VITALS A product by Innova Group

Assessment report

Microsoft 365
Health Assessment

A read-only review of your Microsoft 365 tenant — how content is shared and protected, how sign-in and devices are governed, what you are paying for and using, and whether you are ready for Copilot. Scored, with every finding in priority order and the reasoning behind it.

Prepared for

Kirkwell Industries Ltd

Date

28 July 2026

Prepared by

Innova Group

389 files 8 sites 200 user accounts 22 checks
Read-only assessment · nothing in the tenant was changed hello@innovagroup.tech · innovagroup.tech
VITALSOverall Health / 02

The Headline

Overall health

53.1 / 100 overall health
Emerging

Significant gaps. Content is reachable by people who should not reach it, and the environment needs work before more is built on it.

Optimised90+Healthy75–89Developing60–74Emerging40–59At riskunder 40

By area

Weakest first within each
0%
Email & Domain
Whether your domains can be impersonated, and what mailbox rules are doing
1 check
21%
Identity & Access
Sign-in protection, administrative control and third-party access
5 checks
46%
Licensing & Devices
What you pay for, what is used, and what is managed
2 checks
65%
Copilot Readiness
Whether Copilot can safely be switched on
1 check
73%
Content & Protection
How content is shared, labelled, owned and maintained
9 checks
81%
Workplace Experience
Whether the intranet is current and worth visiting
3 checks
Kirkwell Industries Ltd · 28 July 2026hello@innovagroup.tech · innovagroup.tech
VITALSExecutive Summary / 03

The Short Version

Executive summary

Kirkwell Industries Ltd scored 53.1 / 100Emerging. On the evidence below the environment needs substantial work. Access is wider than intended in several places and there is little to distinguish sensitive content from ordinary content.

The assessment reviewed 389 files across 8 sites and 200 users.

6CriticalAddress this week
12HighAddress this month
26Everything elseAddress this quarter

Resolve these first

Highest severity, most affected
  1. Nothing is protecting sign-in
  2. 20 files shared via anonymous "anyone with the link" links
  3. All 2 Conditional Access policies are in report-only mode

How to read this report

The sections that follow say what to do first: the priorities above, then the scores, then the evidence behind them. The findings section near the back is the reference — grouped by area and ordered by severity within each, so it can be worked through an area at a time or handed to whoever owns that area.

Kirkwell Industries Ltd · 28 July 2026hello@innovagroup.tech · innovagroup.tech
VITALSScores In Detail / 04

All 22 Dimensions

Scores in detail

Ordered weakest area first. The count beside each dimension is how many items were flagged out of how many were examined.

Email & Domain

0%
Email Domain Protection2 of 2 flagged
0%
Each domain the tenant sends mail from; a domain counts as flagged when its published SPF, DKIM or DMARC records leave it open to impersonation.

Identity & Access

21%
Sign-in Protection2 of 2 flagged
0%
Every Conditional Access policy in the tenant; a policy counts as flagged when it is not actually enforcing — report-only, disabled, or scoped to nobody.
Identity & Administration5 of 5 flagged
0%
A fixed set of tenant identity settings — administrator counts, legacy authentication, self-service consent and similar; each one either passes or is flagged.
Third-Party Applications3 of 3 flagged
0%
Third-party applications holding standing consent in the tenant, and the permissions each one was granted.
Microsoft Security BaselineScored on Microsoft's own Secure Score for this tenant, not on the count beside it.
42%
The Microsoft Secure Score controls that apply to this tenant; a control counts as flagged when it is not implemented.
Multi-Factor CoverageWeighted: an administrator who cannot complete a prompt counts for more than a standard account.
59%
Every licensed account; an account counts as flagged when it cannot complete a multi-factor prompt.

Licensing & Devices

46%
Device Management55 of 69 flagged
20%
Staff entitled to a managed device; a person counts as flagged when they have no compliant Intune-managed device enrolled.
Licence Utilisation15 of 86 flagged
83%
Paid licences bought against licences actually assigned; a licence counts as flagged when it is paid for and sitting unassigned.

