Prepared for Melbrooke Ltd · melbrooke.onmicrosoft.com · 2026-08-18
33%
Passing
Significant gaps
Multiple high-severity controls are failing. Address the priorities below before enabling Copilot or broad collaboration.
166
Controls assessed
33%
Controls passing
13
High severity
46
Medium severity
59
Open gaps
Top priorities
What we foundNo all-users MFA Conditional Access policy and security defaults are off; MFA is not enforced tenant-wide.
Why it mattersWeak identity controls are the primary path to account takeover and lateral movement.
Recommended actionEnforce MFA for all users via Conditional Access (pilot in report-only first).
What we foundOne or more mail-flow rules set SCL -1, bypassing spam filtering for the listed senders/domains - a spoofable trust path.
Why it mattersGaps here are the front door for phishing, spoofing and malware delivery.
Recommended actionReview each bypass rule; remove it or replace with tightly-scoped, justified allow entries.
What we foundAuthenticated SMTP (SMTP AUTH) is enabled at the org level - a common MFA/Conditional-Access bypass.
Why it mattersGaps here are the front door for phishing, spoofing and malware delivery.
Recommended actionDisable SMTP AUTH org-wide and per-mailbox after migrating any dependent services.
What we foundNo Safe Attachments policy detonates malicious attachments.
Why it mattersGaps here are the front door for phishing, spoofing and malware delivery.
Recommended actionMaintain a Safe Attachments policy scoped to all recipients with action Block.
What we foundNo Safe Links policy protects users from malicious URLs.
Why it mattersGaps here are the front door for phishing, spoofing and malware delivery.
Recommended actionMaintain a Safe Links policy scoped to all recipients (requires Defender for Office 365).
Scope & basis
Read-only, point-in-time assessment against the Glow Cloud M365 Security Framework - a focused set of high-impact Microsoft 365 security controls in the domains shown. It is not an exhaustive review, and not a certification or accredited audit. Control-level evidence is available on request.
Disclaimer
Findings reflect tenant configuration at the scan date and the read-only data available to the assessment. They are provided for information only, do not guarantee security or regulatory compliance, and are not legal advice. Remediation and its implementation remain the client's responsibility.
Prepared by Glow Cloud SolutionsConfidential · 2026-08-18