Vitals Assessment
A read-only review of your Microsoft 365 tenant — how content is shared and protected, how sign-in and devices are governed, what you are paying for and using, and whether you are ready for Copilot. Scored, with every finding in priority order and the reasoning behind it.
The Headline
Significant gaps. Content is reachable by people who should not reach it, and the environment needs work before more is built on it.
The Short Version
Kirkwell Industries Ltd scored 47.5 / 100 — Emerging. On the evidence below the environment needs substantial work. Access is wider than intended in several places and there is little to distinguish sensitive content from ordinary content.
The assessment reviewed 389 files across 8 sites and 200 users.
How to read this report
The sections that follow say what to do first: the priorities above, then the scores, then the evidence behind them. The findings section near the back is the reference — grouped by area and ordered by severity within each, so it can be worked through an area at a time or handed to whoever owns that area.
All 27 Dimensions
Ordered weakest area first. The count beside each dimension is how many items were flagged out of how many were examined.
What Was Found
Three public records decide whether somebody can send email in your name. SPF lists who may send, DKIM signs what they send, and DMARC is the only one that tells a receiving server to act on a forgery. A domain with the first two and not the third looks protected and is not.
| Domain | SPF | DKIM | DMARC | Policy in force |
|---|---|---|---|---|
| kirkwell-joinery.co.uk | ✓ | ✗ | ✗ | Anyone can send as this domain |
| kirkwell.co.uk | ✓ | ✓ | ● | Reported only — nothing is blocked |
Consent does not expire and is not tied to anybody's session, so none of this is affected by a password reset. Microsoft's own services are excluded. The question for each row is whether somebody can name it and say why it is still here.
| Application | Supplier | Files | Can change | Since | |
|---|---|---|---|---|---|
| Invoice Sync Helper | not recorded | ✓ | ✓ | — | Feb 2026 |
| Mail Signature Manager | Exclaimer Ltd verified | ✓ | — | ✓ | Sept 2023 |
| DocuSign | DocuSign Inc. verified | — | ✓ | — | May 2024 |
A tick under Mail or Files means organisation-wide access, not access to one person's account.
Of 5 administrators, 2 cannot. Those accounts can change anything in the tenant and are protected by a password alone. Registration is what a sign-in policy depends on: a requirement applied to people who cannot meet it produces exclusions, not protection.
The Question Everyone Asks
Copilot answers using whatever the person asking is already allowed to see. It does not widen access — it makes existing access easy to find by asking. So what decides readiness is not the technology, it is whether anything is sitting somewhere it should not be.
Already Paid For
Every subscription in this tenant, and how many are assigned to somebody. Capability that is already paid for is the cheapest improvement available — it needs switching on rather than buying.
| Subscription | Assigned | Bought | Spare |
|---|---|---|---|
| Microsoft 365 Business Premium | 61 | 68 | 7 |
| Microsoft 365 E3 | 8 | 12 | 4 |
| Visio Plan 2 | 2 | 6 | 4 |
Included with Microsoft 365 Business Premium, whether or not it is switched on:
3 personal or app sites excluded by design. OneDrive, Designer, Loop and similar are not part of a SharePoint readiness assessment.
My workspace, Designer, Loop
1 site could not be read
Real business sites blocked by an access policy. Worth an administrator confirming the restriction is intended: Board Confidential.
In Priority Order
The same findings as the reference section, arranged as work rather than as evidence. Nothing here is new — it is the order to do it in.
and 3 more — all listed in full in the findings section.
and 13 more — all listed in full in the findings section.
and 40 more — all listed in full in the findings section.
The Reference
The evidence behind the score, grouped by area and ordered by severity within each — what was found, why it matters, and the standard remedy. Meant to be worked through an area at a time.
Critical Nothing is protecting sign-in
Security defaults are switched off and no Conditional Access policy is enforced. Microsoft offers two ways to require multi-factor authentication and neither is in use, so a password on its own is currently enough to sign in as anybody here, from anywhere.
Recommended fix: If Conditional Access is licensed, use it — it is the more flexible of the two. If not, switch security defaults on. It is free, takes a minute, and is far better than nothing.
Critical External contact is possible and no policy requires a managed device
Any external organisation can start a Teams conversation with an employee here, and no enforced Conditional Access policy requires a managed device — 86% of devices report compliant. Microsoft has documented attackers using exactly this opening: a message that appears to come from IT support, a remote-support session the employee agrees to, and tooling run on the machine from there. Each part of that is legitimate behaviour, which is why no single setting in this report flags it. Nothing enforces multi-factor either, so the same conversation also yields credentials that work from anywhere.