Copilot Readiness

65%
Copilot ReadinessScored on the readiness conditions above, not on the count beside it. Content classification was not available on this tenant, so files are judged on how widely they can be reached rather than on what they are likely to contain.
65%
The conditions that decide whether Copilot can be switched on safely: how widely content is reachable, sharing defaults, labelling and identity posture, weighed together.
Kirkwell Industries Ltd · 28 July 2026hello@innovagroup.tech · innovagroup.tech
VITALSScores In Detail / 05

Content & Protection

73%
Sharing Defaults3 of 3 flagged
0%
Tenant-wide sharing settings — default link type, anonymous link expiry, external sharing scope; each one either passes or is flagged.
Site OwnershipScored across every workspace, not only the sites counted beside it.
57%
Every sampled site; a site counts as flagged when it has no active owner to approve access or answer for its content.
Workspace Hygiene3 of 14 flagged
79%
Every Team, group and site; a workspace counts as flagged when it is empty, abandoned or duplicated.
Content Freshness79 of 389 flagged
80%
Every sampled file; a file counts as flagged when it has not been modified in more than two years.
Labelling & ProtectionScored on whether a label scheme is published at all, per-file labelling being unavailable.
80%
Every sampled file; a file counts as flagged when it carries no sensitivity label, so no protection travels with it.
Access & Oversharing56 of 389 flagged
86%
Every sampled file; a file counts as flagged when it is shared more widely than it needs to be — anonymous links, organisation-wide sharing, or external guests.
Duplication53 of 389 flagged
86%
Files with a content hash, compared to each other; a file counts as flagged when it is a byte-for-byte copy of another one already counted.
Findability49 of 389 flagged
87%
Every sampled file name; a file counts as flagged when its name cannot identify it — “final v3”, “doc1”, “scan0001” and the like.
Guest AccessScored on dormant guests as a share of all accounts, not on the guest count beside it.
93%
External guest accounts with access to tenant content, and how long each has been dormant.

Workplace Experience

81%
Page Freshness10 of 30 flagged
67%
Published site pages; a page counts as flagged when it has not been edited in more than two years.
Landing Pages1 of 8 flagged
88%
The landing page of each sampled site, and whether it has been set up rather than left as the default.
Publishing Hygiene2 of 32 flagged
94%
Site pages; a page counts as flagged when it is still an unpublished draft that readers cannot see.

1 check was not run

These are excluded from the score entirely rather than counted as passes, so nothing above is flattered by them. Each needs a permission that was not granted, or data this tenant does not hold.

  • Mailbox Rules — Mailbox rules were not examined. This check needs the MailboxSettings.Read permission, which reads mailbox settings such as forwarding rules — never the contents of any message. It appears to have been declined or not yet granted.
Kirkwell Industries Ltd · 28 July 2026hello@innovagroup.tech · innovagroup.tech
VITALSEvidence / 06

What Was Found

Evidence

Email protection by domain

Public DNS

Three public records decide whether somebody can send email in your name. SPF lists who may send, DKIM signs what they send, and DMARC is the only one that tells a receiving server to act on a forgery. A domain with the first two and not the third looks protected and is not.

DomainSPFDKIMDMARCPolicy in force
kirkwell-joinery.co.ukAnyone can send as this domain
kirkwell.co.ukReported only — nothing is blocked

Applications with access to your data

Third party only

Consent does not expire and is not tied to anybody's session, so none of this is affected by a password reset. Microsoft's own services are excluded. The question for each row is whether somebody can name it and say why it is still here.

ApplicationSupplierMailFilesCan changeSince
Invoice Sync Helpernot recordedJan 2026
Mail Signature ManagerExclaimer Ltd verifiedAug 2023
DocuSignDocuSign Inc. verifiedApr 2024

A tick under Mail or Files means organisation-wide access, not access to one person's account.

Who can complete a multi-factor prompt

46 of 69
  • 40 app or security key
  • 6 text message or call only
  • 23 nothing registered

Of 5 administrators, 2 cannot. Those accounts can change anything in the tenant and are protected by a password alone. Registration is what a sign-in policy depends on: a requirement applied to people who cannot meet it produces exclusions, not protection.

Kirkwell Industries Ltd · 28 July 2026hello@innovagroup.tech · innovagroup.tech
VITALSCopilot Readiness / 07

The Question Everyone Asks

Microsoft 365 Copilot

Not yet

Copilot answers using whatever the person asking is already allowed to see. It does not widen access — it makes existing access easy to find by asking. So what decides readiness is not the technology, it is whether anything is sitting somewhere it should not be.

