Microsoft 365 permission & sharing intelligence

Know who can reach what in your Microsoft 365 - and prove it.

We map who can actually reach every file in SharePoint - through every group, sharing link and broken-inheritance carve-out - plus every external share, down to the recipient. Read-only, interpreted by a named architect, and yours to keep. Config scoring is included; it is the floor, not the point.

Read-only, least-privilege Microsoft-verified publisher £1M professional indemnity

RBAC relationship map · person view · read-only Melbrooke · sample
Full control Edit Read Limited (traversal) Dashed = direct grant · thickness = reach
PERSON SITES UNIQUE PERMISSIONS Colin Rathbone user · reaches 16 sites, 12 unique items Finance Full control · SP Owners HR Team Full control · SP Owners Executive Team Full control · Security group Compliance Full control · SP Owners IT Department Full control · direct Board Confidential Edit · SP Members Harwick Service Edit · SP Members Ketterby Service Edit · SP Members Bramfield Service Edit · M365 Members Dunmere Sales Edit · SP Members Ashwell Parts Edit · SP Members Calder Vale Service Read · SP Visitors Marketing Read · SP Visitors Health and Safety Read · SP Visitors Melbrooke Parts Limited · traversal only Ketterby Parts Limited · traversal only Asset Register 2026.xlsx File · access differs Payroll Contacts.xlsx File · access differs Job Title List.xlsx File · access differs Compliance Register.xlsx File · access differs Admin Runbook.docx File · access differs CRM Password Reset.pdf File · access differs Barcode Scanner.docx File · access differs Work Order Locks.pdf File · access differs Faster Entry Guide.pdf File · access differs Cisco Phone Restart.pdf File · access differs Warranty Password.docx File · access differs Unlocking Tickets.docx File · access differs
Site AdminM365 MembersSP OwnersSP MembersSP VisitorsSecurity groupDirect grant

One account's real reach: Colin Rathbone lands on 16 sites - mostly through group nesting, two by direct grant - and inside them, 12 files where his access breaks from the site default. This is what a leaver, a contractor, or a busy admin account can actually get to. Static sample; the live report is fully interactive.

Independent, on the record

"You can't grade your own homework and hand it to your insurer."

A security score you generated about yourself is fine for internal tidying. But the moment someone external needs to trust your posture - a cyber-insurer, an auditor, your board, a client doing due diligence, an acquirer - self-assessment carries no weight.

An independent assessment, run by a named person who is accountable for the findings and carries £1M professional-indemnity cover, is evidence those parties will accept. That independence is structural: a tool you run yourself can never be independent of you.

Who this is for

  • Applying for or renewing cyber-insurance
  • A board that wants assurance, not a spreadsheet
  • A client or partner asking you to prove your Microsoft 365 is secure
  • Due diligence before or during an acquisition

The sharing map nobody else shows you

Not "external sharing is on". Every live link, down to the named recipient.

Most audits stop at the tenant setting. The sharing crawl reads every site, then every item, and inventories every live sharing link - Anyone links, org-wide links, specific-people shares and guest grants - ranked site by site so the worst exposure surfaces first.

Then the per-link view drills each one to the item and the people on the end of it, named - including the external ones. It is the oversharing Microsoft 365 Copilot will surface to your staff on day one, found before it does.

  • Every site ranked by exposure: Anyone, org-wide, specific-people and guest links, counted per site.
  • Every link drilled to the item and its named recipients; Anyone links flagged as reachable by whoever holds the URL.
  • The evidence for a real clean-up, link by link - not a tenant-wide warning.
Sharing report · Tier 1 · per-site read-only

Melbrooke Ltd · 40 sites · SharePoint & OneDrive

Where the exposure is

102
Total links
15
Anyone (anon)
16
External / guest
11
Sites w/ anon
All sites Has anonymous Has external Tier 1 · per site
SiteAnyoneOrgSpecificGuest
Executive Team 2 0 0 0
Finance 2 0 0 0
HR Team 2 0 0 0
Warranty 2 0 0 0
Stanmore Service 1 5 0 0
Prepared by Glow CloudTier 1 · per-site exposure
Sharing report · Tier 2 · per-link read-only

