Home / Blog / MSP
MSP

The Microsoft 365 security assessment checklist for MSPs

EntraGUARD·2026-07-21·9 min

Security assessments are one of the easiest services for an MSP to sell and one of the hardest to deliver profitably. The economics only work if the assessment is standardised, repeatable and largely automated. Here is the checklist, and how to turn it into a service that scales past a handful of clients.

Why most MSP assessments do not scale

The first assessment goes fine. You know the client, you spend two days in the admin portals, you write a decent report and the client is happy. The tenth one is where it breaks down: every assessment is slightly different, the findings depend on who did the work, the report takes as long to write as the review took to run, and nobody can tell whether client A is genuinely in better shape than client B because they were assessed differently.

Three constraints have to be satisfied for this to be a real service line: consistency across clients and across technicians, speed, so the labour cost does not eat the margin, and a deliverable the client will act on rather than file.

The checklist

Organised by where the risk actually concentrates, not by which portal you happen to be in.

Identity and access — Entra ID

On-premises Active Directory

Skip this and your assessment covers half the estate. For any client with a domain:

Azure

Collaboration and mail

Logging and evidence

Turning the checklist into a service

Standardise before you scale

Define one assessment methodology and apply it to every client. The moment two technicians assess differently, your comparisons across the client base become meaningless and your reports stop looking like a product. Anchor the methodology to a recognised framework — CIS benchmarks are the natural fit for Microsoft environments — so findings carry an external reference rather than your technician's opinion.

Allow for per-client variation, deliberately

Clients differ. Some do not use a service at all; some have a control that is genuinely out of scope; others have requirements stricter than the standard. Handle this with a documented per-client baseline rather than ad-hoc judgement calls, so exclusions are visible in the report instead of hidden in someone's head. Custom baselines also stop irrelevant findings from burying the ones that matter.

Make the deliverable the product

The report is what the client pays for. It needs a score they can track over time, findings ranked by severity rather than listed by service, a remediation step for each one, and a framework reference so the recommendation is not just your say-so. White-labelling it with your own branding matters more than it sounds — it is your service, not a tool's output.

Sell the cadence, not the one-off

A single assessment is a transaction. The recurring version is the business: quarterly re-assessment, with the score trend as the proof of value. It also solves the awkward conversation where you deliver findings and never hear whether anything was fixed. When the next report shows the score moved from 54% to 78%, the value of the engagement is self-evident — and so is the case for renewing it.

Watch the read-only boundary

Assessment and remediation are different engagements with different risk profiles. Running an assessment that cannot modify a client tenant is both safer and easier to sell: you are not asking for write access to their production identity system to tell them what is wrong with it.

Realistic economics

The variable that decides whether this line is profitable is technician hours per assessment. Manual review across a dozen portals for a mid-sized tenant is a multi-day job, and multi-day jobs price the service out of reach for the small and mid-market clients most MSPs actually serve. Automating the data collection and report generation is what moves the assessment from a bespoke project to a repeatable deliverable — and lets you offer it to the whole client base rather than the top three accounts.

Audit your Microsoft environment

Put this into practice. EntraGUARD runs 283 automated controls across Entra ID, Active Directory and Azure — try the free demo.

Download the free demo