Resolve before rollout

In order
  1. Sign-in protection is not enforced, and Copilot raises what an account is worthEnforce multi-factor authentication before rollout rather than after.
Kirkwell Industries Ltd · 28 July 2026hello@innovagroup.tech · innovagroup.tech
VITALSLicensing & Scope / 08

Already Paid For

What you already own

Every subscription in this tenant, and how many are assigned to somebody. Capability that is already paid for is the cheapest improvement available — it needs switching on rather than buying.

SubscriptionAssignedBoughtSpare
Microsoft 365 Business Premium61687
Microsoft 365 E38124
Visio Plan 2264

Included with Microsoft 365 Business Premium, whether or not it is switched on:

  • Device management (Intune)
  • Conditional Access and multi-factor authentication
  • Information protection and sensitivity labels
  • Defender for Business
  • Multi-factor authentication
  • Exchange Online

What was scanned

Coverage

3 personal or app sites excluded by design. OneDrive, Designer, Loop and similar are not part of a SharePoint readiness assessment.

My workspace, Designer, Loop

1 site could not be read

Real business sites blocked by an access policy. Worth an administrator confirming the restriction is intended: Board Confidential.

Kirkwell Industries Ltd · 28 July 2026hello@innovagroup.tech · innovagroup.tech
VITALSAction Plan / 09

In Priority Order

Action plan

The same findings as the reference section, arranged as work rather than as evidence. Nothing here is new — it is the order to do it in.

This week

6 critical findings
  • Nothing is protecting sign-in
  • 20 files shared via anonymous "anyone with the link" links
  • All 2 Conditional Access policies are in report-only mode
  • 2 third-party applications can read mail across this organisation
  • 2 administrators have no multi-factor method registered
  • 1 domain has no DMARC record, so anybody can send email as this organisation

This month

12 high-severity findings
  • 69 people are licensed for device management, and 14 devices are enrolled
  • 36 files shared org-wide ("Everyone")
  • The tenant permits anonymous "anyone with the link" sharing
  • 15 licences paid for and assigned to nobody
  • 14 guest accounts over a year old
  • 10 intranet pages not updated in over 2 years
  • 6 accounts rely on text message or phone call alone

and 5 more — all listed in full in the findings section.

This quarter

26 remaining findings
  • Microsoft rates this tenant at 41.8% of its own security baseline
  • 79 files not modified in over 2 years
  • 53 duplicate copies across 21 sets of identical files
  • 49 poorly named files
  • 21 accounts have no multi-factor method registered
  • 8 recommended controls are not in place
  • 6 accounts hold full administrative control

and 19 more — all listed in full in the findings section.

Kirkwell Industries Ltd · 28 July 2026hello@innovagroup.tech · innovagroup.tech
VITALSFindings / 10

The Reference

Every finding, in full

The evidence behind the score, grouped by area and ordered by severity within each — what was found, why it matters, and the standard remedy. Meant to be worked through an area at a time.

Identity & Access

16 findings · 6 needing attention

Critical Nothing is protecting sign-in

Security defaults are switched off and no Conditional Access policy is enforced. Microsoft offers two ways to require multi-factor authentication and neither is in use, so a password on its own is currently enough to sign in as anybody here, from anywhere.

Recommended fix: If Conditional Access is licensed, use it — it is the more flexible of the two. If not, switch security defaults on. It is free, takes a minute, and is far better than nothing.

Critical All 2 Conditional Access policies are in report-only mode

Report-only policies record what would have happened without ever stopping anything. They are the right way to test a policy and the wrong way to leave one — the protection appears to be configured while nothing is actually being enforced.

Recommended fix: Review the report-only results, then switch the policies on. This is usually a matter of minutes and needs no new licence.

Critical 2 third-party applications can read mail across this organisation

These applications hold access to mailboxes for the whole organisation, granted once and not tied to anybody's session. A password reset does not affect them, revoking sign-ins does not affect them, and multi-factor authentication was never involved. Some will be tools somebody chose deliberately — a signature manager, a CRM, a backup product. The rest are how a consent-phishing attack keeps reading mail months afterwards.