Melbrooke Ltd · SharePoint & OneDrive

Every link, and exactly who can reach it

102
Links reviewed
15
Anyone-links
29
External recipients
52
Edit access
Link & recipientScopeExpiry
/Weldon Service/Inspection 3778.pdf → [object Object]
ben.considine@agrifinance.co.uk · edit 21 Sep 2026
/Dunmere Service/Job Card 3168.xlsx → [object Object]
james.ockford@fenwick-haulage.co.uk · edit 15 Dec 2026
/Melbrooke Sales/Quote 3831.pdf → [object Object], [object Object]
2 people (1 external) · edit 08 Dec 2026
/Finance/Aged Debtors 2026.xlsx → Anyone with the link
Anyone with the link · edit 29 Nov 2026
/Stanmore Service/Service Report 3349.pdf → Anyone with the link
Anyone with the link · edit 08 Sep 2026

Named to the person, not just the domain: 32 external recipients surfaced across the guest links. Highest risk here - /Finance/Aged Debtors 2026.xlsx, an "Anyone" edit link anyone with the URL can change.

Prepared by Glow CloudTier 2 · link-by-link

The permission map nobody else shows you

Start from a site. See exactly who reaches in, and how.

This is the RBAC relationship map: every principal that reaches a site - the default SharePoint groups, the site admins, security groups and any direct grant - grouped by how far that reach goes, plus the libraries and the items inside where permissions break from the site default. Pick a person instead and the map reverses: everything they can reach, and exactly how they got it.

And it is honest about what it knows. Where a group's membership is only inferred from the site's nesting rather than independently confirmed, we mark it default rather than pretend certainty - the distinction an auditor actually cares about. Counts are shown both ways for the same reason: 6/43 scopes means six places on the site you are looking at, forty-three across the estate.

  • Over-permissioned users, oversized groups, direct grants and outside support accounts surfaced as the headline.
  • Principals grouped by reach: site-wide, into specific libraries only, or a single shared file.
  • Libraries that hold permissions of their own get their own lane, not rolled into the site.
  • Right-hand column is the exposure: items that break inheritance from the site.
  • Dashed = a direct grant; membership marked default where we could not confirm it.
RBAC relationship map · site view · read-only Melbrooke · sample
Full control Edit Read Dashed = direct grant · thickness = reach
PRINCIPALS SITE UNIQUE PERMISSIONS Ashwell Service Site SP Owners Full · default · 5 scopes SP Members Edit · default · 5 scopes SP Visitors Read · default · 4 scopes Melbrooke_All_Admin Security group · 1 scope Site Admin M365 owners · any item Keith Bannerman Direct · 3 scopes · item-level Jasmine Rowe Direct · 3 scopes · item-level Nathan Aldous Direct · 3 scopes · item-level Martin Ackroyd Direct · 3 scopes · item-level Umar Siddiqui Direct · 6 scopes · item-level Zoe Harding Direct · 1 scope · item-level Salary Bands Folder · access differs Asset Register 2026.xlsx File · access differs Completed Forms Folder · access differs Admin Runbook.docx File · access differs CRM Password Reset.pdf File · access differs

Default = group membership inferred from the site's nesting, not independently confirmed. Everything routes through the site (it is on the access path); the right column breaks inheritance from it. Static sample; the live report is fully interactive.

How to read the permission map

One panel, one question: how does this item differ from its site?

One panel compares a single folder or file against the site it lives in, at the same moment. It appears only where that item has unique permissions - inheritance from the site was broken and its access set on its own. A structural difference, not a change over time.

