no surprises.

01

Discovery call

A 30-minute conversation to confirm scope and quote a fixed fee. No obligation.

02

Access

You grant read-only access to your tenant. No software touches your devices, and you can revoke the access at any time.

03

Review

We examine your identity and access configuration setting by setting and collect evidence as we go.

04

Findings

When collection is complete, you receive the report, the fix plan, and the scorecard, then one 90-minute readout with your team or your IT provider.

Who this is for

Organizations that need a clear answer.

Organizations that run on Microsoft 365 and need a clear answer, from lean nonprofits to multi-site companies: for a cyber insurance questionnaire, a board or leadership question, a customer security review, or a concern about account compromise. If you have an IT provider, the report is written so they can act on it directly.

For businesses and organizations only. We do not provide consumer or personal account support.

Who delivers it

Mount Xion Technologies is a veteran-owned firm in San Antonio, Texas. Its founder directed IT and cybersecurity for a $1B+ organization and served in the USAF. Every engagement is principal-led, from first call to final report. When extra hands are needed, we bring in vetted senior practitioners we have worked with directly.

Credentials across the practice include CISSP, PMP, SSCP, CompTIA CySA+, CompTIA Security+, CompTIA Project+, and ITIL 4. We treat credentials as table stakes: the deliverables stand on evidence collected from your tenant, not on letters after names.

Pricing

Fixed fee, scoped after the discovery call. You will know the full cost before any work begins.

Common triggers

  • A cyber insurance questionnaire you cannot answer confidently
  • A board or leadership request for a security picture
  • A customer security review
  • A concern that an account was compromised
  • A general posture check before something goes wrong
Request a discovery call

Request a 30-minute discovery call.

Tell us a little about your organization and we will confirm scope and quote a fixed fee on the call.

All fields help scope the conversation. Nothing here is a commitment.

We respond within one business day. Your information is used only to schedule and scope the conversation.

Prefer to book directly?

Pick a time on the calendar.

Same 30 minutes, same straight answer. No pitch, no obligation.