Services
Every engagement starts with the audit. What happens after that is entirely up to you: take the report and run, book us for a fixed-scope fix, or keep us on as ongoing support.
A comprehensive, read-only review of your Microsoft 365 and Azure security posture. We assess identity (Entra ID & Conditional Access), endpoint & XDR coverage, mail & data protection, cloud posture (Defender for Cloud), Microsoft Sentinel configuration, and licence utilisation. What's automatable gets scored against recognised security benchmarks, Sentinel and Defender are assessed against Microsoft's own best-practice guidance, and everything else is ranked by real-world risk.
Found: Legacy authentication still enabled on 40% of accounts, bypassing MFA entirely.
Fixed: Conditional Access policy blocking legacy auth, phased in over two weeks with an exception list for the last few service accounts that genuinely needed it.
This is exactly the kind of gap a self-reported questionnaire misses: nobody remembers a protocol setting from three IT managers ago. LUNA reads the actual sign-in logs, so it doesn't need anyone to remember.
You get a client-ready report (PDF, plus an editable Word version if you want to present it internally), and a live prioritised action list, not a document that goes stale the day it's sent.
You've got the priority list, now someone needs to actually do the work. An Uplift Engagement is a defined, time-boxed project where we implement the highest-impact fixes from your audit: policy changes, configuration hardening, licence reassignment, the lot. We scope it against your specific findings, agree a fixed fee up front, and deliver against a clear end date. No retainer, no ongoing commitment.
Found: Sensitivity labels existed but were never applied to a single document across three years of use.
Fixed: Priority-ordered label taxonomy rebuilt, auto-labelling policy piloted on Finance, then rolled out tenant-wide over four weeks.
A one-off engagement is the right shape here: a defined project with a real finish line, not an ongoing relationship.
Your Microsoft estate doesn't stand still: new starters, new licences, new integrations, new Microsoft features shipping every month. Engineering Support puts us on retainer as your outsourced security posture function: scheduled re-audits so drift gets caught quickly, ongoing Sentinel tuning so analytics rules and detections keep pace with your estate, remediation as new findings appear, and direct engineering support when something needs fixing fast.
Found: A re-audit six weeks after an initial fix caught a newly-onboarded app registration with tenant-wide mail read access, granted without review.
Fixed: Consent revoked the same day, an app governance review process put in place so it can't happen silently again.
This is the case for ongoing support: a fixed-point audit catches what's wrong today, but a security posture is a moving target.
Assessments
The three engagements above are how you buy. What we point them at is scoped to what you actually need looked at, whether that is your own estate, your detection stack, or the provider you already pay to run it.
Identity, endpoint and XDR, mail and data protection, cloud posture and licence use, scored against recognised benchmarks and ranked by real risk.
Workspace and table hygiene, analytics rule coverage, data connector health, automation, and what your ingestion is actually costing you against what it is buying you.
You pay someone to run your security. We read the tenant and tell you what they have actually configured, so you can hold the contract to what it promised.
Independent assurance
Most organisations that outsource security have no way to check the work. The reporting comes from the same provider doing the configuring, and a monthly service summary is not evidence. We read your tenant directly and show you the difference between what your provider says is in place and what is actually there.
Common questions
Read-only, always. A dedicated application identity (not a personal login) with the minimum Microsoft Graph, Azure RBAC, and, if relevant, Exchange Online permissions to run the audit. Nothing is enabled until an administrator in your organisation approves it, and we run a connectivity check against every permission before the audit starts so you can see exactly what we can see.
Typically a few working days from access being granted to report delivery, depending on the size of your estate. We'll give you an exact timeline once we've scoped the fixed price.
No. The audit stands alone: you get the report and the prioritised list either way, and what you do with it afterwards is entirely up to you.
Often more so. Outsourcing security to a provider does not tell you whether the work is being done, and the reporting you receive comes from the same people doing the configuring. We read your tenant independently and show you what is actually in place. We are not pitching to replace your provider, and the review does not arrive with a proposal to take over the contract.
We score against recognised security benchmarks and assess Sentinel and Defender against Microsoft's own best-practice guidance, with the same evidence cross-mapped to NIST CSF, ASD Essential 8, and ISO 27001 so you can speak to whichever framework matters to your board, client, or insurer without a second audit. The goal is a security posture that holds up in practice, not just a compliance checkbox.