The site

Access everyone here inherits

  • OwnersFull control
  • MembersEdit
  • VisitorsRead
compared · same moment

This item · a carve-out

Unique permissions · inheritance broken

  • +Finance lead Edit · added here
  • +External auditor Edit · added here
  • General staff Read · removed here
  • Former contractor Read · removed here

+ Added here

People granted access to this specific item, beyond the site's normal access - a deliberate carve-out that adds access.

Removed here

People who can reach the wider site but have been excluded from this item - inheritance was intentionally broken. They are still on the site, just not this item.

Carve-outs are the exceptions to the rule - the exact spots where normal access has been overridden, tightened or loosened. That is where accidental over-sharing and awkward lockouts hide.

Not to be confused with drift, a separate view that shows what changed over time between assessments. One is structure; the other is time.

How to read the drift view

The other view: what changed since last time.

The retainer re-runs the whole assessment each quarter and compares it against the last run - on two axes. The assessment diffs your posture: findings closed, new and regressed, with the score as a trend. The permission map diffs your access: who gained reach, whose level went up, and what was removed. The opposite of the carve-out panel: that is structure at a single moment; this is change over time.

Posture drift · from the assessment

Last quarter

Where the prior run left things

  • No tenant-wide MFAHigh
  • Legacy auth allowedHigh
  • Safe Links in placePass
compared · over time

This quarter · what changed

Closed, new and regressed since last run

  • MFA now enforced tenant-wide closed
  • Legacy auth blocked closed
  • +Anonymous link on a Finance file new
  • Safe Links policy removed regressed

Reachability drift · from the permission map

This quarter · what access changed

The permission map diffed against the prior run: who gained reach, and how

Open the reachability drift sample →
9
New access
8
Escalations
0
New external
0
Access removed
  • +MEL_FloorplanFinance_RW now reaches Floorplan Finance sensitive · new access
  • Dunmere Sales Owners on Dunmere Sales: Edit → Full control escalation

Closed

Findings you fixed since last time - the proof that remediation landed and held.

+ New or regressed

A finding that appeared, or one that came back - caught the quarter it happens, not a year later.

Access drift

The map diffed run over run: new reach, escalations and removals - the access changes no scanner reports.

Posture and access both become trend lines you can prove - fewer findings quarter over quarter, privilege creep caught the quarter it happens, and anything that slips back flagged the moment it does. That is what a retainer buys that a one-off PDF never can.

The layer no scanner touches

Config scoring is a commodity. This is where we start.

Free scanners and native scoring both grade your configuration. That is the floor - useful, and now table stakes. Our value is the layer above it, and it is three things nobody automates.

01 · Reachability

Who can actually reach a file

Not “sharing is on”. Who, what and how - across SharePoint and OneDrive, through every group, sharing link and broken-inheritance carve-out - plus the external-sharing deep-dive, down to the named recipient.

02 · The trend

Re-run and re-read each quarter

The same architect re-runs the whole engagement each quarter and reads you what moved - the config baseline tracked control by control, and your reachability and sharing re-mapped and read afresh - a real quarter-over-quarter read, not a dashboard auto-diffing a config file.

03 · The judgement

A person who is accountable

A named architect runs it, interprets it, prioritises it and sits with you to explain it - backed by professional indemnity. Free tools produce output and disclaim advice; we own the answer.

"Why not just run a free scanner?"

A fair question. Here is the honest answer.

Run a free scanner and you will get a config score. We start where that stops: who can actually reach your data, what is over-shared, and what to do about it first - interpreted by a person who is accountable for the answer.

The floor is worth having - we simply do not stop there. What matters is who can actually reach what, and a person on the record for what to do about it first.

What we add

  • Who can reach a given file, and exactly how
  • Every external share, down to the named recipient
  • Over-permissioned users and oversized groups, surfaced
  • Drift, interpreted - what improved, what slipped since last quarter, and what to do about it, from a named architect
  • What to fix first, and why - from a named architect

The floor · free scanners & native scoring

A configuration score - what is set, checked against a list. It cannot tell you who can reach what, or stand behind the answer.

The included foundation

And the baseline we do include, we score straight.

