Do you need admin access? Will you break anything?
Read-only Global Reader + Entra ID audit logs. No changes during check. We run Get-* PowerShell, no Set-*. If we need to test restore, we restore to test library, not overwrite.
We already have an IT guy — will this offend him?
No — 70% of our checks are referred by IT guys who don't specialize in M365 security. We give them the fix list with PowerShell commands. Many become our partner for hardening.
How is this different from Microsoft Secure Score?
Secure Score is generic. We check POPIA evidence (audit log retention 1yr, DLP for SA ID numbers, BitLocker report, immutable backup proof) that Secure Score doesn't cover. Plus live forwarding + OAuth app review — the 2 ways SA SMEs get breached.
What if you find nothing?
You don't pay. Happens in ~8% of audits (usually companies already on Business Premium with hardening). You still keep the 12-page PDF as POPIA evidence that you checked — auditors love it.
Remote vs on-site?
Pretoria, Centurion, Midrand, JHB = we come on-site 2hrs. Anywhere else SA = Teams remote, same checks, same PDF + Loom same day.