Assessment report
A read-only review of your Microsoft 365 tenant — how content is shared and protected, how sign-in and devices are governed, what you are paying for and using, and whether you are ready for Copilot. Scored, with every finding in priority order and the reasoning behind it.
The Headline
Significant gaps. Content is reachable by people who should not reach it, and the environment needs work before more is built on it.
The Short Version
Kirkwell Industries Ltd scored 53.1 / 100 — Emerging. On the evidence below the environment needs substantial work. Access is wider than intended in several places and there is little to distinguish sensitive content from ordinary content.
The assessment reviewed 389 files across 8 sites and 200 users.
How to read this report
The sections that follow say what to do first: the priorities above, then the scores, then the evidence behind them. The findings section near the back is the reference — grouped by area and ordered by severity within each, so it can be worked through an area at a time or handed to whoever owns that area.
All 22 Dimensions
Ordered weakest area first. The count beside each dimension is how many items were flagged out of how many were examined.
1 check was not run
These are excluded from the score entirely rather than counted as passes, so nothing above is flattered by them. Each needs a permission that was not granted, or data this tenant does not hold.
What Was Found
Three public records decide whether somebody can send email in your name. SPF lists who may send, DKIM signs what they send, and DMARC is the only one that tells a receiving server to act on a forgery. A domain with the first two and not the third looks protected and is not.
| Domain | SPF | DKIM | DMARC | Policy in force |
|---|---|---|---|---|
| kirkwell-joinery.co.uk | ✓ | ✗ | ✗ | Anyone can send as this domain |
| kirkwell.co.uk | ✓ | ✓ | ● | Reported only — nothing is blocked |
Consent does not expire and is not tied to anybody's session, so none of this is affected by a password reset. Microsoft's own services are excluded. The question for each row is whether somebody can name it and say why it is still here.
| Application | Supplier | Files | Can change | Since | |
|---|---|---|---|---|---|
| Invoice Sync Helper | not recorded | ✓ | ✓ | — | Jan 2026 |
| Mail Signature Manager | Exclaimer Ltd verified | ✓ | — | ✓ | Aug 2023 |
| DocuSign | DocuSign Inc. verified | — | ✓ | — | Apr 2024 |
A tick under Mail or Files means organisation-wide access, not access to one person's account.
Of 5 administrators, 2 cannot. Those accounts can change anything in the tenant and are protected by a password alone. Registration is what a sign-in policy depends on: a requirement applied to people who cannot meet it produces exclusions, not protection.
The Question Everyone Asks
Copilot answers using whatever the person asking is already allowed to see. It does not widen access — it makes existing access easy to find by asking. So what decides readiness is not the technology, it is whether anything is sitting somewhere it should not be.
Already Paid For
Every subscription in this tenant, and how many are assigned to somebody. Capability that is already paid for is the cheapest improvement available — it needs switching on rather than buying.
| Subscription | Assigned | Bought | Spare |
|---|---|---|---|
| Microsoft 365 Business Premium | 61 | 68 | 7 |
| Microsoft 365 E3 | 8 | 12 | 4 |
| Visio Plan 2 | 2 | 6 | 4 |
Included with Microsoft 365 Business Premium, whether or not it is switched on:
3 personal or app sites excluded by design. OneDrive, Designer, Loop and similar are not part of a SharePoint readiness assessment.
My workspace, Designer, Loop
1 site could not be read
Real business sites blocked by an access policy. Worth an administrator confirming the restriction is intended: Board Confidential.
In Priority Order
The same findings as the reference section, arranged as work rather than as evidence. Nothing here is new — it is the order to do it in.
and 5 more — all listed in full in the findings section.
and 19 more — all listed in full in the findings section.
The Reference
The evidence behind the score, grouped by area and ordered by severity within each — what was found, why it matters, and the standard remedy. Meant to be worked through an area at a time.
Critical Nothing is protecting sign-in
Security defaults are switched off and no Conditional Access policy is enforced. Microsoft offers two ways to require multi-factor authentication and neither is in use, so a password on its own is currently enough to sign in as anybody here, from anywhere.
