Open the Microsoft 365 admin center and everything looks calm. Sharing is on, a handful of policies are set, the compliance score is a reassuring number. The problem is that the admin center shows you settings, not consequences. A security assessment exists to close that gap: to turn a screen full of toggles into a plain answer to the only question that matters - who can reach what, and how did they get there?
Here is what that actually turns up in a real tenant.
Sharing links you forgot you ever made
Every "Copy link" a user has ever clicked is a standing grant. Over a few years a tenant accumulates thousands of them: anonymous "anyone with the link" links that never expire, company-wide links on folders nobody remembers, links shared to a personal address and then forgotten. None of it shows on a dashboard as a problem, because individually none of it is. In aggregate it is the single biggest source of accidental exposure in Microsoft 365.
An assessment enumerates them - every link, its scope, its age, and the content behind it - so you can see the ones that matter instead of guessing.
Permission paths, not permission settings
"Who can access this site?" is rarely a one-line answer. Access flows through nested groups, dynamic membership, inherited permissions, and guest accounts three hops removed from the file. A setting can look locked down while a path around it is wide open.
The permission map traces those paths. It shows the effective access - the real answer after every group, share and inheritance is resolved - not the theoretical one on the configuration screen. That is the difference between "external sharing is restricted" and "this contract folder is reachable by a supplier who left twelve months ago."
Guests and external identities that outstayed their welcome
Guest accounts are created for a project and almost never removed when it ends. An assessment surfaces every external identity, when it was last active, and exactly what it can still reach - so stale access becomes a short list you can act on rather than an unknown you hope is fine.
The gap between what you pay for and what you turned on
Most tenants own security features they have never enabled: conditional access that was scoped to a pilot group and left there, audit settings switched off, protections available under a licence tier nobody realised they had. The assessment maps what your licences entitle you to against what is actually configured, so the cheapest wins - the ones you have already paid for - come first.
Why Copilot raises the stakes on all of it
Microsoft 365 Copilot honours existing permissions - which sounds reassuring until you remember what those permissions actually are. Copilot will happily summarise, quote and surface anything a user can already reach, including the forgotten share and the over-broad group. It does not create exposure; it industrialises the exposure you already have. Mapping who can reach what is no longer housekeeping - it is the prerequisite for turning Copilot on safely.
What an honest score looks like
Plenty of tools produce a single confident number. The trouble is how they get there: marking you down for features you are not licensed to use, padding the checklist to look thorough, or scoring settings while ignoring consequences. We score against the Glow Cloud M365 Security Framework, and the rule is simple - you are never penalised for a control you cannot reach on your plan, and anything that needed access you did not grant is flagged as requires consent, never guessed and never counted against you. A score you can trust is worth more than a score that flatters you.
Assessments are aligned with recognised industry best practice.
The output of all this is not a login to yet another portal. It is a self-contained, interactive report you own and keep - the map, the findings, the fixes in priority order. Read-only going in, nothing left behind coming out.
See it on your own tenant
Get the permission map for your Microsoft 365.
A read-only assessment, scored honestly, delivered as a self-contained report you own. Start with a free Copilot-readiness health-check, or request a full assessment.