Cloud identity and email security

Microsoft 365 Security Review for Small Businesses

Your firewall can be working while an unexpected cloud session goes unnoticed. Wolex helps small businesses understand their Microsoft 365 identity and email controls, validate available evidence and give each improvement an owner. Start by email; scope and price are agreed before access or testing.

What to expect

Clear scope. Practical outcomes.

Every engagement begins with the current environment, business priorities and the evidence needed to make a defensible decision.

Identity and administrator access

Review agreed MFA coverage, administrator roles, sign-in methods and Conditional Access policies where licensing supports them. Document necessary exceptions and the business impact of proposed changes.

  • MFA and administrative account separation
  • Least-privilege role review
  • Legacy and device-code authentication needs
  • Emergency access and lockout considerations

Email and application access

Review agreed mailbox forwarding, inbox-rule monitoring, delegated access and third-party application permissions. Each observation is checked against legitimate business use before it becomes a recommendation.

  • External forwarding and mailbox rules
  • Application consent and granted permissions
  • Delegated mailbox access
  • Email protection policy coverage

Cloud evidence and response readiness

Confirm which sign-in and audit records are available, their retention period and who acts on alerts. A defined review can examine an agreed time window for unexplained account, device or mailbox changes.

  • Sign-in and device-registration evidence
  • Account and permission changes
  • Alert ownership and escalation
  • Evidence limits and follow-up questions

A report your provider can use

Receive an owner-friendly summary, the evidence supporting confirmed observations and a prioritized improvement plan. Changes, implementation assistance and any validation retest are priced and authorized separately unless included in the agreed scope.

  • Agreed scope and evidence coverage
  • Confirmed findings and unknowns
  • Business impact and technical next steps
  • Named owners and validation checks

Service guide

Details for an informed first conversation.

Useful scope, operating context and decision points for organizations evaluating this service.

Cloud access has its own evidence trail

A connection to a cloud mailbox or shared file can originate away from your office. That means an office firewall log may not show the activity you need to understand. A Microsoft 365 review looks at agreed cloud identity, email and audit controls alongside the way staff, administrators and applications actually use them.

An unfamiliar location or device is a reason to ask questions, rather than a verdict. Legitimate travel, remote access and incomplete device details can affect interpretation. Wolex validates available records with approved contacts, documents what the evidence supports and identifies what remains unknown.

A defined scope before access

The first email should explain what prompted the review: a customer requirement, an insurer questionnaire, an unexplained sign-in, a recent change or a routine check. We then agree on the tenant, relevant services, control areas, evidence window, authorized contacts, deliverables and price. No sensitive evidence is needed in that first inquiry.

Where suitable, customer-controlled exports or a supervised review can supply evidence without sharing credentials. Any reviewer permissions, retention period and access removal are documented before work begins. Tenant configuration changes are separately authorized; reviewing a policy does not grant approval to alter it.

Useful baselines with practical limits

CISA’s SCuBA project provides Microsoft 365 secure configuration baselines and ScubaGear assessment tooling. These can inform a scoped review, but an automated result still needs interpretation against licensing, business dependencies and approved exceptions. Wolex does not represent a baseline comparison as a compliance certificate or an assurance that compromise is impossible.

The outcome is a decision-ready list: confirmed gaps, controls supported by evidence, limitations and the next actions your provider can own. Oregon organizations in Beaverton, Hillsboro and the Portland metro can begin remotely by email. For immediate unauthorized access, use your incident-response contact rather than waiting for a routine assessment.

Frequently asked questions

Useful answers before we talk.

Is this included in the external Security Checkup?

No. The external checkup reviews authorized public domains and IP addresses without internal credentials. A Microsoft 365 review needs a separate scope covering cloud configuration and evidence, with access and price agreed in advance.

Do we need to send passwords or full logs by email?

No. Begin with your organization size, Microsoft 365 use and the question you need answered. Do not email passwords, MFA codes, tokens, configuration exports or unredacted logs. Customer-controlled evidence sharing or appropriately limited access is agreed after authorization.

Does this prove that we have not been hacked?

No. A review can assess agreed controls and available evidence. Missing records, retention limits and licensing can leave questions unresolved. Suspected active compromise requires a separately agreed investigation and containment process.

Can you work with our current IT provider?

Yes. Wolex can provide an independent review alongside your internal team or existing provider. Findings distinguish validated gaps, necessary exceptions and areas needing more evidence.

Next step

Find out who owns your cloud security controls.

Email a cloud review question