Recommended fix: If Conditional Access is licensed, use it — it is the more flexible of the two. If not, switch security defaults on. It is free, takes a minute, and is far better than nothing.
Critical All 2 Conditional Access policies are in report-only mode
Report-only policies record what would have happened without ever stopping anything. They are the right way to test a policy and the wrong way to leave one — the protection appears to be configured while nothing is actually being enforced.
Recommended fix: Review the report-only results, then switch the policies on. This is usually a matter of minutes and needs no new licence.
Critical 2 third-party applications can read mail across this organisation
These applications hold access to mailboxes for the whole organisation, granted once and not tied to anybody's session. A password reset does not affect them, revoking sign-ins does not affect them, and multi-factor authentication was never involved. Some will be tools somebody chose deliberately — a signature manager, a CRM, a backup product. The rest are how a consent-phishing attack keeps reading mail months afterwards.
Recommended fix: Review each one in Entra under Enterprise applications. Anything nobody can name and account for should have its permissions revoked today; the access does not lapse on its own.
Critical 2 administrators have no multi-factor method registered
These accounts can change anything in the tenant and are protected by a password alone. An administrator without multi-factor is the single most valuable target in the organisation and the least defended, and the credentials for it are worth buying rather than guessing.
Recommended fix: Register a method on these accounts today. Where one is a break-glass account kept deliberately outside the policy, it still needs a method registered, a long stored password and somebody watching it for use.
High 6 accounts rely on text message or phone call alone
Codes by text and voice call are better than a password on its own and are the weakest thing Microsoft still counts as multi-factor. A mobile number can be moved to an attacker's SIM by persuading the network to do it, which is a routine attack against anybody worth the effort, and it defeats both. At least one of these is an administrator.
Recommended fix: Move these to the Microsoft Authenticator app, which is free and works on any phone. Administrators should move first.
High 1 disabled account still holds administrative rights
A disabled account that retains Global Administrator is a re-enabled account away from full control of the tenant. Disabling is what happens when somebody leaves; removing the role is what should happen with it.
Recommended fix: Remove the administrative role from these accounts, then decide separately whether the account itself should still exist.
Medium Microsoft rates this tenant at 41.8% of its own security baseline
Secure Score is Microsoft's assessment of the tenant against its own recommendations — currently 214 points of 512 available. It is a useful independent measure precisely because it is not ours, and it is the number a customer can check for themselves at any time.
Recommended fix: Work through the highest-value controls first. The Microsoft 365 admin centre orders them by the points they carry, which broadly follows the risk they address.
Medium 21 accounts have no multi-factor method registered
Nothing is enforcing multi-factor on this tenant, and these accounts could not satisfy a requirement if one were introduced. That ordering matters: getting people registered first is what makes enforcement a switch rather than an incident.
Recommended fix: Run a registration campaign before enforcing anything. Microsoft can prompt people to register at next sign-in, which does the work for you.
Medium 8 recommended controls are not in place
These are Microsoft's own recommendations for this tenant, and nothing has been recorded against them — neither implemented nor deliberately set aside. Many are settings rather than purchases, and a good number are covered by licences this organisation already holds.
Recommended fix: Review them by area. The identity ones usually give the largest improvement for the least work.
Medium 6 accounts hold full administrative control
A Global Administrator can do anything in the tenant, including granting themselves access to anybody's mailbox or files and removing the record that they did. Every one of these accounts is worth more to an attacker than any ordinary account, and the number tends to grow because adding one solves an immediate problem and removing one never does.
Recommended fix: Reduce to two or three named people. Where somebody needs to do one specific job, a narrower role usually exists for it — user administration, or helpdesk, rather than everything.
Medium Guests can invite further guests
An external person who has been given access can invite other external people, who can invite more. Nobody inside the organisation approves any of it, and the resulting list is not one anybody is reviewing.
Recommended fix: Restrict invitations to administrators, or to a named group of people who understand what they are granting.