Recommended fix: Require a compliant or hybrid-joined device for access to Microsoft 365 through Conditional Access. That single control is what makes the difference between a persuaded employee and a compromised organisation, because it constrains where a working session can be used rather than trying to prevent the conversation. Restricting who may start an external Teams chat to named partner organisations is worth doing as well, but on its own it only narrows the opening.
Critical 2 third-party applications can read mail across this organisation
These applications hold access to mailboxes for the whole organisation, granted once and not tied to anybody's session. A password reset does not affect them, revoking sign-ins does not affect them, and multi-factor authentication was never involved. Some will be tools somebody chose deliberately — a signature manager, a CRM, a backup product. The rest are how a consent-phishing attack keeps reading mail months afterwards.
Recommended fix: Review each one in Entra under Enterprise applications. Anything nobody can name and account for should have its permissions revoked today; the access does not lapse on its own.
Critical 2 administrators have no multi-factor method registered
These accounts can change anything in the tenant and are protected by a password alone. An administrator without multi-factor is the single most valuable target in the organisation and the least defended, and the credentials for it are worth buying rather than guessing.
Recommended fix: Register a method on these accounts today. Where one is a break-glass account kept deliberately outside the policy, it still needs a method registered, a long stored password and somebody watching it for use.
High Inferred 18 accounts have contact details that no longer allow a password reset
A mobile number or alternate address is recorded against these accounts, but was never registered as an authentication method. Since 7 September 2026 Microsoft no longer accepts directory contact details for self-service password reset. The people affected cannot tell: they can see their own number on their profile, and it will do nothing when they are locked out — which is exactly when they will find out, and when it becomes a call to somebody rather than a self-service reset.
Recommended fix: Run a registration campaign before these accounts need recovery rather than after. Microsoft can prompt people to register at next sign-in. Where the number really is the recovery route, it has to be registered as a method, not left as a profile field.
High 5 accounts rely on text message or phone call alone
Codes by text and voice call are better than a password on its own and are the weakest thing Microsoft still counts as multi-factor. A mobile number can be moved to an attacker's SIM by persuading the network to do it, which is a routine attack against anybody worth the effort, and it defeats both. At least one of these is an administrator.
Recommended fix: Move these to the Microsoft Authenticator app, which is free and works on any phone. Administrators should move first.
High No enforced policy requires multi-factor authentication
Conditional Access is in use, but nothing currently in force requires a second factor. A password on its own remains enough to sign in, which is the single most common way an account is taken over.
Recommended fix: Add a policy requiring multi-factor authentication, starting with administrators and then all users.
High Inferred Legacy authentication does not appear to be blocked
Older sign-in protocols cannot present a second factor, so they are the route around multi-factor authentication rather than through it. Where they remain available, an attacker will use them in preference to anything else.
Recommended fix: Add a policy blocking legacy authentication. Check for older devices or line-of-business applications that still rely on it before enforcing.
High 1 disabled account still holds administrative rights
A disabled account that retains Global Administrator is a re-enabled account away from full control of the tenant. Disabling is what happens when somebody leaves; removing the role is what should happen with it.
Recommended fix: Remove the administrative role from these accounts, then decide separately whether the account itself should still exist.
High 1 administrator account acquired a new sign-in method in the last 30 days
Registered since 25 July: 1 passkey. Each of these should be something the administrator remembers doing. A method registered against a privileged account by anybody else, at any hour, from anywhere, is the whole intrusion in one line of a log — and the log is where it stays unless somebody looks.
Recommended fix: Confirm each with the administrator concerned. Anything they cannot account for: remove the method, revoke the account's sessions, reset the password, and treat everything that account touched since the registration as suspect.
Hand-over document: The first hour: a sign-in method nobody can account for →
Medium Calculated Microsoft rates this tenant at 41.8% of its own security baseline
Secure Score is Microsoft's assessment of the tenant against its own recommendations — currently 214 points of 512 available. It is a useful independent measure precisely because it is not ours, and it is the number a customer can check for themselves at any time.
Recommended fix: Work through the highest-value controls first. The Microsoft 365 admin centre orders them by the points they carry, which broadly follows the risk they address.
Medium Registering a new sign-in method is protected only by a prompt the caller can talk someone through
"Require MFA to register security info" applies to registering security information, which is the right place for a policy, and it is enforced. What it asks for is the "Multifactor authentication" authentication strength, which the employee satisfies with the same Authenticator prompt they approve for everything else — and the attack this guards against begins with the employee approving prompts because a caller asked them to. It stops a stolen password from registering a method. It does not stop a persuaded person from doing so.