The map and the trend sit on that config baseline: your posture across identity, email, Teams, devices and data protection, scored against the Glow Cloud M365 Security Framework. It is included in every engagement - and we do it straight. No false passes, no false fails, and features you are not licensed for are never marked against you.

Scored automatically

The checks that can be evidenced from your configuration, scored and shown with the evidence.

Flagged for manual review

The judgement calls, flagged with the exact portal page to check. Never a false auto-pass.

Not marked down unfairly

Licence-aware: features you do not own are marked not applicable, not failed.

A report you own, not a portal you rent

Why we don't hand you another dashboard.

Most Microsoft 365 governance tools are subscription portals: a standing connection to your tenant, your data living in their cloud, and a bill that never stops. We work the other way round - a read-only look, a self-contained report you own and keep, and nothing left behind.

The working data behind an assessment stays on our own secured machine, never a standing dataset in someone else's cloud and never in a portal you have to sign in to. We sweep delivered copies on a regular cycle, and we delete everything for a client on request, in writing, at any time. Retainer clients keep prior runs by design, because the quarter-over-quarter drift is computed from them.

What lands in your inbox

  • A prioritised findings report, High to Low, in plain English
  • The sharing deep-dive: every site ranked, then every link drilled
  • The permission (RBAC) map: who can reach what, and how
  • A readout to walk you through it, not a PDF you decode alone
Glow Cloud Security A report you own A governance portal A subscription you rent
Your data A report you own; delivered copies swept on a regular cycle, and everything deleted on request. Lives in their cloud for as long as you keep subscribing.
What you get A self-contained, interactive report - yours to keep for good. A dashboard you log into, and lose the day you cancel.
Access Read-only, point-in-time, and revocable the moment we're done. A standing, always-on connection into your tenant.
The permission map Who can reach which file, and exactly how they got there. Setting-level flags - rarely the real-world consequence.
Scoring Honest: features you are not licensed for are never marked against you. One blunt score, often padded to look thorough.
Cost A one-off fixed price, or a light quarterly retainer for drift tracking. An open-ended per-tenant subscription.

Comparison is with typical subscription-based Microsoft 365 governance platforms, described in general terms. No specific product is named or implied.

Focus, not a firehose

A baseline you can act on, not a feed you babysit.

Always-on monitoring never stops talking. Most teams don't have someone watching a dashboard at 2am, so the alerts pile up unread and nothing actually gets fixed. We give you the opposite: a fixed, prioritised picture of where you stand, and a short list of what to change first - work you can finish, not a stream you have to babysit.

This is posture, not an alarm. Live monitoring answers "is someone in my tenant right now?"; our assessment answers "is it configured and shared safely, and what do I fix first?" - a different job. And your configuration posture doesn't change every second: it changes when someone changes something, which is exactly what the quarterly re-read is built to catch.

A fixed target

Plan remediation against a baseline that isn't moving under you - close the top items, then re-measure.

Yours to keep

A document you own and can hand to an insurer, board or auditor. A live feed is not evidence you can file.

Caught on the re-run

Quarterly drift tracking surfaces what moved since last time, without the always-on noise.

Pricing

Productised. One price, no surprises.

Tell us which report you need and book a 30-minute onboarding call - we run the assessment and hand you a self-contained report you own and keep. A one-off engagement, or a quarterly retainer for ongoing assurance. No portal, no subscription, no lock-in.

Free

Free health-check

Free

Oversharing exposure and a Copilot-readiness verdict, across six areas. The free way in - you keep the report whether or not you go further.

Signature

Permission (RBAC) Map

£1,750

The signature deliverable, and the one nothing else on the market produces: a visual map of who can reach which sites, libraries, folders and files - and how they got there, whether through a group, a sharing link or a direct grant. Principals are grouped by how far their reach goes - site-wide, into specific libraries only, or nothing but a single shared file - and libraries holding their own permissions are drawn in their own lane, so per-library compartmentalisation is visible rather than rolled up. Includes per-user reachability, compare-two-users, broken-inheritance carve-outs, and a raw data export your admin team can work from. Included in the Complete engagement below. Report within 5 business days of access.