Medium Any user can register an application
Ordinary accounts can create applications that request access to company data. This is how consent-phishing works: the victim is asked to approve an app rather than to hand over a password, and multi-factor authentication does not help because nothing was stolen — it was granted.
Recommended fix: Restrict application registration to administrators, and require admin consent for applications requesting access to data.
Medium 1 third-party application has access to SharePoint and OneDrive content
These hold organisation-wide access to files, and read what they can reach. That is the same content the rest of this report assesses for over-sharing, reached by something that does not appear in any sharing list.
Recommended fix: Confirm each application is still in use and still supplied by who you think it is. Remove the ones that are not.
Medium 1 application carries no publisher details in Entra
Entra records no verified publisher for these, so who supplied them cannot be confirmed from the tenant alone. That is not an accusation: publisher verification is optional, and reputable vendors — particularly ones sold through IT providers rather than direct — routinely skip it. Applications built in-house never have it at all. The point is that each of these holds broad access and Entra cannot tell you who stands behind it, so somebody has to.
Recommended fix: Name the supplier and the internal owner for each. Recognising the vendor is enough; the ones to worry about are those nobody can account for.
Low 2 applications have held access for more than 2 years
Consent does not expire. These were approved at some point, for some reason, and have held their access ever since — through staff changes, supplier changes and system replacements. Long-lived access is not wrong; long-lived access nobody has reviewed is how an estate accumulates doors that nobody remembers fitting.
Recommended fix: Add an annual review of consented applications. Anything without a current owner and a current reason should be removed.
Info 1 control has been marked as covered elsewhere or not applicable
Somebody has reviewed these and decided they are handled by another product or do not apply. That is a legitimate answer, and they are listed here only so the decision is visible rather than invisible.
Recommended fix: Worth confirming the third-party product named is still in place, since these decisions outlive the arrangements that prompted them.
Critical 1 domain has no DMARC record, so anybody can send email as this organisation
Without DMARC, a receiving mail server has no instruction about what to do with a message that claims to come from this domain but did not. Most will deliver it. That is how a supplier receives an invoice from the finance director's address with different bank details on it, and how staff receive a request from the managing director that the managing director never sent. The forged message is not a copy of the domain — it is the domain.
Recommended fix: Publish a DMARC record starting at p=none to see who is currently sending as you, then move to p=quarantine and p=reject once the legitimate senders are accounted for. It is a DNS change and costs nothing.
High DMARC is published but set to take no action on 1 domain
A policy of p=none means forged mail is reported and then delivered anyway. This is the correct place to start and the wrong place to stop, and it is where most organisations stop — the record exists, the box is ticked, and nothing is being blocked. Anyone checking whether this domain is protected will be told it is.
Recommended fix: Review the DMARC reports for legitimate senders that would fail, fix those, then move the policy to quarantine and finally to reject.
Medium DKIM signing is not configured for 1 domain
DKIM adds a signature that survives forwarding, where SPF does not. Without it, legitimate mail that has been forwarded — through a mailing list, or a client's own rules — can fail checks and be treated as forged. This becomes the reason DMARC enforcement gets rolled back after complaints.
Recommended fix: Enable DKIM for these domains in the Microsoft 365 Defender portal and publish the two CNAME records it gives you. Do this before moving DMARC to reject.
Critical 20 files shared via anonymous "anyone with the link" links
Anonymous links bypass identity entirely — anyone holding the URL can open the file, and the link can be forwarded outside the organisation without leaving a trace. Nothing records who has it, so there is no way to answer who has seen a file, and no way to withdraw it from one person without breaking the link for everybody.
Recommended fix: Disable anonymous link creation at the tenant/site level and expire existing anonymous links. Replace with specific-people or company-wide links where sharing is genuinely needed.
High 36 files shared org-wide ("Everyone")
Company-wide sharing means every member of staff can open these files, whether or not that was ever the intention. Sharing set up for convenience is rarely revisited once it works. It is also a common cause of Copilot answering from something it should not have.
Recommended fix: Review org-wide shares and scope them to the owning department or a security group. Start with the sites holding finance, HR or customer material.
