Microsoft 365 security assessment sample report
The complete report, published.
Every section a paying customer receives, from a tenant built for the purpose. No form, no email address, nothing redacted. 31 pages, with the evidence rows under each finding.
This is a real Microsoft 365 security assessment report: the same format, the same 27 checks and the same scoring a paying customer receives, run against a tenant built for the purpose.
Kirkwell Industries Ltd is not a real company. The tenant, the staff and the findings are invented, and deliberately typical rather than a worst case.

What to look for in the sample
Three things worth checking, because they are what separate a report from a dashboard export.
Every finding names the evidence it was read from — the Microsoft data, not an assertion. Every finding says how it knows: observed, calculated, inferred, or not assessed. And the coverage page states what was not scanned, so anything unassessed is excluded from the score rather than quietly counted as a pass.
See how a finding is made →See all 27 Microsoft 365 checks →
What the document contains
In the order it arrives in.
The score, and what it means
One number out of 100 with the band it falls in, then six area scores — identity, email, data, licensing, workplace and Copilot — so a low score names the area that owns the problem rather than passing one verdict on everything.
Severity as a schedule
Critical, high and everything else, each with a timeframe against it: this week, this month, this quarter. The action plan is written in that order.
Evidence tables
Every domain against SPF, DKIM and DMARC. Every third-party application and what it can reach. Who can complete a multi-factor prompt. The narrative explains; the tables are what somebody works through.
A Copilot verdict
Ready, or not yet, with the blockers named. The sample says not yet and lists what would have to change first — considerably cheaper to establish before the licences are bought than after.
Every finding, in full
Grouped by area and ordered by severity within each, so the document can be worked through one area at a time or forwarded to whoever owns that area.
What was not scanned
How many sites were examined out of how many exist, and which checks did not run. Anything unassessed is excluded from the score rather than counted as a pass.
The same document, about your tenant
What you have just read is what arrives, with your own findings in it. Reports are delivered within three working days of access being approved.
Read about Vitals security and access first, or check Copilot readiness.