Live readout with the architect who ran it

Tenants over ~250 SharePoint sites? Book a call for a scoped quote →

Reachability

Sharing & Permission Deep-Dive

£1,000

A complete map of external sharing and access exposure: every sharing link, every broken-inheritance file, and who can reach what - down to the named recipient. Includes the per-site and per-link breakdown from a read-only crawl. The oversharing Copilot will surface on day one - found first. For tenants up to ~250 SharePoint sites; larger tenants, book a call for a scoped quote. Report within 5 business days of access.

Live readout with the architect who ran it

Tenants over ~250 SharePoint sites? Book a call for a scoped quote →

Posture + sharing

Full Suite

£2,200

The sharing deep-dive and the config baseline in one run: every external share down to the named recipient, plus your posture across identity, email, Teams, SharePoint, devices and data protection. It does not include the permission map - if you want to see who can actually reach what, take the Complete engagement. For tenants up to ~250 SharePoint sites; larger tenants, book a call. Report within 5 business days of access.

Live readout with the architect who ran it

Tenants over ~250 SharePoint sites? Book a call for a scoped quote →

Complete

Full Suite + Permission Map

£2,700

Everything, in one read-only run: the config baseline, the external-sharing deep-dive down to the named recipient, and the permission map. This is the engagement that answers the whole question - what is configured, what is shared, and who can actually reach it - from a single crawl of your tenant. Most buyers who are assessing risk rather than ticking a box take this one. For tenants up to ~250 SharePoint sites; larger tenants, book a call. Report within 5 business days of access.

Live readout with the architect who ran it

Tenants over ~250 SharePoint sites? Book a call for a scoped quote →

Retainer

Quarterly Retainer

from £7,500 /yr

Your posture as a tracked record rather than four separate reports. Each quarter we re-run the complete engagement and diff it against your held baseline: what closed, what regressed, what is new, and whether last quarter's fixes actually held. The history is the deliverable. It is what lets you show an insurer, a board or an auditor a direction of travel instead of a snapshot, and it is the one thing a first assessment cannot give you at any price - it only exists once there is a prior run to measure against. Same architect every quarter, and your baseline held between runs so the comparison is real.

A live readout every quarter, same architect

Foundation

Config baseline assessment

£1,500

The config baseline on its own: your posture across identity, email, Teams, SharePoint, devices and data protection, scored against the Glow Cloud M365 Security Framework - honestly, and licence-aware. The included foundation, available standalone; most buyers take it inside the Full Suite. Report within 3 business days of access.

Live readout with the architect who ran it

Buying more than one? We bundle them when we scope, because one read-only crawl feeds all of it - you are never charged twice for the same scan. The Complete engagement is the fully bundled price; any other combination we quote when we scope.

What access does it need? +

One read-only approval covers most of the assessment - identity, email, storage, Purview, Intune, licensing and more. Two minutes, needs a Global Administrator.

Two further approvals are set up together on your onboarding call:

  • Fabric / Power BI checks - a read-only admin-API setting in your Fabric portal (plus adding our read-only connection to a security group you control).
  • The permission map - approving a second read-only connection, plus a dedicated SharePoint Administrator account you create for the engagement and disable when we hand over. Microsoft shows a site’s own permission list, and some tenant-level SharePoint settings, only to a signed-in administrator, so a full run signs in at up to three points: twice early on and once near the end. We sign in ourselves, so none of your people need to be on hand at both ends of an overnight run. SharePoint Administrator is a privileged role rather than a read-only one, so the account stays yours to audit and revoke, and we commit to using it for reads only. This one is not truly optional if you have bought the map: reading each site’s own permission list is what produces the library-level detail. Decline it and the map still renders, but it shows access rolled up to the site.

