Rolling out Copilot? Run this check first. It reads everything your staff can.

Security & governance

Microsoft 365 security, mapped to the file.

We map who can actually reach every file across SharePoint and OneDrive, trace every external share down to the recipient, and re-run it each quarter to track what changed. Interpreted by a named architect, read-only, and handed to you as a report you own - a config baseline included.

The Glow Cloud M365 Security Assessment has its own home. Full detail, sample reports and how it works live at glowcloudsecurity.com.

Visit glowcloudsecurity.com →

The permission & sharing deep-dive

Not "this setting is wrong". Who can reach which file, and how.

Most audits stop at a misconfiguration. We show you the consequence: every external share, every broken-inheritance file, and a visual map of who can reach which document, through which site and which library, and how they got there - including the access that stops at one library, or at one shared file. It is the oversharing Copilot would surface on day one - found before it does. Nothing else in this space visualises access like this.

Pick a person and see every site and library they can reach, how they got there, and every item where their access breaks from the site default:

RBAC relationship map · person view · read-only Melbrooke · sample
Full control Edit Read Limited (traversal) Dashed = direct grant · thickness = reach
PERSON SITES UNIQUE PERMISSIONS Colin Rathbone user · reaches 16 sites, 12 unique items Finance Full control · SP Owners HR Team Full control · SP Owners Executive Team Full control · Security group Compliance Full control · SP Owners IT Department Full control · direct Board Confidential Edit · SP Members Harwick Service Edit · SP Members Ketterby Service Edit · SP Members Bramfield Service Edit · M365 Members Dunmere Sales Edit · SP Members Ashwell Parts Edit · SP Members Calder Vale Service Read · SP Visitors Marketing Read · SP Visitors Health and Safety Read · SP Visitors Melbrooke Parts Limited · traversal only Ketterby Parts Limited · traversal only Asset Register 2026.xlsx File · access differs Payroll Contacts.xlsx File · access differs Job Title List.xlsx File · access differs Compliance Register.xlsx File · access differs Admin Runbook.docx File · access differs CRM Password Reset.pdf File · access differs Barcode Scanner.docx File · access differs Work Order Locks.pdf File · access differs Faster Entry Guide.pdf File · access differs Cisco Phone Restart.pdf File · access differs Warranty Password.docx File · access differs Unlocking Tickets.docx File · access differs
Site AdminM365 MembersSP OwnersSP MembersSP VisitorsSecurity groupDirect grant

One account's real reach: Colin Rathbone lands on 16 sites - mostly through group nesting, two by direct grant - and inside them, 12 files where his access breaks from the site default. This is what a leaver, a contractor, or a busy admin account can actually get to. Static sample; the live report is fully interactive.

Or turn it around and start from a site - every principal that reaches in, with default groups, site admins and direct grants told apart, and membership marked default where it is only inferred, not confirmed:

RBAC relationship map · site view · read-only Melbrooke · sample
Full control Edit Read Dashed = direct grant · thickness = reach
PRINCIPALS SITE UNIQUE PERMISSIONS Ashwell Service Site SP Owners Full · default · 5 scopes SP Members Edit · default · 5 scopes SP Visitors Read · default · 4 scopes Melbrooke_All_Admin Security group · 1 scope Site Admin M365 owners · any item Keith Bannerman Direct · 3 scopes · item-level Jasmine Rowe Direct · 3 scopes · item-level Nathan Aldous Direct · 3 scopes · item-level Martin Ackroyd Direct · 3 scopes · item-level Umar Siddiqui Direct · 6 scopes · item-level Zoe Harding Direct · 1 scope · item-level Salary Bands Folder · access differs Asset Register 2026.xlsx File · access differs Completed Forms Folder · access differs Admin Runbook.docx File · access differs CRM Password Reset.pdf File · access differs

Default = group membership inferred from the site's nesting, not independently confirmed. Everything routes through the site (it is on the access path); the right column breaks inheritance from it. Static sample; the live report is fully interactive.