Recommended fix: Change the grant to require a phishing-resistant authentication strength, or a compliant device, or a trusted location. Any of those constrains where and with what a method can be added, which is the constraint a phone call cannot talk its way past. Keep a temporary access pass as the deliberate exception for people registering their first method.
Hand-over document: The first hour: a sign-in method nobody can account for →
Medium 21 accounts have no multi-factor method registered
Nothing is enforcing multi-factor on this tenant, and these accounts could not satisfy a requirement if one were introduced. That ordering matters: getting people registered first is what makes enforcement a switch rather than an incident.
Recommended fix: Run a registration campaign before enforcing anything. Microsoft can prompt people to register at next sign-in, which does the work for you.
Medium 11 accounts have no registered recovery method
Every one of these is a future call to whoever resets passwords, at a moment when the person cannot work. Self-service reset only removes that call for people who registered a method before they needed it.
Recommended fix: Enable registration prompting at sign-in and let the population close the gap on its own over a fortnight.
Medium 8 recommended controls are not in place
These are Microsoft's own recommendations for this tenant, and nothing has been recorded against them — neither implemented nor deliberately set aside. Many are settings rather than purchases, and a good number are covered by licences this organisation already holds.
Recommended fix: Review them by area. The identity ones usually give the largest improvement for the least work.
Medium Calculated 6 accounts hold full administrative control
A Global Administrator can do anything in the tenant, including granting themselves access to anybody's mailbox or files and removing the record that they did. Every one of these accounts is worth more to an attacker than any ordinary account, and the number tends to grow because adding one solves an immediate problem and removing one never does.
Recommended fix: Reduce to two or three named people. Where somebody needs to do one specific job, a narrower role usually exists for it — user administration, or helpdesk, rather than everything.
Medium 5 endpoint protection controls are not implemented
Microsoft's own assessment of this tenant reports these as unimplemented. They matter to this path specifically: once a remote-support session has been used to run something on a machine, endpoint detection is what turns an incident into an alert rather than into a discovery weeks later.
Recommended fix: Work through these in Microsoft's own order — they are ranked by effect, and the assessment behind them has already been done.
Medium 4 administrators hold no phishing-resistant method
These accounts can change anything in the tenant, and every method registered against them can be handed to an attacker by the person who holds it. A convincing sign-in page relays the code as it is typed; a stream of prompts gets one approved. Neither works against a security key, Windows Hello or a passkey, because those are bound to the site that issued them and produce nothing on a page that only looks like it.
Recommended fix: Issue a security key or enable Windows Hello for these accounts, then require phishing-resistant authentication for administrative roles through a Conditional Access authentication strength. Administrators are few enough that this is an afternoon, not a project.
Medium Guests can invite further guests
An external person who has been given access can invite other external people, who can invite more. Nobody inside the organisation approves any of it, and the resulting list is not one anybody is reviewing.
Recommended fix: Restrict invitations to administrators, or to a named group of people who understand what they are granting.
Medium Any user can register an application
Ordinary accounts can create applications that request access to company data. This is how consent-phishing works: the victim is asked to approve an app rather than to hand over a password, and multi-factor authentication does not help because nothing was stolen — it was granted.
Recommended fix: Restrict application registration to administrators, and require admin consent for applications requesting access to data.
Medium 1 third-party application has access to SharePoint and OneDrive content
These hold organisation-wide access to files, and read what they can reach. That is the same content the rest of this report assesses for over-sharing, reached by something that does not appear in any sharing list.
Recommended fix: Confirm each application is still in use and still supplied by who you think it is. Remove the ones that are not.
Medium 1 application carries no publisher details in Entra
Entra records no verified publisher for these, so who supplied them cannot be confirmed from the tenant alone. That is not an accusation: publisher verification is optional, and reputable vendors — particularly ones sold through IT providers rather than direct — routinely skip it. Applications built in-house never have it at all. The point is that each of these holds broad access and Entra cannot tell you who stands behind it, so somebody has to.
Recommended fix: Name the supplier and the internal owner for each. Recognising the vendor is enough; the ones to worry about are those nobody can account for.
Medium Temporary access passes can be used more than once
A temporary access pass is a complete sign-in on its own — no password, no second factor — issued so that somebody can register their first method. Set to be reusable, one pass read out over the phone lets the caller in as many times as they like until it expires, and an administrator may issue one that lives for 30 days.
