B BROCENT
Brocent — Your Asia IT Team
BCS Support Center · Hong Kong
it-service@brocent.com
Monthly client report · 05 of 09

Microsoft 365 Security

Tenant security posture, conditional access, email threat protection, external sharing, data retention and licence utilisation for the August 2026 reporting period.

Client
Acme Capital Limited
Reporting period
2026-08-01 → 08-31
Issued
2026-09-03
Reference
M365-2026-08
Scope
1 tenant · 40 Business Premium
Sources
Entra ID, Defender, Purview
Prepared by
BCS Support Center
Classification
Confidential
01 · Executive summary

Identity controls are strong; sharing and retention need decisions

Tenant secure score reached 74% of the applicable maximum, up eight points in the period, driven by completing multi-factor enrolment and blocking legacy authentication protocols. Conditional access now covers every staff account with device compliance and location conditions, and no user-level policy exclusion remains.

Two governance gaps need a client decision rather than technical work. Eleven SharePoint and OneDrive links are shared with anyone who has the URL, four of them to folders containing investor material; and no retention policy is applied to Teams chat, which means chat evidence is deleted on the platform default rather than on a schedule the firm has chosen. Email protection blocked 1,284 malicious messages in the period with no confirmed delivery of a phishing payload.

Service verdict
On track
All five tenant service levels were met. No account compromise, no mail-flow rule created outside change control, and no data-loss policy in override. The sharing and retention items are tracked as M365-R01 and M365-R02.
02 · Key indicators

Tenant position at period end

Secure score
74%
▲ +8 pts
CA policy coverage
41 /41
▲ +2 vs Jul
Anonymous links
11
▼ +3 vs Jul
Workloads w/o retention
2
— unchanged
Malicious mail blocked
1,284
▲ +112 vs Jul
Risky sign-ins
3
▲ all benign
Licences assigned
38 /40
— 2 spare
External guests
9
▲ −2 vs Jul

Secure score is expressed against the maximum achievable on the licences held, not the absolute Microsoft maximum, so it is comparable period to period without being distorted by features the firm does not own.

03 · Key findings

Four items require action

Eleven anonymous sharing links are live, four to investor material
HIGH

Evidence. Eleven "anyone with the link" links exist across SharePoint and OneDrive; three were created in the period. Four point to folders under the investor-relations site, and two of the eleven have no expiry date.

Impact. Anonymous links are transferable and untraceable: anyone who receives the URL, including a forwarded copy, can read the content without authenticating. For investor material this is a confidentiality and regulatory exposure.

Recommendation. Restrict anonymous links tenant-wide to the marketing site only, force a 30-day expiry, and convert the four investor links to named external guests with view-only access.

Owner Client IT + BCS Target 2026-09-30 Ref M365-2026-08-01
No retention policy covers Teams chat or channel messages · carried forward (3 periods)
HIGH

Evidence. Mailboxes and SharePoint carry a seven-year retention policy. Teams chat and channel messages carry none, so they follow the platform default and are not preserved on a defined schedule.

Impact. Business discussion now happens in chat as often as in email. Without retention the firm cannot demonstrate a records policy over that channel, and cannot reliably produce chat evidence in a dispute or regulatory request.

Recommendation. Apply the seven-year retention policy to Teams chat and channels to match email, and record the decision in the records-management note. This requires a client decision on retention period, not technical work.

Owner Client COO Target 2026-09-30 Ref M365-2026-06-02
Two mailboxes forward externally under a legacy rule
MEDIUM

Evidence. Two inbox rules forward a copy of selected messages to an external accountant's domain. Both were created in 2024 with client approval; neither has been reviewed since, and the tenant-wide automatic-forwarding block carries an exception for them.

Impact. External forwarding is the standard exfiltration route after an account compromise. A standing exception weakens an otherwise effective control and is a routine due-diligence question.

Recommendation. Replace both rules with a shared mailbox the accountant accesses as a named guest, then remove the forwarding exception entirely.