Recommended fix: Review each one in Entra under Enterprise applications. Anything nobody can name and account for should have its permissions revoked today; the access does not lapse on its own.

Critical 2 administrators have no multi-factor method registered

These accounts can change anything in the tenant and are protected by a password alone. An administrator without multi-factor is the single most valuable target in the organisation and the least defended, and the credentials for it are worth buying rather than guessing.

Recommended fix: Register a method on these accounts today. Where one is a break-glass account kept deliberately outside the policy, it still needs a method registered, a long stored password and somebody watching it for use.

Kirkwell Industries Ltd · 28 July 2026hello@innovagroup.tech · innovagroup.tech
VITALSFindings / 11

High 6 accounts rely on text message or phone call alone

Codes by text and voice call are better than a password on its own and are the weakest thing Microsoft still counts as multi-factor. A mobile number can be moved to an attacker's SIM by persuading the network to do it, which is a routine attack against anybody worth the effort, and it defeats both. At least one of these is an administrator.

Recommended fix: Move these to the Microsoft Authenticator app, which is free and works on any phone. Administrators should move first.

High 1 disabled account still holds administrative rights

A disabled account that retains Global Administrator is a re-enabled account away from full control of the tenant. Disabling is what happens when somebody leaves; removing the role is what should happen with it.

Recommended fix: Remove the administrative role from these accounts, then decide separately whether the account itself should still exist.

Medium Microsoft rates this tenant at 41.8% of its own security baseline

Secure Score is Microsoft's assessment of the tenant against its own recommendations — currently 214 points of 512 available. It is a useful independent measure precisely because it is not ours, and it is the number a customer can check for themselves at any time.

Recommended fix: Work through the highest-value controls first. The Microsoft 365 admin centre orders them by the points they carry, which broadly follows the risk they address.

Medium 21 accounts have no multi-factor method registered

Nothing is enforcing multi-factor on this tenant, and these accounts could not satisfy a requirement if one were introduced. That ordering matters: getting people registered first is what makes enforcement a switch rather than an incident.

Recommended fix: Run a registration campaign before enforcing anything. Microsoft can prompt people to register at next sign-in, which does the work for you.

Medium 8 recommended controls are not in place

These are Microsoft's own recommendations for this tenant, and nothing has been recorded against them — neither implemented nor deliberately set aside. Many are settings rather than purchases, and a good number are covered by licences this organisation already holds.

Recommended fix: Review them by area. The identity ones usually give the largest improvement for the least work.

Medium 6 accounts hold full administrative control

A Global Administrator can do anything in the tenant, including granting themselves access to anybody's mailbox or files and removing the record that they did. Every one of these accounts is worth more to an attacker than any ordinary account, and the number tends to grow because adding one solves an immediate problem and removing one never does.

Recommended fix: Reduce to two or three named people. Where somebody needs to do one specific job, a narrower role usually exists for it — user administration, or helpdesk, rather than everything.

Kirkwell Industries Ltd · 28 July 2026hello@innovagroup.tech · innovagroup.tech
VITALSFindings / 12

Medium Guests can invite further guests

An external person who has been given access can invite other external people, who can invite more. Nobody inside the organisation approves any of it, and the resulting list is not one anybody is reviewing.

Recommended fix: Restrict invitations to administrators, or to a named group of people who understand what they are granting.

Medium Any user can register an application

Ordinary accounts can create applications that request access to company data. This is how consent-phishing works: the victim is asked to approve an app rather than to hand over a password, and multi-factor authentication does not help because nothing was stolen — it was granted.

Recommended fix: Restrict application registration to administrators, and require admin consent for applications requesting access to data.

Medium 1 third-party application has access to SharePoint and OneDrive content

These hold organisation-wide access to files, and read what they can reach. That is the same content the rest of this report assesses for over-sharing, reached by something that does not appear in any sharing list.

Recommended fix: Confirm each application is still in use and still supplied by who you think it is. Remove the ones that are not.