Recommended fix: Set passes to one-time use with a default lifetime of an hour or less. Onboarding does not need longer; the pass is used once, at the desk, to register a passkey, and is then finished with.
Medium Text message can still be registered as a sign-in method
The methods a person can be persuaded to add are the methods the policy leaves open. A phone number is the easiest of all: it is registered in seconds, it survives a password reset, and the code it receives can be relayed by the person who holds it to anyone convincing enough to ask. Whoever is currently registered on one is reported under Multi-Factor Coverage; this is about closing the door for everyone else.
Recommended fix: Disable text message and voice in the authentication methods policy once the people relying on them have moved to the Authenticator app or a passkey — the registration campaign below does that work. Disabling the method does not lock anyone out who holds another.
Low 2 policies are in report-only mode
These were probably switched to report-only for testing. Left that way they record activity without preventing anything.
Recommended fix: Confirm whether each is still being evaluated, and enable or remove the ones that are not.
Low Calculated 2 applications have held access for more than 2 years
Consent does not expire. These were approved at some point, for some reason, and have held their access ever since — through staff changes, supplier changes and system replacements. Long-lived access is not wrong; long-lived access nobody has reviewed is how an estate accumulates doors that nobody remembers fitting.
Recommended fix: Add an annual review of consented applications. Anything without a current owner and a current reason should be removed.
Low 2 passwordless credentials issued to people by somebody else
Registered since 19 July: 2 temporary access passes. Passes and passkeys issued by an administrator are how new starters get going, so on their own these are routine. What makes them worth a glance is whether the issuer expected to be issuing them: a helpdesk account whose session has been taken over issues exactly the same passes.
Recommended fix: Check that each was raised through the normal joiner or reset process, and that the issuing accounts are the ones meant to be doing it.
Low Authenticator prompts do not show which application is asking or where the sign-in is coming from
A prompt that arrives while the caller is on the line, saying "approve this to finish setting up your passkey", is approved. The same prompt showing "Microsoft Graph — from Lagos" is refused, or at least questioned. The context costs nothing and is switched off by default.
Recommended fix: Enable application name and geographic location in the Microsoft Authenticator settings of the authentication methods policy.
Low People cannot report a prompt they did not ask for
Report suspicious activity puts a button on the prompt that the employee did not initiate. Pressing it marks the account high-risk and raises an alert. Without it, the first unexpected prompt is a shrug, the tenth is approved.
Recommended fix: Enable report suspicious activity in the authentication methods policy, and make sure somebody receives the resulting alert.
Low No registration campaign is nudging people to a stronger method
Microsoft can prompt people at sign-in to set up the Authenticator app, which is how a tenant gets off text messages without a project. It is off here, so the estate moves only as fast as somebody chases it.
Recommended fix: Enable the registration campaign in the authentication methods policy. A short snooze period and a modest daily prompt is enough.
Low The legacy multi-factor and password-reset policies still apply
Microsoft has three places a method can be permitted, and this tenant has not finished consolidating them into one. Until it does, a method disabled in the modern policy can remain allowed by the legacy one, and the settings reported here describe only part of what is in force.
Recommended fix: Complete the authentication methods migration in the Entra admin centre. Microsoft has announced the legacy policies are being retired; doing it deliberately beats having it done to you.
Info 1 control has been marked as covered elsewhere or not applicable
Somebody has reviewed these and decided they are handled by another product or do not apply. That is a legitimate answer, and they are listed here only so the decision is visible rather than invisible.
Recommended fix: Worth confirming the third-party product named is still in place, since these decisions outlive the arrangements that prompted them.
Info Calculated 1% of accounts hold a phishing-resistant method
Phishing-resistant methods are present but not yet the norm. The order that works is administrators first, then the people who handle payments and supplier details, then everybody — rather than a tenant-wide switch that generates enough exceptions to undo itself.
Recommended fix: Set a target of every privileged account on a phishing-resistant method, then extend by role rather than by percentage.
Info 1 passkey registered in the last 30 days
Passkeys are the right direction, and these are reported so that each can be recognised rather than because any is wrong. The attacks this dimension exists for end with a passkey being registered; an organisation that knows which passkeys it expected to see is the one that spots the extra one.
Recommended fix: Nothing to fix. Keep a habit of reviewing new passkey registrations weekly, which takes a minute in the audit log.