Owner BCS Support Center Target 2026-10-31 Ref M365-2026-08-03
Nine external guests, three inactive for over ninety days
LOW

Evidence. Nine guest identities hold access to one or more Teams. Three have not signed in since May 2026: a former auditor, a fund administrator contact who has changed role, and a design agency contact.

Recommendation. Remove the three dormant guests and enable quarterly guest access review so removal happens by policy rather than by inspection.

Owner BCS Support Center Target 2026-10-31 Ref M365-2026-08-04
Closed this period · legacy authentication blocked tenant-wide
RESOLVED

Basic authentication and legacy protocol access were blocked on 2026-08-07 after the last dependent scanner workflow was migrated. This closed the July finding, removed 184 password-spray attempts from reaching authentication, and contributed five points of the secure-score improvement.

04 · Service level attainment

Five of five service levels met

Committed service levelTargetActualStatusNote
Conditional access coverage 100% of staff 100% MET No user-level exclusions
Secure score ≥ 70% 74% MET Against licensed maximum
Phishing report triage ≤ 4 hours 1.1 h avg MET 14 user reports triaged
Tenant config change control 100% recorded 100% MET 7 changes, all ticketed
Monthly report issued By 5th working day 3rd working day MET Issued 2026-09-03
05 · Trend

Three-period movement

MetricJun 2026Jul 2026Aug 2026Direction of travel
Secure score 61% 66% 74% Rising; the remaining points need client policy decisions.
Malicious mail blocked 998 1,172 1,284 Volume rising with sector-wide campaigns; block rate holding.
User phishing reports 9 11 14 Increasing reporting is a positive signal, not a threat signal.
Anonymous sharing links 6 8 11 Growing each period — needs a tenant-level restriction.
External guests 12 11 9 Falling as dormant guests are removed.
Workloads without retention 2 2 2 No movement; Teams chat and channels still uncovered.
Secure score by control area · % of licensed maximum
Identity
92%
Devices
86%
Email & collaboration
71%
Data & retention
48%
Apps
79%

Data and retention is the weakest area and accounts for most of the gap to a 90% score. Both open findings sit in that area, and both are client decisions.

06 · Detail data

Conditional access policies

PolicyApplies toConditionControlStateExclusions
Require MFA for all usersAll staffAny locationMFAONBreak-glass only
Block legacy authenticationAll accountsLegacy clientsBlockONNone
Require compliant deviceAll staffDesktop clientsComplianceONNone
Block sign-in outside HK/CNAll staffNamed locationsBlockON3 travel exemptions
Require MFA for admins5 privilegedAny locationMFA + PIMONNone
Session limits on unmanagedAll staffBrowser onlyNo downloadONNone
Block high-risk sign-inAll staffRisk = highBlockREPORTPending enforcement

The high-risk sign-in policy is deliberately in report-only mode for one further period to confirm no legitimate workflow is blocked; enforcement is scheduled for 2026-09-15.

Email threat protection

CategoryCountDeliveredNote
Phishing blocked7420Mostly credential-harvest pages impersonating the tenant login.
Malware blocked960Attachment-based; all quarantined at the gateway.
Spam / bulk blocked446Routine volume; no user complaints of false positives.
Impersonation attempts182Two low-confidence CEO-impersonation mails reached inboxes; both reported by users and removed within the hour.
Safe-link clicks blocked27Users clicked; the link was detonated and blocked at time of click.
User-reported messages1411 confirmed malicious, 3 benign. Mean triage 1.1 hours.

Sharing, guests and retention

ItemCountStatusNote
Anonymous links — investor site4ACTIONConvert to named guests with view-only access.
Anonymous links — other sites7REVIEWTwo without expiry; apply a 30-day default.
External guests active6OKFund administrator, auditor, legal counsel, two agencies.
External guests dormant3REMOVENo sign-in since May 2026.
Retention — mail and SharePoint7 yrsAPPLIEDImmutable hold; matches the records policy.
Retention — Teams chat and channelsNoneGAPPlatform default only — see finding.
Data-loss policies active3OKHKID, bank account and passport patterns; 4 blocks, no overrides.
07 · Risk register