Skip the Fabric setting and the assessment still runs, with those checks clearly marked "requires consent" in your report, never silently missing and never guessed. Skip the SharePoint account and the map is shallower rather than absent, and we will say so at the readout. Nothing is scored against you for access you chose not to grant. And the price is the price: full coverage costs nothing extra - the only thing gating your report is what you choose to grant.

The fine print, plainly

  • Fixed-scope engagement - full refund if we can't gain read-only access within 5 business days; non-refundable once the assessment run begins.
  • Delivery - 3 business days from access for the Assessment; 5 business days for the Sharing & Permission Deep-Dive, Full Suite and RBAC Map.
  • Your data - the working data stays on our own secured machine, never in a portal you sign in to. We sweep delivered copies on a regular cycle and delete everything for a client on request, in writing, at any time. A retainer keeps prior runs by design, because the improvement measure is computed from them.
  • Custody on delivery - the report arrives as a single encrypted file via a link bound to your named recipient, with the passphrase relayed separately; from delivery, both are in your care - keep them apart.

Engaging us means you agree to our terms & policies.

Sample reports

Open the actual deliverables.

Melbrooke Ltd is a fictional company generated through the real engine - real, drillable reports in your browser, zero client data. No install, no email needed.

Inside the reports

The receipts, control by control, link by link, and permission by permission.

Clear, interactive reports from one read-only run. The visuals below mirror the Melbrooke Ltd demo: fictional company, real engine.

Compliance by domain GC Framework

Melbrooke Ltd · 13 domains · 54 of 166 controls passing

Account & Authentication 37% · 19/52
Application Permissions 22% · 2/9
Mobile Device Management 8% · 1/12
Storage 27% · 4/15
Lifecycle 0% · 0/2
Licensing 25% · 1/4
Copilot Readiness 17% · 1/6
Email Security 34% · 10/29
Data Management 71% · 5/7
External Sharing 0% · 0/1
Auditing 100% · 2/2
Teams 31% · 5/16
Fabric 36% · 4/11
PassPartialFailNot assessed

Compliance by domain

Every domain broken down - not one blunt number.

Entra, Intune, SharePoint, email, data and auditing, each control marked Pass, Partial, Fail or Manual across the whole Glow Cloud M365 Security Framework, so you see precisely where the gaps are.

Glow Cloud M365 Security Assessment confidential

Melbrooke Ltd · July 2026

Executive summary

Significant gaps

Multiple high-severity controls are failing. Address the priorities below before enabling Copilot or broad collaboration.

33%
Passing
13
High
46
Medium
35
Low

Top priorities

  1. 01 No tenant-wide MFA enforcement High
  2. 02 1 transport rule(s) bypass spam filtering High
  3. 03 Authenticated SMTP enabled org-wide High
  4. 04 No Safe Attachments policy High
  5. 05 No Safe Links policy High
Prepared by Glow CloudGlow Cloud M365 Security Framework · read-only

Executive summary

The verdict, the numbers, what to fix first.

A clear verdict and the High-severity priorities to act on first, so the readout takes minutes, not a wade through a spreadsheet.

✕ Fail High

No tenant-wide MFA enforcement

Glow Cloud Framework · SPG-AUTH-201 · Account & Authentication

What we found

No all-users MFA Conditional Access policy, and security defaults are off - MFA is not enforced tenant-wide.

Why it matters

Without enforced MFA, a single stolen password is enough to take over an account - the primary path to account takeover and lateral movement.

Recommended action

Enforce MFA for all users via Conditional Access (pilot in report-only first), then disable security defaults.

Evidence · GET /identity/conditionalAccess/policies · GET /policies/authenticationMethodsPolicy

Every finding, in full

Actionable, not a vague flag.

Each finding carries its framework control reference, what we found, why it matters, a recommended action and the evidence behind it. See a complete sample report, filterable by platform, domain, type, severity and status.

The sharing deep-dive

Site by site, then link by link. Two reports.