Info Not assessed Remote-support governance was not assessed
Whether Quick Assist is restricted, whether Remote Help is scoped to the helpdesk, and which third-party remote tools are permitted are not readable through the interface this assessment uses, so they form no part of the score above. They are the step the documented attacks actually turn on: the employee grants the session willingly.
Recommended fix: Answer three questions internally. Which remote-support tools are permitted, who is allowed to initiate a session, and how would an employee verify that the person asking really is the helpdesk. If the last one has no answer, that is the place to start.
Critical 2 mailbox rules send company mail to an outside address
Mail arriving in these mailboxes is copied or redirected to an address outside the organisation, automatically and without anybody being told. Some rules like this are legitimate — a person forwarding to their own second address, or to an accountant. The rest are how a compromised mailbox keeps paying out long after the password has been changed, and the two are indistinguishable from here. Each one needs an owner who recognises it.
Recommended fix: Ask each mailbox owner whether they created the rule. Anything nobody recognises should be removed, that mailbox's sign-in history reviewed, and its sessions revoked.
Critical 1 domain has no DMARC record, so anybody can send email as this organisation
Without DMARC, a receiving mail server has no instruction about what to do with a message that claims to come from this domain but did not. Most will deliver it. That is how a supplier receives an invoice from the finance director's address with different bank details on it, and how staff receive a request from the managing director that the managing director never sent. The forged message is not a copy of the domain — it is the domain.
Recommended fix: Publish a DMARC record starting at p=none to see who is currently sending as you, then move to p=quarantine and p=reject once the legitimate senders are accounted for. It is a DNS change and costs nothing.
High 1 mailbox rule deletes incoming mail automatically
These rules delete matching mail before the recipient sees it. Used honestly this is tidiness. Used dishonestly it is the second half of an invoice fraud: the rule quietly removes the replies querying the changed bank details, so the person being impersonated never learns of it and the conversation continues without them.
Recommended fix: Confirm each rule with the mailbox owner, paying particular attention to any keyed on words like invoice, payment, bank or the name of a supplier.
High DMARC is published but set to take no action on 1 domain
A policy of p=none means forged mail is reported and then delivered anyway. This is the correct place to start and the wrong place to stop, and it is where most organisations stop — the record exists, the box is ticked, and nothing is being blocked. Anyone checking whether this domain is protected will be told it is.
Recommended fix: Review the DMARC reports for legitimate senders that would fail, fix those, then move the policy to quarantine and finally to reject.
Medium DKIM signing is not configured for 1 domain
DKIM adds a signature that survives forwarding, where SPF does not. Without it, legitimate mail that has been forwarded — through a mailing list, or a client's own rules — can fail checks and be treated as forged. This becomes the reason DMARC enforcement gets rolled back after complaints.
Recommended fix: Enable DKIM for these domains in the Microsoft 365 Defender portal and publish the two CNAME records it gives you. Do this before moving DMARC to reject.
Info 1 rule of this kind is present but switched off
These rules would forward or delete mail if they were enabled. They are not, so nothing is happening today. They are listed because a rule that was switched off can be switched back on, and one nobody remembers writing is worth asking about now rather than later.
Recommended fix: Delete the ones nobody recognises. There is no cost to removing a rule that is doing nothing.
Critical Inferred 37 likely-sensitive files with no sensitivity label
Without a label these files carry no protection that travels with them — no encryption, no "do not summarise", and no DLP rule can act on them. Anything with access treats them like any other document, Copilot included.
Recommended fix: Run auto-labelling policies (or apply labels manually) to sensitive content. Consider a default label on high-risk libraries (HR, Finance, Legal).
Critical 20 files shared via anonymous "anyone with the link" links
Anonymous links bypass identity entirely — anyone holding the URL can open the file, and the link can be forwarded outside the organisation without leaving a trace. Nothing records who has it, so there is no way to answer who has seen a file, and no way to withdraw it from one person without breaking the link for everybody.
Recommended fix: Disable anonymous link creation at the tenant/site level and expire existing anonymous links. Replace with specific-people or company-wide links where sharing is genuinely needed.
Critical Inferred 9 likely-sensitive files over-shared
These files look like they hold personal, financial or HR data, and are reachable org-wide or anonymously. That combination is the one worth fixing first whatever else is going on — it is a live exposure today, not a risk that begins when something new is switched on.
Recommended fix: Restrict access and apply a sensitivity label to these before anything else on this list.
High 36 files shared org-wide ("Everyone")
Company-wide sharing means every member of staff can open these files, whether or not that was ever the intention. Sharing set up for convenience is rarely revisited once it works. It is also a common cause of Copilot answering from something it should not have.
