Skip to main content
April 2, 2026•22 min read•Security & Compliance

Microsoft 365 Security & Compliance Health Check

Secure Score optimization, permission audits, Purview compliance configuration, DLP policy review, and incident response planning for regulated enterprises.

Quick Answer: A Microsoft 365 Security & Compliance Health Check assesses your tenant's Secure Score and several key areas:

The average enterprise Secure Score is 45-55%. EPC Group usually improves scores by 25-40 points during the first engagement. The assessment starts at $20,000 for a 3-week period.

By Errin O'Connor, Founder & Chief AI Architect, EPC Group

Last updated: 2026 · Read time: ~6 min

Key Facts

  • Health check covers: Secure Score gap analysis, permission audit, Purview compliance controls, DLP effectiveness, and incident response readiness.
  • Most common improvements found: Conditional Access gaps for non-admin users, missing anti-phishing policies, audit logging gaps, sensitivity label coverage below 30%.
  • Compliance check covers six surfaces: SharePoint, OneDrive, Teams, Exchange, Azure AD groups, and Power Platform.
  • E5 ($57/user/month) adds Defender Plan 2, Defender for Cloud Apps, Insider Risk, Communication Compliance, Audit Premium, and more vs. E3 ($36/user/month).
  • EPC Group has delivered security health checks for Fortune 500 healthcare, financial services, and government clients.
  • Contact: (888) 381-9725 · contact@epcgroup.net

Why Most M365 Tenants Are Under-Secured

Microsoft 365 provides over 300 security and compliance controls. The average enterprise has configured fewer than 40% of them. This gap exists because M365 security is not a single product — it spans Azure AD/Entra ID, Exchange Online Protection, Microsoft Defender for Office 365, Microsoft Purview, Intune, SharePoint admin center, Teams admin center, and Power Platform admin center. No single administrator owns all of these consoles, and security configurations drift over time as features are added and organizational needs change.

The result is predictable: enterprises pass initial compliance audits but develop security gaps over 12-24 months as configurations drift, new features go unconfigured, and organizational changes create permission sprawl. A security health check resets the baseline and identifies the highest-impact remediations.

Health Check Assessment Areas

Microsoft Secure Score Optimization

Secure Score is the starting point as it gives a clear baseline. The health check reviews your current score in four categories. It identifies actions for improvement, ranked by point value and effort needed for implementation.

Permission Audit and Remediation

Permission sprawl is the biggest security risk in most M365 environments. Our health check audits various aspects of your system, including:

The most dangerous finding is typically "everyone except external users" sharing links in SharePoint — a single misconfigured sharing link can expose sensitive documents to the entire organization. In healthcare environments, this often means PHI is accessible to users outside the care team, violating HIPAA minimum necessary requirements.

Microsoft Purview Compliance Configuration

The Purview compliance center manages data governance across M365. The health check assesses several key areas:

Data Loss Prevention (DLP) Effectiveness

Many organizations have Data Loss Prevention (DLP) policies that are either too strict or too lenient. Strict policies can block legitimate business activities and lead to alert fatigue. On the other hand, lenient policies may not catch actual data loss events.

The health check evaluates DLP policy coverage across:

The system analyzes false positive and false negative rates from policy match logs. It also reviews policy exceptions and overrides to ensure they are appropriate. Furthermore, it tests policies against realistic data loss scenarios.

Effective Data Loss Prevention (DLP) requires tuning, not just deployment. EPC Group employs a data-driven approach to optimize DLP. This method reduces false positives by 60-80% and improves the detection of actual data loss events.