  • Per-user access report: pick a person, see everything they can reach and exactly how, via which group or direct grant. The reverse-lookup a config scan cannot produce.
  • Compare two users: a new hire against their predecessor, or two peers, shared access and what each has that the other does not.
  • A discrepancies audit: over-permissioned users, oversized groups, direct grants, external access and broken-inheritance debt, surfaced as the headline.

Interactive sample

See it for yourself. It's live.

Pick a person and see everything they can reach. Map a site, compare two users, drill into every discrepancy. The full report on sample data, nothing to install.

Run one is the full map. Re-run it each quarter on the retainer and the drift view shows what access changed since last quarter - new grants, escalations, and who can now reach what.

RBAC permission map · read-only read-only

Melbrooke Ltd · SharePoint & OneDrive

Who can reach what, and how

Sales (Members)

M365 group

Human Resources

Edit · site

SG-Finance

Security group

Employee Records

Read · unique scope

k.reed (CFO)

Direct grant

CEO Compensation.xlsx

Full · unique scope

Discrepancies

7
reach 50+ scopes
1
external principal
5
direct grants
2
changed carve-outs
Prepared by Glow CloudLeast-privilege, proven

Beyond the score

A config score is the floor. We start above it.

A configuration score - however it is produced - tells you what is set, not who can reach what. Our value is the layer above: who can actually reach a given file, what is over-shared, and a named architect accountable for what to fix first.

The config baseline is included, done honestly and licence-aware - if you don't own a feature you are not marked down for it, and nothing is a number padded to flatter.

Microsoft-verified publisher · Glow Cloud M365 Security Framework · read-only, always

Melbrooke Ltd · Glow Cloud M365 Security Framework read-only

Framework coverage

87% of controls scored

Most scored automatically · the judgement calls flagged for manual review, each with the exact portal page to check

§1

Microsoft 365 admin center

8/14 auto

§2

Microsoft 365 Defender

15/18 auto

§3

Microsoft Purview

3/4 auto

§5

Microsoft Entra

30/35 auto

§6

Exchange Online

12/12 auto

§7 new

SharePoint admin

15/15 auto

§8 new

Microsoft Teams

16/17 auto

§9 new

Fabric / Power BI

11/11 auto

Licence-aware: never marked down for features you don't own Prepared by Glow Cloud

Your report. Your data. No portal.

A report you own and keep - not a SaaS login.

We don't keep your configuration in a cloud you have to log into. The assessment runs read-only from our access and produces a single, self-contained report you own and keep. Nothing to subscribe to, nothing to leak.

A one-off assessment is purged after 30 days. Retainer clients keep prior reports only to compute quarter-over-quarter drift, on our own secured storage and deletable on request.

Unlike portal-based governance platforms, your tenant data never becomes a standing dataset in someone else's cloud.

What lands in your inbox

  • A prioritised findings report, High to Low, in plain English
  • The sharing deep-dive: every site ranked, then every link drilled
  • The permission (RBAC) map: who can reach what, and how
  • A readout to walk you through it, not a PDF you decode alone

Independent, on the record

"You can't grade your own homework and hand it to your insurer."

A security score you generated about yourself is fine for internal tidying. But the moment someone external needs to trust your posture - a cyber-insurer, an auditor, your board, a client doing due diligence, an acquirer - self-assessment carries no weight.

An independent assessment, run by a named person who is accountable for the findings and carries £1M professional-indemnity cover, is evidence those parties will accept. That independence is structural: an assessment you run yourself can never be independent of you.

Named architect, accountable for the findings · £1M professional indemnity · Read-only, app-only

Who this is for

  • Applying for or renewing cyber-insurance
  • A board that wants assurance, not a spreadsheet
  • A client or partner asking you to prove your Microsoft 365 is secure
  • Due diligence before or during an acquisition

The engine

One read-only engine, six ways to run it.