Medium 1 application carries no publisher details in Entra

Entra records no verified publisher for these, so who supplied them cannot be confirmed from the tenant alone. That is not an accusation: publisher verification is optional, and reputable vendors — particularly ones sold through IT providers rather than direct — routinely skip it. Applications built in-house never have it at all. The point is that each of these holds broad access and Entra cannot tell you who stands behind it, so somebody has to.

Recommended fix: Name the supplier and the internal owner for each. Recognising the vendor is enough; the ones to worry about are those nobody can account for.

Low 2 applications have held access for more than 2 years

Consent does not expire. These were approved at some point, for some reason, and have held their access ever since — through staff changes, supplier changes and system replacements. Long-lived access is not wrong; long-lived access nobody has reviewed is how an estate accumulates doors that nobody remembers fitting.

Recommended fix: Add an annual review of consented applications. Anything without a current owner and a current reason should be removed.

Info 1 control has been marked as covered elsewhere or not applicable

Somebody has reviewed these and decided they are handled by another product or do not apply. That is a legitimate answer, and they are listed here only so the decision is visible rather than invisible.

Recommended fix: Worth confirming the third-party product named is still in place, since these decisions outlive the arrangements that prompted them.

Kirkwell Industries Ltd · 28 July 2026hello@innovagroup.tech · innovagroup.tech
VITALSFindings / 13

Email & Domain

3 findings · 2 needing attention

Critical 1 domain has no DMARC record, so anybody can send email as this organisation

Without DMARC, a receiving mail server has no instruction about what to do with a message that claims to come from this domain but did not. Most will deliver it. That is how a supplier receives an invoice from the finance director's address with different bank details on it, and how staff receive a request from the managing director that the managing director never sent. The forged message is not a copy of the domain — it is the domain.

Recommended fix: Publish a DMARC record starting at p=none to see who is currently sending as you, then move to p=quarantine and p=reject once the legitimate senders are accounted for. It is a DNS change and costs nothing.

High DMARC is published but set to take no action on 1 domain

A policy of p=none means forged mail is reported and then delivered anyway. This is the correct place to start and the wrong place to stop, and it is where most organisations stop — the record exists, the box is ticked, and nothing is being blocked. Anyone checking whether this domain is protected will be told it is.

Recommended fix: Review the DMARC reports for legitimate senders that would fail, fix those, then move the policy to quarantine and finally to reject.

Medium DKIM signing is not configured for 1 domain

DKIM adds a signature that survives forwarding, where SPF does not. Without it, legitimate mail that has been forwarded — through a mailing list, or a client's own rules — can fail checks and be treated as forged. This becomes the reason DMARC enforcement gets rolled back after complaints.

Recommended fix: Enable DKIM for these domains in the Microsoft 365 Defender portal and publish the two CNAME records it gives you. Do this before moving DMARC to reject.

Content & Protection

15 findings · 6 needing attention

Critical 20 files shared via anonymous "anyone with the link" links

Anonymous links bypass identity entirely — anyone holding the URL can open the file, and the link can be forwarded outside the organisation without leaving a trace. Nothing records who has it, so there is no way to answer who has seen a file, and no way to withdraw it from one person without breaking the link for everybody.

Recommended fix: Disable anonymous link creation at the tenant/site level and expire existing anonymous links. Replace with specific-people or company-wide links where sharing is genuinely needed.

High 36 files shared org-wide ("Everyone")

Company-wide sharing means every member of staff can open these files, whether or not that was ever the intention. Sharing set up for convenience is rarely revisited once it works. It is also a common cause of Copilot answering from something it should not have.

Recommended fix: Review org-wide shares and scope them to the owning department or a security group. Start with the sites holding finance, HR or customer material.

Kirkwell Industries Ltd · 28 July 2026hello@innovagroup.tech · innovagroup.tech
VITALSFindings / 14

High The tenant permits anonymous "anyone with the link" sharing

This setting is why 20 files in this scan are reachable by anybody holding a URL, with no sign-in and no record of who opened them. Those files can be fixed one by one, but while the setting stands the next person to press Share will create more.

Recommended fix: Restrict sharing to guests who sign in, so that access is attributable and can be withdrawn. Where anonymous links are genuinely needed, set an expiry on them.

High 14 guest accounts over a year old

Long-lived guest accounts are rarely reviewed and often outlast the project they were invited for, leaving standing external access to your content.

