MFA exceptions
2 users excluded from MFA policy.
Evidence: Identity policy review and user coverage audit.
Illustrative example
Fictional example for illustrative purposes. It shows the level of detail a completed assessment can provide without exposing real client information.
Executive summary
This sample report format documents observed state, supporting evidence, risk, and the next actions. It is designed to be readable by firm leadership and useful to the MSP or IT team carrying out the remediation.
MFA exceptions
2 users excluded from MFA policy.
Evidence: Identity policy review and user coverage audit.
DMARC
Monitoring only.
Evidence: DNS record review.
Privileged accounts
Shared admin account observed.
Evidence: Role export and sign-in review.
Audit logging
Enabled and retained.
Evidence: Tenant configuration review.
Remediation priorities
Immediate: remove MFA exceptions and separate privileged access.
30 days: move DMARC to enforcement and recheck sender inventory.
90 days: verify the resulting state and update the evidence file.
Next step
2 minutes. No internal access. No passwords.
Start with the free Zero-Access Exposure Review, then move into the Security Baseline if you need a defensible view of the controls your firm relies on.