Recommended fix: Review org-wide shares and scope them to the owning department or a security group. Prioritise anything flagged as containing sensitive information.
High The tenant permits anonymous "anyone with the link" sharing
This setting is why 20 files in this scan are reachable by anybody holding a URL, with no sign-in and no record of who opened them. Those files can be fixed one by one, but while the setting stands the next person to press Share will create more.
Recommended fix: Restrict sharing to guests who sign in, so that access is attributable and can be withdrawn. Where anonymous links are genuinely needed, set an expiry on them.
High Calculated 14 guest accounts over a year old
Long-lived guest accounts are rarely reviewed and often outlast the project they were invited for, leaving standing external access to your content.
Recommended fix: Run an access review of external guests and remove those no longer needed. Enable Entra access reviews to recertify guests on a schedule.
High 2 workspaces with no owner
Ownerless sites and Teams have nobody accountable for their content, access or lifecycle. They accumulate risk silently and are a common audit finding.
Recommended fix: Assign at least two owners to every workspace. Use an ownerless-group policy so Microsoft 365 prompts members to take ownership automatically.
High Sharing defaults to the widest option rather than the narrowest
When somebody presses Share, the link they are offered first is one that works for more people than they probably intend. Most sharing is done quickly and accepts whatever is offered, so this single setting shapes most of what ends up over-shared.
Recommended fix: Change the default to specific people. Anyone who needs a wider link can still choose one; they will simply have to mean it.
High Inferred 1 account synced far more files than the rest of the organisation
The typical person here synced 26 files to a device in the last 30 days. user61@kirkwell.co.uk synced 4,180 — 4,180 of the 5,773 files synced across the whole tenant. Syncing is how a library leaves the tenant in bulk: one click, every file, to whatever machine holds the session. A new starter setting up a laptop looks exactly like this. So does the first day of an intrusion. No enforced policy requires a managed device, so the machine it went to could be anyone's.
Recommended fix: Ask. Each of these is a person whose manager can say in a sentence whether that volume makes sense this month. Where it does not, revoke the account's sessions and check its sign-ins before anything else. Then require a compliant device for SharePoint and OneDrive, which turns the question from "who" into "which of our machines".
Medium 173 further files with no label
Where most content is unlabelled, data-governance controls cannot be applied with any precision — DLP, retention and any AI-access restriction all key off the label. Broad coverage is what makes the rest of it enforceable.
Recommended fix: Define a simple label taxonomy (e.g. Public / Internal / Confidential) and drive coverage up with auto-labelling.
Medium Calculated 79 files not modified in over 2 years
Of these, 26 are more than 4 years old. Superseded documents do not announce themselves — they sit in search looking identical to the current version and get quoted in good faith. Anything reading the library, staff and Copilot alike, treats them as current.
Recommended fix: Archive or move superseded content out of active libraries, or apply a retention or archive label so it can be scoped out of search. Establish a review-by date for key documents.
Medium Calculated 53 duplicate copies across 21 sets of identical files
The most duplicated file exists in 6 places. When the same content lives in several locations nobody can tell which one is authoritative — including the people relying on it, and any search or assistant reading across them.
Recommended fix: Consolidate to a single source of truth and replace copies with links. Prioritise duplicate sets that span multiple sites or departments.
Medium Inferred 49 poorly named files
Generic and versioned names ('Document1', 'Copy of…', 'FINAL v3') carry no meaning to search. If someone cannot find a document by name they recreate it, which is how duplicate sets start. The same missing signal makes search return the wrong file.
Recommended fix: Adopt a naming convention and rename the worst offenders. Encourage descriptive titles and use metadata columns instead of encoding version/status into the filename.
Medium Calculated 1 SharePoint site inactive for 12+ months
Abandoned sites still hold their data and still appear in search, long after anyone stopped maintaining them. They widen the surface that has to be secured and reviewed, and they are where content nobody has looked at in years quietly stays reachable.
Recommended fix: Confirm ownership, archive or delete abandoned sites, and set an inactivity policy so they are caught automatically in future.
Medium Anonymous links never expire
A link shared for one afternoon keeps working indefinitely. Nobody revisits them, so the set of live anonymous links only ever grows, and each one outlives the reason it was created.
Recommended fix: Set an expiry — 30 days suits most work. Existing links are unaffected, so this stops the problem growing rather than fixing what is already there.