Open items carried between periods

RefRiskSeverityOwnerDueStatusNext action
M365-R01 Anonymous sharing of investor material — untraceable read access HIGH Client IT + BCS 2026-09-30 Open Restrict anonymous links tenant-wide; convert 4 links to named guests.
M365-R02 No retention over Teams chat — records policy not demonstrable HIGH Client COO 2026-09-30 Open Client to confirm retention period; BCS to apply the policy.
M365-R03 Standing external forwarding exception — weakens exfiltration control MEDIUM BCS Support Center 2026-10-31 Open Replace with guest access to a shared mailbox; remove the exception.
M365-R04 High-risk sign-in policy not enforcing — report-only mode MEDIUM BCS Support Center 2026-09-15 In progress Switch to enforce after the final report-only review.
M365-R05 No guest access review cycle — removal relies on inspection LOW BCS Support Center 2026-10-31 Open Enable quarterly guest access review with the ops lead as approver.

Next period commitments

BCS Support Center willClient is asked to
Restrict anonymous links and apply a 30-day expiry default. Confirm the retention period for Teams chat and channel messages.
Enforce the high-risk sign-in policy on 2026-09-15. Approve conversion of the four investor links to named guest access.
Remove the three dormant guests and enable quarterly guest review. Confirm the accountant's continued need for message copies.
Report secure score by control area each period against the licensed maximum. Nominate the approver for quarterly guest access reviews.
Appendix · Method and definitions

How this report was produced

SourceExtractedRecordsUsed for
Secure score export 2026-09-01 02:05 HKT 5 areas Score by control area against the licensed maximum.
Conditional access export 2026-09-01 02:10 HKT 7 policies Policy state, conditions, exclusions.
Defender for Office 365 2026-09-01 02:40 HKT 31 days Blocked mail by category, safe-link clicks, user reports.
SharePoint sharing report 2026-09-01 03:10 HKT 11 links Anonymous link inventory and expiry state.
Purview retention and DLP 2026-09-01 03:20 HKT 3 policies Retention coverage by workload; DLP matches and overrides.
Licence assignment report 2026-09-01 40 seats Assigned versus purchased seats.

Method and definitions

Secure score is stated as a percentage of the maximum achievable on the licences the firm holds. Microsoft's own headline figure includes controls that require higher-tier licensing, which makes it look artificially low and is not comparable period to period; this report never uses that figure.

Blocked mail counts messages stopped before or at delivery. A message delivered and later removed by automated purge is reported as delivered, because for a period of time it was reachable by the user.

Anonymous link is any sharing link that grants access without authentication, regardless of whether it is view-only or editable, and regardless of expiry.

Exclusions. Account lifecycle and MFA enrolment detail are reported in the Account Management report; entitlement detail inside SharePoint sites is reported in the quarterly Access & Permission Review. Endpoint compliance is reported in the Configuration Management report.

Anonymisation notice

This copy is an anonymised sample prepared for illustration. The client name, tenant name, site names, user identifiers and third-party organisations have been replaced with fictitious or generic values; counts, ratios, dates and findings reflect a representative managed tenant. No real client data appears in this document.

Questions on this report
BCS Support Center · it-service@brocent.com
Brocent — Your Asia IT Team
Frequently asked

Questions clients ask about this report

How do you report Microsoft Secure Score fairly?

As a percentage of the maximum achievable on the licences the tenant actually holds. Microsoft's headline figure includes controls that require higher-tier licensing, which makes any tenant look worse than it is and is not comparable period to period.

What are the most common Microsoft 365 findings you report?

Anonymous sharing links that never expire, no retention policy over Teams chat, standing external mail-forwarding exceptions, and dormant guest accounts. All four appear in the sample report on this page.

Is Microsoft 365 backup included in this report?

No. Tenant security posture is reported here; protection of tenant data is reported in the Backup and Recovery report, so the same control is never counted twice.

Next step

See what your own Microsoft 365 Security report would say

A free IT health check produces a first version of this report against your real estate, at no cost and with no obligation. It takes about a week and needs a few hours of your team’s time.

Book a free IT health check Contact BCS Support Center