Lukáš Hofrichtr

For organisations / Microsoft 365

One account must not unlock the entire organisation.

Reduce the impact of an account compromise without creating a configuration that can lock administrators out.

Situation

One compromised administrator can bypass most other controls.

Microsoft 365 often grows from an office tool into the organisation’s main identity system, while roles, exceptions and external access evolve less deliberately.

The assessment looks for excessive privilege and verifies that emergency access still works when normal authentication or a policy change fails.

Who it is for

When Microsoft 365 holds identity, data and remote collaboration.

  • Global administrator accounts are used for daily work
  • MFA exists but exceptions and legacy protocols are not reviewed
  • Conditional Access evolved gradually without a safe emergency path
  • Guests, suppliers and applications retain long-lived permissions

Scope

Limit account impact without blocking operations.

The review covers configuration as well as administration, change approval and recovery when normal access fails.

01

Privileged roles

Scope, administrator count, separate accounts and delegation.

02

MFA and authentication

Methods, registration, exceptions and phishing resistance.

03

Conditional Access

Coverage, policy priority, exclusions and safe deployment.

04

Emergency access

Break-glass accounts, monitoring and secure storage.

05

External access

Guests, suppliers, applications, consent and permission lifecycle.

06

Operations and evidence

Audit logs, alerting, documentation and responsibilities.

Process

A controlled review with minimal tenant impact.

01

Context

Roles, licensing and critical scenarios.

02

Read-only review

Configuration, roles, policies, applications and logs.

03

Priorities

Highest-risk paths and the safe order of changes.

04

Remediation

One agreed change with rollback and documentation.

Important boundary

No uncontrolled changes in production.

Conditional Access and privilege changes can lock out users or administrators. Every implementation needs a test group, emergency access and an agreed rollback.

Next step

Would an independent review of your Microsoft 365 tenant help?

Share the number of users, licences and current operating model. I will suggest a proportionate scope.

lukas@hofta.cz +420 777 127 745 Czech Republic · on-site in Europe · remote worldwide