Every site ranked by exposure (per-site), then every individual link drilled down to who can reach it, what it exposes and whether it ever expires (per-link), delivered as two separate reports.

Sharing report · Tier 1 · per-site read-only

Melbrooke Ltd · 40 sites · SharePoint & OneDrive

Where the exposure is

102
Total links
15
Anyone (anon)
16
External / guest
11
Sites w/ anon
All sites Has anonymous Has external Tier 1 · per site
SiteAnyoneOrgSpecificGuest
Executive Team 2 0 0 0
Finance 2 0 0 0
HR Team 2 0 0 0
Warranty 2 0 0 0
Stanmore Service 1 5 0 0
Prepared by Glow CloudTier 1 · per-site exposure
Per-site, open sample →
Sharing report · Tier 2 · per-link read-only

Melbrooke Ltd · SharePoint & OneDrive

Every link, and exactly who can reach it

102
Links reviewed
15
Anyone-links
29
External recipients
52
Edit access
Link & recipientScopeExpiry
/Weldon Service/Inspection 3778.pdf → [object Object]
ben.considine@agrifinance.co.uk · edit 21 Sep 2026
/Dunmere Service/Job Card 3168.xlsx → [object Object]
james.ockford@fenwick-haulage.co.uk · edit 15 Dec 2026
/Melbrooke Sales/Quote 3831.pdf → [object Object], [object Object]
2 people (1 external) · edit 08 Dec 2026
/Finance/Aged Debtors 2026.xlsx → Anyone with the link
Anyone with the link · edit 29 Nov 2026
/Stanmore Service/Service Report 3349.pdf → Anyone with the link
Anyone with the link · edit 08 Sep 2026

Named to the person, not just the domain: 32 external recipients surfaced across the guest links. Highest risk here - /Finance/Aged Debtors 2026.xlsx, an "Anyone" edit link anyone with the URL can change.

Prepared by Glow CloudTier 2 · link-by-link
Per-link, open sample →

How it works

Four steps, nothing installed.

01

Connect (read-only)

You grant a read-only, least-privilege app. The assessment app only ever reads, and never writes to your tenant. On a large estate some sites cannot be read that way; where that happens we agree a temporary permission on just those sites with you first, and remove it when the run is done.

02

Map & assess

We map who can reach what across your SharePoint sites, trace external sharing across SharePoint and OneDrive, and assess the config baseline. Read-only throughout, no agents, no disruption. Most of the run uses the read-only app; the permission map and the OneDrive sharing checks need one SharePoint Administrator sign-in during the scan window.

03

Receive your report

A self-contained, interactive report: prioritised findings, the sharing deep-dive and the permission map. Yours to keep.

04

Track drift (retainer)

Re-run each quarter and see exactly what improved, control by control.

Assessed against the Glow Cloud M365 Security Framework - our own control set, refined across years of hands-on Microsoft 365 governance work.

Who it's for

Built for organisations that need the truth about their posture.

Security-conscious and regulated organisations - finance, legal, pharma, professional services - and any team rolling out Microsoft 365 Copilot who needs proof their data is not overshared.

"Built by a Microsoft 365 architect who got tired of audits that stop at a settings screen. The permission map is the report I always wanted to hand a client and could never buy."
Mark Berry, founder of Glow Cloud Solutions

Read-only, least-privilege

We never change your environment.

Microsoft-verified publisher

Verified on the consent screen.

£1M professional indemnity

Insured, boutique, accountable.

A named architect, not a portal

The same person runs it, presents it, and stands behind it.

Point-in-time assessment; not a certification or accredited audit; not legal advice. Assessments can be aligned to recognised industry best practice on request.

Questions, answered

The bits people ask first.

