it-service@brocent.com
Microsoft 365 Security
Tenant security posture, conditional access, email threat protection, external sharing, data retention and licence utilisation for the August 2026 reporting period.
Identity controls are strong; sharing and retention need decisions
Tenant secure score reached 74% of the applicable maximum, up eight points in the period, driven by completing multi-factor enrolment and blocking legacy authentication protocols. Conditional access now covers every staff account with device compliance and location conditions, and no user-level policy exclusion remains.
Two governance gaps need a client decision rather than technical work. Eleven SharePoint and OneDrive links are shared with anyone who has the URL, four of them to folders containing investor material; and no retention policy is applied to Teams chat, which means chat evidence is deleted on the platform default rather than on a schedule the firm has chosen. Email protection blocked 1,284 malicious messages in the period with no confirmed delivery of a phishing payload.
Tenant position at period end
Secure score is expressed against the maximum achievable on the licences held, not the absolute Microsoft maximum, so it is comparable period to period without being distorted by features the firm does not own.
Four items require action
Evidence. Eleven "anyone with the link" links exist across SharePoint and OneDrive; three were created in the period. Four point to folders under the investor-relations site, and two of the eleven have no expiry date.
Impact. Anonymous links are transferable and untraceable: anyone who receives the URL, including a forwarded copy, can read the content without authenticating. For investor material this is a confidentiality and regulatory exposure.
Recommendation. Restrict anonymous links tenant-wide to the marketing site only, force a 30-day expiry, and convert the four investor links to named external guests with view-only access.
Evidence. Mailboxes and SharePoint carry a seven-year retention policy. Teams chat and channel messages carry none, so they follow the platform default and are not preserved on a defined schedule.
Impact. Business discussion now happens in chat as often as in email. Without retention the firm cannot demonstrate a records policy over that channel, and cannot reliably produce chat evidence in a dispute or regulatory request.
Recommendation. Apply the seven-year retention policy to Teams chat and channels to match email, and record the decision in the records-management note. This requires a client decision on retention period, not technical work.
Evidence. Two inbox rules forward a copy of selected messages to an external accountant's domain. Both were created in 2024 with client approval; neither has been reviewed since, and the tenant-wide automatic-forwarding block carries an exception for them.
Impact. External forwarding is the standard exfiltration route after an account compromise. A standing exception weakens an otherwise effective control and is a routine due-diligence question.
Recommendation. Replace both rules with a shared mailbox the accountant accesses as a named guest, then remove the forwarding exception entirely.
Evidence. Nine guest identities hold access to one or more Teams. Three have not signed in since May 2026: a former auditor, a fund administrator contact who has changed role, and a design agency contact.
Recommendation. Remove the three dormant guests and enable quarterly guest access review so removal happens by policy rather than by inspection.
Basic authentication and legacy protocol access were blocked on 2026-08-07 after the last dependent scanner workflow was migrated. This closed the July finding, removed 184 password-spray attempts from reaching authentication, and contributed five points of the secure-score improvement.
Five of five service levels met
| Committed service level | Target | Actual | Status | Note |
|---|---|---|---|---|
| Conditional access coverage | 100% of staff | 100% | MET | No user-level exclusions |
| Secure score | ≥ 70% | 74% | MET | Against licensed maximum |
| Phishing report triage | ≤ 4 hours | 1.1 h avg | MET | 14 user reports triaged |
| Tenant config change control | 100% recorded | 100% | MET | 7 changes, all ticketed |
| Monthly report issued | By 5th working day | 3rd working day | MET | Issued 2026-09-03 |
Three-period movement
| Metric | Jun 2026 | Jul 2026 | Aug 2026 | Direction of travel |
|---|---|---|---|---|
| Secure score | 61% | 66% | 74% | Rising; the remaining points need client policy decisions. |
| Malicious mail blocked | 998 | 1,172 | 1,284 | Volume rising with sector-wide campaigns; block rate holding. |
| User phishing reports | 9 | 11 | 14 | Increasing reporting is a positive signal, not a threat signal. |
| Anonymous sharing links | 6 | 8 | 11 | Growing each period — needs a tenant-level restriction. |
| External guests | 12 | 11 | 9 | Falling as dormant guests are removed. |
| Workloads without retention | 2 | 2 | 2 | No movement; Teams chat and channels still uncovered. |
Data and retention is the weakest area and accounts for most of the gap to a 90% score. Both open findings sit in that area, and both are client decisions.
Conditional access policies
| Policy | Applies to | Condition | Control | State | Exclusions |
|---|---|---|---|---|---|
| Require MFA for all users | All staff | Any location | MFA | ON | Break-glass only |
| Block legacy authentication | All accounts | Legacy clients | Block | ON | None |
| Require compliant device | All staff | Desktop clients | Compliance | ON | None |
| Block sign-in outside HK/CN | All staff | Named locations | Block | ON | 3 travel exemptions |
| Require MFA for admins | 5 privileged | Any location | MFA + PIM | ON | None |
| Session limits on unmanaged | All staff | Browser only | No download | ON | None |
| Block high-risk sign-in | All staff | Risk = high | Block | REPORT | Pending enforcement |
The high-risk sign-in policy is deliberately in report-only mode for one further period to confirm no legitimate workflow is blocked; enforcement is scheduled for 2026-09-15.