High The tenant permits anonymous "anyone with the link" sharing
This setting is why 20 files in this scan are reachable by anybody holding a URL, with no sign-in and no record of who opened them. Those files can be fixed one by one, but while the setting stands the next person to press Share will create more.
Recommended fix: Restrict sharing to guests who sign in, so that access is attributable and can be withdrawn. Where anonymous links are genuinely needed, set an expiry on them.
High 14 guest accounts over a year old
Long-lived guest accounts are rarely reviewed and often outlast the project they were invited for, leaving standing external access to your content.
Recommended fix: Run an access review of external guests and remove those no longer needed. Enable Entra access reviews to recertify guests on a schedule.
High 2 workspaces with no owner
Ownerless sites and Teams have nobody accountable for their content, access or lifecycle. They accumulate risk silently and are a common audit finding.
Recommended fix: Assign at least two owners to every workspace. Use an ownerless-group policy so Microsoft 365 prompts members to take ownership automatically.
High Sharing defaults to the widest option rather than the narrowest
When somebody presses Share, the link they are offered first is one that works for more people than they probably intend. Most sharing is done quickly and accepts whatever is offered, so this single setting shapes most of what ends up over-shared.
Recommended fix: Change the default to specific people. Anyone who needs a wider link can still choose one; they will simply have to mean it.
Medium 79 files not modified in over 2 years
Of these, 26 are more than 4 years old. Superseded documents do not announce themselves — they sit in search looking identical to the current version and get quoted in good faith. Anything reading the library, staff and Copilot alike, treats them as current.
Recommended fix: Archive or move superseded content out of active libraries, or apply a retention or archive label so it can be scoped out of search. Establish a review-by date for key documents.
Medium 53 duplicate copies across 21 sets of identical files
The most duplicated file exists in 6 places. When the same content lives in several locations nobody can tell which one is authoritative — including the people relying on it, and any search or assistant reading across them.
Recommended fix: Consolidate to a single source of truth and replace copies with links. Prioritise duplicate sets that span multiple sites or departments.
Medium 49 poorly named files
Generic and versioned names ('Document1', 'Copy of…', 'FINAL v3') carry no meaning to search. If someone cannot find a document by name they recreate it, which is how duplicate sets start. The same missing signal makes search return the wrong file.
Recommended fix: Adopt a naming convention and rename the worst offenders. Encourage descriptive titles and use metadata columns instead of encoding version/status into the filename.
Medium 1 SharePoint site inactive for 12+ months
Abandoned sites still hold their data and still appear in search, long after anyone stopped maintaining them. They widen the surface that has to be secured and reviewed, and they are where content nobody has looked at in years quietly stays reachable.
Recommended fix: Confirm ownership, archive or delete abandoned sites, and set an inactivity policy so they are caught automatically in future.
Medium Anonymous links never expire
A link shared for one afternoon keeps working indefinitely. Nobody revisits them, so the set of live anonymous links only ever grows, and each one outlives the reason it was created.
Recommended fix: Set an expiry — 30 days suits most work. Existing links are unaffected, so this stops the problem growing rather than fixing what is already there.
Low 2 Teams with no recent activity
Inactive Teams keep their SharePoint document libraries live and indexable long after the work has stopped.
Recommended fix: Archive dormant Teams to freeze their content while preserving it for reference.
Low 2 workspaces with only one owner
A single owner is a continuity risk — if they leave, the workspace becomes ownerless.
Recommended fix: Add a second owner to each of these workspaces.
Info 18 guest accounts in the tenant
Guests make up 9% of all accounts. Each is an identity outside the organisation that can hold access to sites and files, and that nobody inside manages day to day.
Recommended fix: Confirm every guest is still required and governed by expiry / access-review policies.
Info Sensitivity-label scheme in place (3 labels)
A label taxonomy is published, which is what every other protection keys off. Per-file label adoption could not be measured with read-only Graph access in this scan.