Recommended fix: Run an access review of external guests and remove those no longer needed. Enable Entra access reviews to recertify guests on a schedule.

High 2 workspaces with no owner

Ownerless sites and Teams have nobody accountable for their content, access or lifecycle. They accumulate risk silently and are a common audit finding.

Recommended fix: Assign at least two owners to every workspace. Use an ownerless-group policy so Microsoft 365 prompts members to take ownership automatically.

High Sharing defaults to the widest option rather than the narrowest

When somebody presses Share, the link they are offered first is one that works for more people than they probably intend. Most sharing is done quickly and accepts whatever is offered, so this single setting shapes most of what ends up over-shared.

Recommended fix: Change the default to specific people. Anyone who needs a wider link can still choose one; they will simply have to mean it.

Medium 79 files not modified in over 2 years

Of these, 26 are more than 4 years old. Superseded documents do not announce themselves — they sit in search looking identical to the current version and get quoted in good faith. Anything reading the library, staff and Copilot alike, treats them as current.

Recommended fix: Archive or move superseded content out of active libraries, or apply a retention or archive label so it can be scoped out of search. Establish a review-by date for key documents.

Medium 53 duplicate copies across 21 sets of identical files

The most duplicated file exists in 6 places. When the same content lives in several locations nobody can tell which one is authoritative — including the people relying on it, and any search or assistant reading across them.

Recommended fix: Consolidate to a single source of truth and replace copies with links. Prioritise duplicate sets that span multiple sites or departments.

Kirkwell Industries Ltd · 28 July 2026hello@innovagroup.tech · innovagroup.tech
VITALSFindings / 15

Medium 49 poorly named files

Generic and versioned names ('Document1', 'Copy of…', 'FINAL v3') carry no meaning to search. If someone cannot find a document by name they recreate it, which is how duplicate sets start. The same missing signal makes search return the wrong file.

Recommended fix: Adopt a naming convention and rename the worst offenders. Encourage descriptive titles and use metadata columns instead of encoding version/status into the filename.

Medium 1 SharePoint site inactive for 12+ months

Abandoned sites still hold their data and still appear in search, long after anyone stopped maintaining them. They widen the surface that has to be secured and reviewed, and they are where content nobody has looked at in years quietly stays reachable.

Recommended fix: Confirm ownership, archive or delete abandoned sites, and set an inactivity policy so they are caught automatically in future.

Medium Anonymous links never expire

A link shared for one afternoon keeps working indefinitely. Nobody revisits them, so the set of live anonymous links only ever grows, and each one outlives the reason it was created.

Recommended fix: Set an expiry — 30 days suits most work. Existing links are unaffected, so this stops the problem growing rather than fixing what is already there.

Low 2 Teams with no recent activity

Inactive Teams keep their SharePoint document libraries live and indexable long after the work has stopped.

Recommended fix: Archive dormant Teams to freeze their content while preserving it for reference.

Low 2 workspaces with only one owner

A single owner is a continuity risk — if they leave, the workspace becomes ownerless.

Recommended fix: Add a second owner to each of these workspaces.

Info 18 guest accounts in the tenant

Guests make up 9% of all accounts. Each is an identity outside the organisation that can hold access to sites and files, and that nobody inside manages day to day.

Recommended fix: Confirm every guest is still required and governed by expiry / access-review policies.

Info Sensitivity-label scheme in place (3 labels)

A label taxonomy is published, which is what every other protection keys off. Per-file label adoption could not be measured with read-only Graph access in this scan.

Recommended fix: Confirm auto-labelling is applied to high-risk libraries (HR, Finance, Legal), and enable SharePoint Advanced Management or Purview reporting to measure coverage.

Kirkwell Industries Ltd · 28 July 2026hello@innovagroup.tech · innovagroup.tech
VITALSFindings / 16

Licensing & Devices

5 findings · 2 needing attention

High 69 people are licensed for device management, and 14 devices are enrolled

Device management is included in the subscriptions this organisation already holds. Where a device is not enrolled, none of it applies: company data on that machine cannot be protected, wiped if it is lost, or held to any standard. This is capability that is already paid for and is not being used.

Recommended fix: Enrol company devices in Intune, starting with laptops that hold or access company data. No additional licence is needed — the entitlement is already there.