Email threat protection
| Category | Count | Delivered | Note |
|---|---|---|---|
| Phishing blocked | 742 | 0 | Mostly credential-harvest pages impersonating the tenant login. |
| Malware blocked | 96 | 0 | Attachment-based; all quarantined at the gateway. |
| Spam / bulk blocked | 446 | — | Routine volume; no user complaints of false positives. |
| Impersonation attempts | 18 | 2 | Two low-confidence CEO-impersonation mails reached inboxes; both reported by users and removed within the hour. |
| Safe-link clicks blocked | 27 | — | Users clicked; the link was detonated and blocked at time of click. |
| User-reported messages | 14 | — | 11 confirmed malicious, 3 benign. Mean triage 1.1 hours. |
Sharing, guests and retention
| Item | Count | Status | Note |
|---|---|---|---|
| Anonymous links — investor site | 4 | ACTION | Convert to named guests with view-only access. |
| Anonymous links — other sites | 7 | REVIEW | Two without expiry; apply a 30-day default. |
| External guests active | 6 | OK | Fund administrator, auditor, legal counsel, two agencies. |
| External guests dormant | 3 | REMOVE | No sign-in since May 2026. |
| Retention — mail and SharePoint | 7 yrs | APPLIED | Immutable hold; matches the records policy. |
| Retention — Teams chat and channels | None | GAP | Platform default only — see finding. |
| Data-loss policies active | 3 | OK | HKID, bank account and passport patterns; 4 blocks, no overrides. |
Open items carried between periods
| Ref | Risk | Severity | Owner | Due | Status | Next action |
|---|---|---|---|---|---|---|
| M365-R01 | Anonymous sharing of investor material — untraceable read access | HIGH | Client IT + BCS | 2026-09-30 | Open | Restrict anonymous links tenant-wide; convert 4 links to named guests. |
| M365-R02 | No retention over Teams chat — records policy not demonstrable | HIGH | Client COO | 2026-09-30 | Open | Client to confirm retention period; BCS to apply the policy. |
| M365-R03 | Standing external forwarding exception — weakens exfiltration control | MEDIUM | BCS Support Center | 2026-10-31 | Open | Replace with guest access to a shared mailbox; remove the exception. |
| M365-R04 | High-risk sign-in policy not enforcing — report-only mode | MEDIUM | BCS Support Center | 2026-09-15 | In progress | Switch to enforce after the final report-only review. |
| M365-R05 | No guest access review cycle — removal relies on inspection | LOW | BCS Support Center | 2026-10-31 | Open | Enable quarterly guest access review with the ops lead as approver. |
Next period commitments
| BCS Support Center will | Client is asked to |
|---|---|
| Restrict anonymous links and apply a 30-day expiry default. | Confirm the retention period for Teams chat and channel messages. |
| Enforce the high-risk sign-in policy on 2026-09-15. | Approve conversion of the four investor links to named guest access. |
| Remove the three dormant guests and enable quarterly guest review. | Confirm the accountant's continued need for message copies. |
| Report secure score by control area each period against the licensed maximum. | Nominate the approver for quarterly guest access reviews. |
How this report was produced
| Source | Extracted | Records | Used for |
|---|---|---|---|
| Secure score export | 2026-09-01 02:05 HKT | 5 areas | Score by control area against the licensed maximum. |
| Conditional access export | 2026-09-01 02:10 HKT | 7 policies | Policy state, conditions, exclusions. |
| Defender for Office 365 | 2026-09-01 02:40 HKT | 31 days | Blocked mail by category, safe-link clicks, user reports. |
| SharePoint sharing report | 2026-09-01 03:10 HKT | 11 links | Anonymous link inventory and expiry state. |
| Purview retention and DLP | 2026-09-01 03:20 HKT | 3 policies | Retention coverage by workload; DLP matches and overrides. |
| Licence assignment report | 2026-09-01 | 40 seats | Assigned versus purchased seats. |
Method and definitions
Secure score is stated as a percentage of the maximum achievable on the licences the firm holds. Microsoft's own headline figure includes controls that require higher-tier licensing, which makes it look artificially low and is not comparable period to period; this report never uses that figure.
Blocked mail counts messages stopped before or at delivery. A message delivered and later removed by automated purge is reported as delivered, because for a period of time it was reachable by the user.
Anonymous link is any sharing link that grants access without authentication, regardless of whether it is view-only or editable, and regardless of expiry.
Exclusions. Account lifecycle and MFA enrolment detail are reported in the Account Management report; entitlement detail inside SharePoint sites is reported in the quarterly Access & Permission Review. Endpoint compliance is reported in the Configuration Management report.
This copy is an anonymised sample prepared for illustration. The client name, tenant name, site names, user identifiers and third-party organisations have been replaced with fictitious or generic values; counts, ratios, dates and findings reflect a representative managed tenant. No real client data appears in this document.
BCS Support Center · it-service@brocent.com
Questions clients ask about this report
As a percentage of the maximum achievable on the licences the tenant actually holds. Microsoft's headline figure includes controls that require higher-tier licensing, which makes any tenant look worse than it is and is not comparable period to period.
Anonymous sharing links that never expire, no retention policy over Teams chat, standing external mail-forwarding exceptions, and dormant guest accounts. All four appear in the sample report on this page.
No. Tenant security posture is reported here; protection of tenant data is reported in the Backup and Recovery report, so the same control is never counted twice.
See what your own Microsoft 365 Security report would say
A free IT health check produces a first version of this report against your real estate, at no cost and with no obligation. It takes about a week and needs a few hours of your team’s time.