Recommended fix: Confirm auto-labelling is applied to high-risk libraries (HR, Finance, Legal), and enable SharePoint Advanced Management or Purview reporting to measure coverage.
High 69 people are licensed for device management, and 14 devices are enrolled
Device management is included in the subscriptions this organisation already holds. Where a device is not enrolled, none of it applies: company data on that machine cannot be protected, wiped if it is lost, or held to any standard. This is capability that is already paid for and is not being used.
Recommended fix: Enrol company devices in Intune, starting with laptops that hold or access company data. No additional licence is needed — the entitlement is already there.
High 15 licences paid for and assigned to nobody
These subscriptions are being billed in full every month regardless of whether anyone holds them. Keeping a seat or two spare for a new starter is sensible; beyond that it is a standing cost with nothing behind it. The most common cause is somebody leaving and the licence never being released.
Recommended fix: Review each subscription against current headcount and reduce the quantity at the next billing date, keeping a small buffer for new starters. Your Microsoft partner or the Microsoft 365 admin centre can adjust the counts.
Medium 2 enrolled devices fail the organisation's own policy
These devices are enrolled but do not meet the rules this organisation has itself set — commonly a missing update, disabled encryption, or no screen lock. A device failing policy is usually a device that has drifted rather than one that was never set up.
Recommended fix: Review the failures by reason in the Intune admin centre. Most resolve by bringing the device up to date rather than by changing any policy.
Medium 2 devices have not checked in for over 30 days
An enrolled device that has stopped contacting Intune is managed on paper only. It will not receive policy, will not report its state, and cannot be wiped remotely if it is lost. The usual causes are a machine that has been retired without being removed, or one that has quietly fallen out of management.
Recommended fix: Retire devices that are genuinely gone so the estate reflects reality, and investigate any that should still be in use.
Low Microsoft 365 Business Premium already includes device and identity protection
61 users hold Microsoft 365 Business Premium, which entitles this organisation to capabilities that are frequently bought again elsewhere or simply left switched off — device management, conditional access and information protection among them.
Recommended fix: Before considering additional security products, confirm which of these are actually switched on. Turning on something already paid for is the cheapest security improvement available.
High 10 intranet pages not updated in over 2 years
Outdated pages make an intranet feel abandoned, and staff stop checking it — which is usually when people start keeping their own copies instead. Search and Copilot both cite the content as though it were current.
Recommended fix: Assign page owners and a review-by date, refresh or retire stale pages, and consider page-level expiry on time-sensitive content.
Medium 1 active site with no published landing page
These sites hold real content but present visitors with a bare document library instead of a modern page with navigation, news and context — a poor front door.
Recommended fix: Add a modern home page to each active site with clear navigation, key links and an owner. Use a site template to make this consistent.
Low 2 pages stuck in draft
Draft pages are invisible to visitors — someone started them but never published. They clutter authoring views and represent unfinished intranet work.
Recommended fix: Review draft pages: publish the ones that are ready and delete the abandoned ones.
High Sign-in protection is not enforced, and Copilot raises what an account is worth
A compromised account currently gives an intruder whatever that person can reach, if they know where to look. With Copilot it gives them a research assistant over the same material. The account becomes a more valuable target without becoming better defended.
Recommended fix: Enforce multi-factor authentication before rollout rather than after.
Low 38 people work in Teams and documents daily — the natural first group
Of 52 licensed users active in the last 30 days, these also work across Teams and files, which is the material Copilot draws on. Starting with people who already collaborate is what makes a pilot look successful; starting with everyone is what makes it look expensive. A further 17 licensed 17 accounts have shown no activity at all, which is worth resolving before adding anything to them.
Recommended fix: Pilot with this group first and measure it before widening. Copilot is charged per user per month, so who goes first is a cost decision as much as a technical one.
Next steps
The findings above are in priority order, each with the reasoning behind it. You are free to work through the list yourself or hand it to your existing IT provider — it is yours either way. If you would rather we carried out the remediation, Innova Group can do that and re-scan afterwards so you can see exactly what changed. Where there is nothing meaningful to fix, we will tell you that instead.