Medium Inferred 1 account shared far more files externally than the rest of the organisation
The typical person here shared 1 file outside the organisation in the last 30 days. user9@kirkwell.co.uk shared 46. Sharing a file to an outside address is the other way an estate leaves quietly: nothing is downloaded, the link simply works from wherever the recipient is, and it keeps working after the account is cleaned up. Some roles do this all day. The question is whether these are those roles.
Recommended fix: Confirm the role. Where it does not fit, review what was shared and to whom in the SharePoint sharing reports, and remove the links that should not exist. The tenant-wide sharing defaults reported elsewhere decide how easily this can happen at all.
Low Calculated 2 Teams with no recent activity
Inactive Teams keep their SharePoint document libraries live and indexable long after the work has stopped.
Recommended fix: Archive dormant Teams to freeze their content while preserving it for reference.
Low 2 workspaces with only one owner
A single owner is a continuity risk — if they leave, the workspace becomes ownerless.
Recommended fix: Add a second owner to each of these workspaces.
Info 18 guest accounts in the tenant
Guests make up 9% of all accounts. Each is an identity outside the organisation that can hold access to sites and files, and that nobody inside manages day to day.
Recommended fix: Confirm every guest is still required and governed by expiry / access-review policies.
High Inferred 69 people are licensed for device management, and 14 devices are enrolled
Device management is included in the subscriptions this organisation already holds. Where a device is not enrolled, none of it applies: company data on that machine cannot be protected, wiped if it is lost, or held to any standard. This is capability that is already paid for and is not being used.
Recommended fix: Enrol company devices in Intune, starting with laptops that hold or access company data. No additional licence is needed — the entitlement is already there.
High Calculated 15 licences paid for and assigned to nobody
These subscriptions are being billed in full every month regardless of whether anyone holds them. Keeping a seat or two spare for a new starter is sensible; beyond that it is a standing cost with nothing behind it. The most common cause is somebody leaving and the licence never being released.
Recommended fix: Review each subscription against current headcount and reduce the quantity at the next billing date, keeping a small buffer for new starters. Your Microsoft partner or the Microsoft 365 admin centre can adjust the counts.
Medium 2 enrolled devices fail the organisation's own policy
These devices are enrolled but do not meet the rules this organisation has itself set — commonly a missing update, disabled encryption, or no screen lock. A device failing policy is usually a device that has drifted rather than one that was never set up.
Recommended fix: Review the failures by reason in the Intune admin centre. Most resolve by bringing the device up to date rather than by changing any policy.
Medium Calculated 2 devices have not checked in for over 30 days
An enrolled device that has stopped contacting Intune is managed on paper only. It will not receive policy, will not report its state, and cannot be wiped remotely if it is lost. The usual causes are a machine that has been retired without being removed, or one that has quietly fallen out of management.
Recommended fix: Retire devices that are genuinely gone so the estate reflects reality, and investigate any that should still be in use.
Low Microsoft 365 Business Premium already includes device and identity protection
61 users hold Microsoft 365 Business Premium, which entitles this organisation to capabilities that are frequently bought again elsewhere or simply left switched off — device management, conditional access and information protection among them.
Recommended fix: Before considering additional security products, confirm which of these are actually switched on. Turning on something already paid for is the cheapest security improvement available.
High Calculated 10 intranet pages not updated in over 2 years
Outdated pages make an intranet feel abandoned, and staff stop checking it — which is usually when people start keeping their own copies instead. Search and Copilot both cite the content as though it were current.
Recommended fix: Assign page owners and a review-by date, refresh or retire stale pages, and consider page-level expiry on time-sensitive content.
High 1 site is running a business process on retired technology
These sites hold form libraries — the shape of an application rather than a document store. Somebody built a form, connected it to a process, and the business has been running on it since. InfoPath, which is what these libraries were built with, has been out of support for years, and the classic surfaces around it are dated for read-only from October 2028. The risk is not the deadline. It is that nobody currently employed knows what the form does or what depends on its output.
Recommended fix: Find the owner and the process for each one now, while there is time to rebuild rather than react. Power Apps and Power Automate cover most of what these were built to do. Where nobody can say what a form is for, that is the answer — but confirm it before deleting it.
Medium 1 active site with no published landing page
These sites hold real content but present visitors with a bare document library instead of a modern page with navigation, news and context — a poor front door.
Recommended fix: Add a modern home page to each active site with clear navigation, key links and an owner. Use a site template to make this consistent.