From a free health-check to recurring assurance, each option reads more, and none of them ever writes.

Free

Health-check

Oversharing exposure and a Copilot-readiness verdict. The free way in.

Read-only · no crawl

Sample · Copilot-readiness verdict →

Signature

Permission (RBAC) map

Who can reach what in SharePoint - and how they got that access, through a group, a share or a direct grant. Site-wide, library-level and single-file reach told apart. Least-privilege, proven.

Read-only · permission crawl

Sample · first run →Sample · what the retainer adds →

Reachability

Sharing deep-dive

Every site, then every link: who can reach it, at what scope, down to the named recipient, and whether it ever expires.

Read-only · overnight crawl

Sample · per-site →Sample · per-link →

Full suite

Map + sharing + baseline

The reachability map and sharing deep-dive, plus the config baseline, in one run.

Read-only · overnight crawl

Sample · full report →Sample · what the retainer adds →Sample · executive summary →

Retainer

Re-assessment + drift

The full suite re-run each quarter, with drift on both axes: posture (findings closed, regressed and new) and access (who gained reach, whose level went up). The recurring assurance.

Read-only · quarterly

Sample · posture drift →Sample · reachability drift →

Foundation

Config baseline

The included foundation on its own: identity, email, Teams, SharePoint, devices and data protection - assessed honestly and licence-aware.

Read-only · no crawl

Sample · full report →Sample · what the retainer adds →Sample · executive summary →
Read-only, always. The engine reads your tenant and never writes to it, no config is ever changed. Fixing what it finds is a separate, hands-on remediation sprint; the assessment itself only ever reports.

Read-only, app-only

Least-privilege access. We never write to your tenant, ever.

Microsoft-verified publisher

Verified on the consent screen.

£1M professional indemnity

Insured, boutique, accountable.

Your data stays yours

It never lives in a third-party portal.

Sample reports

Open the actual deliverables.

Melbrooke Ltd is a fictional company generated through the real engine - real reports, drillable in your browser, zero client data.

Free to start

The health-check costs nothing and shows you exactly what the engine sees.

Temporary, read-only access

We never change a thing. Consent is scoped, read-only, and removed when the run is done.

Delivered and explained

An interactive report you can drill, not a PDF you decode alone - walked through in a readout.

Inside the reports

The receipts, control by control, link by link, and permission by permission.

Clear, interactive reports from one read-only run. The visuals below mirror the Melbrooke Ltd demo: fictional company, real engine.

Compliance by domain GC Framework

Melbrooke Ltd · 13 domains · 54 of 160 controls passing

Account & Authentication 37% · 19/52
Application Permissions 22% · 2/9
Mobile Device Management 8% · 1/12
Storage 27% · 4/15
Lifecycle 0% · 0/2
Licensing 25% · 1/4
Copilot Readiness 17% · 1/6
Email Security 34% · 10/29
Data Management 71% · 5/7
External Sharing 0% · 0/1
Auditing 100% · 2/2
Teams 31% · 5/16
Fabric 36% · 4/11
PassPartialFailNot assessed

Compliance by domain

Every domain broken down - not one blunt number.

Identity, Intune, SharePoint, email, data and auditing, each control marked Pass, Partial, Fail or Manual across the whole Glow Cloud M365 Security Framework, so you see precisely where the gaps are.

Glow Cloud M365 Security Assessment confidential

Melbrooke Ltd · July 2026

Executive summary

Significant gaps

Multiple high-severity controls are failing. Address the priorities below before enabling Copilot or broad collaboration.

33%
Passing
13
High
46
Medium
35
Low

Top priorities

  1. 01 No tenant-wide MFA enforcement High
  2. 02 1 transport rule(s) bypass spam filtering High
  3. 03 Authenticated SMTP enabled org-wide High
  4. 04 No Safe Attachments policy High
  5. 05 No Safe Links policy High
Prepared by Glow CloudGlow Cloud M365 Security Framework · read-only

Executive summary

The verdict, the numbers, what to fix first.