High 15 licences paid for and assigned to nobody

These subscriptions are being billed in full every month regardless of whether anyone holds them. Keeping a seat or two spare for a new starter is sensible; beyond that it is a standing cost with nothing behind it. The most common cause is somebody leaving and the licence never being released.

Recommended fix: Review each subscription against current headcount and reduce the quantity at the next billing date, keeping a small buffer for new starters. Your Microsoft partner or the Microsoft 365 admin centre can adjust the counts.

Medium 2 enrolled devices fail the organisation's own policy

These devices are enrolled but do not meet the rules this organisation has itself set — commonly a missing update, disabled encryption, or no screen lock. A device failing policy is usually a device that has drifted rather than one that was never set up.

Recommended fix: Review the failures by reason in the Intune admin centre. Most resolve by bringing the device up to date rather than by changing any policy.

Medium 2 devices have not checked in for over 30 days

An enrolled device that has stopped contacting Intune is managed on paper only. It will not receive policy, will not report its state, and cannot be wiped remotely if it is lost. The usual causes are a machine that has been retired without being removed, or one that has quietly fallen out of management.

Recommended fix: Retire devices that are genuinely gone so the estate reflects reality, and investigate any that should still be in use.

Low Microsoft 365 Business Premium already includes device and identity protection

61 users hold Microsoft 365 Business Premium, which entitles this organisation to capabilities that are frequently bought again elsewhere or simply left switched off — device management, conditional access and information protection among them.

Recommended fix: Before considering additional security products, confirm which of these are actually switched on. Turning on something already paid for is the cheapest security improvement available.

Kirkwell Industries Ltd · 28 July 2026hello@innovagroup.tech · innovagroup.tech
VITALSFindings / 17

Workplace Experience

3 findings · 1 needing attention

High 10 intranet pages not updated in over 2 years

Outdated pages make an intranet feel abandoned, and staff stop checking it — which is usually when people start keeping their own copies instead. Search and Copilot both cite the content as though it were current.

Recommended fix: Assign page owners and a review-by date, refresh or retire stale pages, and consider page-level expiry on time-sensitive content.

Medium 1 active site with no published landing page

These sites hold real content but present visitors with a bare document library instead of a modern page with navigation, news and context — a poor front door.

Recommended fix: Add a modern home page to each active site with clear navigation, key links and an owner. Use a site template to make this consistent.

Low 2 pages stuck in draft

Draft pages are invisible to visitors — someone started them but never published. They clutter authoring views and represent unfinished intranet work.

Recommended fix: Review draft pages: publish the ones that are ready and delete the abandoned ones.

Copilot Readiness

2 findings · 1 needing attention

High Sign-in protection is not enforced, and Copilot raises what an account is worth

A compromised account currently gives an intruder whatever that person can reach, if they know where to look. With Copilot it gives them a research assistant over the same material. The account becomes a more valuable target without becoming better defended.

Recommended fix: Enforce multi-factor authentication before rollout rather than after.

Low 38 people work in Teams and documents daily — the natural first group

Of 52 licensed users active in the last 30 days, these also work across Teams and files, which is the material Copilot draws on. Starting with people who already collaborate is what makes a pilot look successful; starting with everyone is what makes it look expensive. A further 17 licensed 17 accounts have shown no activity at all, which is worth resolving before adding anything to them.

Recommended fix: Pilot with this group first and measure it before widening. Copilot is charged per user per month, so who goes first is a cost decision as much as a technical one.

Kirkwell Industries Ltd · 28 July 2026hello@innovagroup.tech · innovagroup.tech
VITALS A product by Innova Group

Next steps

What to do next

The findings above are in priority order, each with the reasoning behind it. You are free to work through the list yourself or hand it to your existing IT provider — it is yours either way. If you would rather we carried out the remediation, Innova Group can do that and re-scan afterwards so you can see exactly what changed. Where there is nothing meaningful to fix, we will tell you that instead.

Get in touch

hello@innovagroup.tech · innovagroup.tech

hello@innovagroup.tech · innovagroup.tech

Kirkwell Industries Ltd · 28 July 2026 Source: Mock tenant (synthetic sample data) · advisory, based on a read-only assessment