Common Findings by Industry

FindingHealthcare (HIPAA)Finance (SOC 2)Government (FedRAMP)
Average Secure Score48%52%61%
Permission SprawlPHI exposed beyond care teamFinancial data oversharedCUI accessible to non-cleared staff
DLP GapNo PHI detection in TeamsPCI data not monitoredCUI marking not enforced
Audit Retention180 days (need 6 years)180 days (need 7 years)90 days (need 3 years)
Incident ResponseNo breach notification planPlan exists but untestedPlan exists, tested annually

EPC Group vs. Competitors: M365 Security Health Check

CapabilityEPC GroupMSSPsGeneral IT Consultancies
Assessment Depth300+ controls across 8 admin centersFocus on Defender/Sentinel onlySecure Score review only
Compliance MappingPre-built for HIPAA, SOC 2, FedRAMPSecurity-focused, not complianceBasic mapping
Permission Audit DepthFull inheritance chain analysisAdmin-level onlySpot-check approach
DLP OptimizationData-driven tuning, 60-80% FP reductionPolicy deployment onlyTemplate-based policies
RemediationAssessment + implementation (Better/Best)Report only, separate SOW for fixesReport only
CostFixed price, scoped after discovery$50K-$150K+ T&M$15K-$30K (shallow scope)

Pricing Tiers: M365 Security Health Check

Microsoft 365 Security and Compliance Health Check

Last updated: 2026 · Read time: ~6 min

A Microsoft 365 security and compliance health check reviews several key areas. These include Secure Score, permission structures, Purview compliance controls, DLP policies, and incident response readiness.

EPC Group offers this as a fixed-fee service for HIPAA, SOC 2, and FedRAMP environments. In their first audit, most enterprises find 15–30 critical gaps.

Key facts

  • Health check covers: Secure Score gap analysis, permission audit, Purview compliance controls, DLP effectiveness, and incident response readiness.
  • Most common improvements found: Conditional Access gaps for non-admin users, missing anti-phishing policies, audit logging gaps, sensitivity label coverage below 30%.
  • Compliance check covers six surfaces: SharePoint, OneDrive, Teams, Exchange, Azure AD groups, and Power Platform.
  • E5 ($57/user/month) adds Defender Plan 2, Defender for Cloud Apps, Insider Risk, Communication Compliance, Audit Premium, and more vs. E3 ($36/user/month).
  • EPC Group has delivered security health checks for Fortune 500 healthcare, financial services, and government clients.
  • Contact: (888) 381-9725 · contact@epcgroup.net

What the health check covers

Secure Score optimization

Microsoft Secure Score is the primary health metric for M365 security. A well-configured enterprise tenant should score above 75%. Most unmanaged tenants score 40–55%.

The health check identifies your top 10 Secure Score improvement actions by impact and implementation complexity. Common high-value items:

  • Enable Conditional Access policies for all users — not just admins.
  • Configure anti-phishing policies in Defender for Office 365.
  • Enable unified audit logging with extended retention.
  • Deploy sensitivity labels for automatic data classification.
  • Implement Privileged Identity Management (PIM) for just-in-time admin access.

Permission audit

Permissions are the most common source of data exposure — and the most common pre-condition for Copilot data leaks. The health check audits all six permission surfaces:

  • SharePoint — site collection permissions, inheritance chains, "Everyone except external users" links.
  • OneDrive — internal and external sharing links, stale shares.
  • Teams — membership, guest access, external federation settings.
  • Exchange Online — mailbox delegation, shared mailboxes, send-as rights.
  • Azure AD — group membership, dynamic group rules, stale accounts.
  • Power Platform — environment permissions, data connector access.

Purview compliance controls

The compliance section evaluates six Purview capabilities. Each is checked for configuration completeness and policy effectiveness:

  • Retention policies — configured to meet regulatory record-keeping requirements for your industry.
  • Sensitivity labels — deployed and adopted by users, not just configured in the admin portal.
  • DLP policies — effective without generating excessive false positives that cause users to bypass them.
  • Communication compliance — monitoring for regulatory violations in Teams and email.
  • Information barriers — configured where required (e.g., between departments with conflicts of interest).
  • Insider risk management — configured to detect high-risk data exfiltration patterns.