How do you access my Microsoft 365 tenant? +

You grant a read-only, least-privilege app, and we never write to your tenant. Access is revocable at any time, and every read shows in your own audit log. Most of the assessment runs app-only with nobody signed in. Some stages are the exception: reading each site’s own permission list, and certain tenant-level SharePoint settings, needs a signed-in administrator rather than an app. You create a dedicated SharePoint Administrator account for the engagement and disable it when we hand over; a full run signs into it at up to three points, and we do the signing in, so nobody of yours has to be available overnight. Without it the map still renders, but it shows access rolled up to the site and misses the library-level detail that makes it worth having.

Where does my data go? +

Nowhere you have to log into. The assessment produces a single, self-contained report you own and keep, and nothing about your tenant sits in a portal you have to sign in to. The working data behind it stays on our own secured machine. We sweep delivered copies on a regular cycle, and we delete everything for a client on request, in writing, at any time. Retainer clients keep prior runs by design, because the quarter-over-quarter drift is computed from them.

What does the assessment cover? +

The reachability map - who can reach which file, and exactly how - a link-by-link external-sharing deep-dive down to the recipient, and a config baseline across Entra, email, Teams, SharePoint, devices and data protection. All scored against the Glow Cloud M365 Security Framework, licence-aware and honest.

Why not just run a free scanner? +

Free scanners and native scoring grade your configuration - that is the floor, and it is useful. We start above it: who can actually reach your data, what is over-shared, and what to fix first - interpreted by a named architect who is accountable for the answer. A config score cannot tell you who can reach what, or stand behind the finding.

Will it show whether we are ready for Microsoft 365 Copilot? +

Yes. We surface the oversharing and broad access Copilot would expose to staff on day one, so you can fix it before switching Copilot on.

Is this a certification or an accredited audit? +

No. It is a point-in-time assessment, not a certification or accredited audit, and not legal advice. Assessments can be aligned to recognised industry best practice on request.

Do you just send a report and leave? +

No. Every paid engagement includes a live readout with the architect who ran it - we walk your team through the findings, what they mean for your estate specifically, and what to do first. The report is yours to keep and is written to be read without us, but the readout is where most of the value lands: the questions that matter are almost always about your data, not about the method. Retainer clients get one every quarter.

How much does it cost? +

The Complete engagement - config baseline, sharing deep-dive and permission map in one run - is £2,700, and is what most buyers take. Individually: the Permission (RBAC) Map is £1,750, the Sharing & Permission Deep-Dive is £1,000, the Full Suite (baseline and deep-dive, no map) is £2,200, and the config baseline on its own is £1,500. The quarterly retainer starts at £7,500/yr and includes four complete engagements, the drift comparison between them, and a readout each quarter. The Copilot-readiness health-check is free.

How long does it take? +

Your report lands within 3 business days of access for the Assessment, and within 5 business days for the Deep-Dive, Full Suite and RBAC Map.

What if our tenant is large? +

The fixed prices cover a tenant of up to around 250 SharePoint sites - typically a few hundred users, though headcount is only half of it. The effort, and the size of the reports, scale with the number of sites, and a small team can easily have thousands. Above that the work is scoped individually, and we will always confirm the price before anything starts. Tell us roughly how many sites you have, or just book a call.

What if we skip one of the optional approvals? +

The assessment still runs, and anything that needed a consent you chose not to grant is marked “requires consent” in your report rather than being silently missing, guessed at, or scored against you. One approval works differently and we would rather say so: if you decline the SharePoint Administrator sign-in, the permission map still renders, but it shows access rolled up to the site instead of down to the library. We will tell you at the readout if that happened.

Can we get a refund? +

Yes - it is a fixed-scope engagement: a full refund if we cannot gain read-only access within 5 business days. Once the assessment run begins it is non-refundable.

Ready to see who can reach what?

Request a Microsoft 365 security assessment.

Tell us your tenant and we will arrange a read-only access window. No sales call required, and no obligation.

  • Temporary, read-only access - you stay in control
  • We retain only the report we hand you
  • A report you own, walked through in a readout

Request your assessment

No cost to ask. No sales call required.

Prefer email? hello@glowcloud.uk

We use your details only to respond. See our privacy & cookies policy.