Medium 1 site uses classic publishing and is still active
These sites keep their pages in a classic publishing library rather than in Site Pages, and 34 classic pages were found in them. Microsoft has set March 2027 and October 2028 as the milestones for classic page retirement, with affected pages becoming read-only for existing tenants in the later phase. Because these sites are in use, doing nothing means somebody discovers they cannot edit an important page, at short notice, without a plan.
Recommended fix: Work through them in order of use rather than in order of age. Most classic pages are a communication site and an afternoon; the ones that resist are the ones carrying custom code, and those are worth identifying early.
Low 2 pages stuck in draft
Draft pages are invisible to visitors — someone started them but never published. They clutter authoring views and represent unfinished intranet work.
Recommended fix: Review draft pages: publish the ones that are ready and delete the abandoned ones.
Low Calculated 1 classic site has not been touched in over two years
Classic markers, and no activity since before the retirement dates were announced. These are almost certainly finished work rather than live systems, and migrating them would be paying to move something nobody opens. They still carry whatever was shared out of them, which is the reason to close them rather than simply ignore them.
Recommended fix: Confirm there is no retention or legal obligation, export anything worth keeping, then archive or delete. This is the cheapest item on the list and it shrinks everything that follows.
Info Not assessed Custom script permissions were not assessed
Whether a site permits custom script is not readable through the interface this assessment uses, so it forms no part of the result above. It matters for the same sites: custom script is how most classic customisation was delivered, and it is what makes a migration hard rather than routine.
Recommended fix: Check the setting directly on the sites listed above before scoping any migration work, and disable it wherever nothing depends on it.
Critical Inferred 9 likely-sensitive files are readable across the organisation before Copilot is switched on
Copilot answers with whatever the person asking is already allowed to see. These files are already open to everyone; today that is only a risk if somebody goes looking. With Copilot, asking "what do we pay people?" or "what were the board's concerns?" is enough to find them, and it will answer honestly.
Recommended fix: Resolve the sharing on these before any Copilot rollout. This is the single most common reason an AI pilot has to be paused after launch rather than before.
High 2 third-party applications can already read the content Copilot would draw on
These applications hold standing consent to read files across the tenant. They were approved once, by somebody, at some point, and they do not require a person to be signed in to use it. Any governance decision taken about what Copilot may see is incomplete while these hold the same access with less visibility over what they do with it. 1 of them has an unverified publisher.
Recommended fix: Review each one against a named business owner and a reason. Remove consent where neither exists — an application nobody can account for is not one to leave reading everything. This review belongs in the same conversation as the Copilot rollout, not a separate one.
High Sign-in protection is not enforced, and Copilot raises what an account is worth
A compromised account currently gives an intruder whatever that person can reach, if they know where to look. With Copilot it gives them a research assistant over the same material. The account becomes a more valuable target without becoming better defended.
Recommended fix: Enforce multi-factor authentication before rollout rather than after.
Low Calculated 38 people work in Teams and documents daily — the natural first group
Of 52 licensed users active in the last 30 days, these also work across Teams and files, which is the material Copilot draws on. Starting with people who already collaborate is what makes a pilot look successful; starting with everyone is what makes it look expensive. A further 17 licensed 17 accounts have shown no activity at all, which is worth resolving before adding anything to them.
Recommended fix: Pilot with this group first and measure it before widening. Copilot is charged per user per month, so who goes first is a cost decision as much as a technical one.
Info Not assessed Web grounding governance was not assessed
Copilot and Copilot Chat answer from the public web as well as from this organisation's own content, and web grounding is on by default for every licensed person. Which sites it may draw on is decided in two places, neither of which this assessment can read: the "Allow web search in Copilot" policy, which says whether web grounding is on and for whom, and the domain exclusion list, which lets an administrator name up to a thousand sites Copilot must never cite. No tenant has an exclusion list unless somebody has deliberately created one, and both are readable only by a signed-in administrator.
Recommended fix: Answer three questions before the licences are bought. Is web grounding meant to be on, and for everyone or for named groups? Which sources should Copilot never cite — competitors, content farms, anything the organisation's own policies already bar? And has anyone configured the exclusion list? If the last answer is no, the list is empty, and every answer with a web citation in it can cite anything.
Hand-over document: Copilot web source policy — a one-page template →
Next steps
The findings above are in priority order, each with the reasoning behind it. You are free to work through the list yourself or hand it to your existing IT provider — it is yours either way. If you would rather we carried out the remediation, Innova Group can do that and re-scan afterwards so you can see exactly what changed. Where there is nothing meaningful to fix, we will tell you that instead.