Incident response readiness

Most enterprises have no documented incident response runbook for M365-specific breaches. The health check validates:

  • Documented runbooks for mailbox compromise, bulk file download, and ransomware events.
  • Microsoft Sentinel analytics rules tuned to your environment.
  • Alert routing to on-call security personnel.
  • Contact information for Microsoft escalation paths (CSS, DART).

E3 vs E5 licensing gap analysis

Part of every health check is a licensing gap analysis. E5 adds significant security capabilities beyond E3.

  • E3 — $36/user/month: Core M365 apps, Defender for Office 365 Plan 1, Entra ID P1, Intune, Audit Standard.
  • E5 — $57/user/month: Adds Defender for Endpoint Plan 2, Defender for Cloud Apps, Insider Risk Management, Communication Compliance, Audit Premium (6-year retention), Customer Lockbox, Microsoft Sentinel ingestion.

For regulated industries, E5 is typically more cost-effective than purchasing equivalent third-party tools separately.

Frequently asked questions

What is a Microsoft 365 security health check?

The audit evaluates the security and compliance of your M365 tenant. It focuses on several key areas:

  • Secure Score optimization
  • Permission structures
  • Purview compliance controls
  • DLP policy effectiveness
  • Incident response readiness

Most organizations discover 15–30 critical gaps during their first audit.

How long does the health check take?

A standard health check takes 2–3 weeks. The process is divided into three weeks:

  • Week 1: Data collection and automated scanning.
  • Week 2: Manual review and analysis.
  • Week 3: Findings documentation and delivery of the remediation roadmap.

What are the most common gaps found?

Conditional Access not enforced for non-admin users, anti-phishing policies not configured, audit logging with insufficient retention, sensitivity label coverage below 30%, and Privileged Identity Management not deployed for admin accounts.

Do you provide a remediation roadmap?

Yes. Every health check delivers a prioritized remediation roadmap with effort estimates, licensing implications, and recommended implementation sequence. EPC Group can also deliver remediation as a follow-on engagement.

Does the health check cover Copilot readiness?

Yes. Copilot readiness is a core component. It checks Restricted SharePoint Search configuration, sensitivity label coverage, oversharing exposure, Purview AI Hub setup, and Microsoft Sentinel Copilot analytics rules.

Schedule a health check

Talk to an EPC Group security architect about your M365 security posture. Call (888) 381-9725 or request a discovery call.

Why EPC Group for M365 Security

EPC Group has been a Microsoft partner since 2000 (Gold Partner 2000–2022, Solutions Partner today) with over 10,000 implementations across the most security-sensitive industries. Our founder, Errin O'Connor, is a 4x bestselling author (Microsoft Press / Sams) and former NASA Lead Architect who designed security architectures for mission-critical systems.

Get Your M365 Security Health Check

Schedule a 30-minute call to discuss your M365 security posture, compliance requirements, and Secure Score. We will recommend the right assessment tier and timeline.

Schedule Security Assessment

Or call us directly: (888) 381-9725

Microsoft 365 Strategy: 2026 Considerations for Blog Microsoft 365 Security Compliance Health Check

In 2026, the choice between Microsoft 365 GCC High and Commercial tenant affects a contractor's ability to manage Controlled Unclassified Information (CUI) for federal work. This is crucial under CMMC Level 2, which requires 110 NIST 800-171 controls, or Level 3, which requires 134 controls.

GCC High costs about twice as much as the commercial version, ranging from $23 to $57 per user per month. However, it is essential for any DoD prime or sub-prime contractor handling CUI.

Choosing between Microsoft 365 E5 and E3 in 2026 is mainly about security and compliance. The E5 plan costs $57 per user per month and includes:

This complete set offers about $35 per user per month in added value if you choose E3 with add-ons. For regulated industries, the E5 bundle is often more cost-effective than the equivalent E3 options.

Decision factors EPC Group evaluates

For a tailored read on this topic in your specific tenant, contact EPC Group at contact@epcgroup.net or +1 (888) 381-9725. Engagement options at /pricing.

AI assistant — not human