A clear verdict and the High-severity priorities to act on first, so the readout takes minutes, not a wade through a spreadsheet.

✕ Fail High

No tenant-wide MFA enforcement

Glow Cloud Framework · SPG-AUTH-201 · Account & Authentication

What we found

No all-users MFA Conditional Access policy, and security defaults are off - MFA is not enforced tenant-wide.

Why it matters

Without enforced MFA, a single stolen password is enough to take over an account - the primary path to account takeover and lateral movement.

Recommended action

Enforce MFA for all users via Conditional Access (pilot in report-only first), then disable security defaults.

Evidence · GET /identity/conditionalAccess/policies · GET /policies/authenticationMethodsPolicy

Every finding, in full

Actionable, not a vague flag.

Each finding carries its framework control reference, what we found, why it matters, a recommended action and the evidence behind it. See a complete sample report, filterable by platform, domain, type, severity and status.

The sharing deep-dive

Site by site, then link by link. Two reports.

Every site ranked by exposure (per-site), then every individual link drilled down to who can reach it, what it exposes and whether it ever expires (per-link), delivered as two separate reports.

Sharing report · Tier 1 · per-site read-only

Melbrooke Ltd · 40 sites · SharePoint & OneDrive

Where the exposure is

102
Total links
15
Anyone (anon)
16
External / guest
11
Sites w/ anon
All sites Has anonymous Has external Tier 1 · per site
SiteAnyoneOrgSpecificGuest
Executive Team 2 0 0 0
Finance 2 0 0 0
HR Team 2 0 0 0
Warranty 2 0 0 0
Stanmore Service 1 5 0 0
Prepared by Glow CloudTier 1 · per-site exposure
Per-site, open sample →
Sharing report · Tier 2 · per-link read-only

Melbrooke Ltd · SharePoint & OneDrive

Every link, and exactly who can reach it

102
Links reviewed
15
Anyone-links
29
External recipients
52
Edit access
Link & recipientScopeExpiry
/Finance/Aged Debtors 2026.xlsx → Anyone with the link
Anyone · edit 29 Nov 2026
/Stanmore Service/Service Report 3349.pdf → Anyone with the link
Anyone · edit 08 Sep 2026
/Weldon Service/Inspection 3778.pdf → ben.considine@agrifinance.co.uk
Guest · edit 21 Sep 2026
/Dunmere Service/Job Card 3168.xlsx → james.ockford@fenwick-haulage.co.uk
Guest · edit 15 Dec 2026
/Bramfield Service/Inspection 4454.pdf → Anyone with the link
Anyone · edit 24 Sep 2026

Named to the person, not just the domain: 32 external recipients surfaced across the guest links. Highest risk here - /Finance/Aged Debtors 2026.xlsx, an "Anyone" edit link anyone with the URL can change.

Prepared by Glow CloudTier 2 · link-by-link
Per-link, open sample →

What you get

Everything from one read-only run.

A full Microsoft 365 security assessment, every applicable control evidenced against the Glow Cloud M365 Security Framework
A Copilot-readiness verdict, so you know what Copilot would surface before you switch it on
Compliance broken down by domain and platform, each with a recommended action
A sharing deep-dive: every site ranked by exposure, then every link drilled to who can reach it
An RBAC permission map: who can reach what in SharePoint, how, and who shouldn't
A prioritised roadmap, High to Low, in plain English, and a readout to walk you through it
Quarterly re-assessment with drift tracking, all read-only, nothing ever written to your tenant

Run an MSP? The engine white-labels. You own the client, we supply the engine and the report - partner pricing on request.

Talk to us →

Point-in-time assessment; not a certification or accredited audit; not legal advice. Assessments can be aligned to recognised industry best practice on request.

Start with a free health-check.

Read-only. The whole tenant. One clear report.

Get your free health-check →