Somebody set up your Microsoft 365 tenant. Nobody has read it since.

Not because anyone was careless. A tenant that works asks nobody to look at it. Saint Sync reads yours: what is actually enforced, what is quietly exposed, and what a stranger could reach today. Then fixes it, in the order that matters.

  • Forty minutes to read it.
  • One page to explain it.
  • Yours either way.

What we check, and what we usually find

SS-01Rev 2026.2
One row per configuration check: its number, the check itself, the finding we most often record against it, and a remark on why that finding turns up.
No. Check Typical finding Remark
01 Multifactor enforced, everyone Partial Exemptions added once and never removed
02 Legacy authentication closed Open Left on for equipment long since retired
03 Administrator accounts Excess Including people who left, and their sessions
04 Devices enrolled and encrypted None Personal laptops holding company records
05 A copy the tenant cannot reach Absent Microsoft protects the service, not your files

These are what we find most often in tenants that were configured once and not read since. Yours takes about forty minutes to check, and the report is yours whether or not you hire us.

How it works
01

Read

You grant read-only access from your own admin account. No agent, no install, nothing changed in your tenant. We check what is actually enforced against what everyone assumes is enforced. About forty minutes.

02

Report

One page, in plain language: what is exposed, what it would cost us to fix, and what you can fix yourself for nothing. No severity scores nobody can act on, and no findings padded in to make the list look longer.

03

Fix

We work the list in the order that actually reduces risk, starting with identity and then whatever your tenant needs. We write down what changed as we go, so the next person to read it is not starting from nothing.

We support what we configure. Changing security settings creates friction: lockouts, prompts, a restore someone needs today. Handing a client that friction with nobody to call is not a service.

Why nobody has read it

The tenant works. That is the problem.

A Microsoft 365 tenant that is broken gets attention within the hour. One that is merely wide open works perfectly. Mail arrives, files open, nobody calls. So nobody looks.

Meanwhile the configuration drifts, one reasonable decision at a time: an exemption added for one person during one bad week and never removed, a legacy protocol left enabled for a scanner that was decommissioned years ago, an administrator account still belonging to a contractor whose project finished last spring. None of it shows up in a status page. Reading the configuration is the only way to find it, and almost nobody does. That is why forty minutes usually turns up more than anyone expects.

Schematic: a Microsoft 365 tenant configured once and not read since, its identity, access and data settings carrying typical findings, with a read-only assessment reading the configuration and issuing a one-page report.
Who we do this for

Two kinds of tenant, one job.

Nonprofits

Grant licensing that changed under you, a board that needs an answer in plain English, and donor data sitting in a tenant nobody has audited. Tampa nonprofits are where this practice started.

Businesses

You may already have an IT provider keeping things running. Reading the security configuration they inherited is a different job, and it is usually nobody’s.

Where we focus

Microsoft 365, read properly.

Our work sits inside Microsoft 365: identity, access, data and the configuration that governs them. That focus is the reason the assessment finds things a generalist misses: it is the same surface every week, and we know what a well-run tenant is supposed to look like. When an engagement needs something outside it, we say so on the first call and either bring in someone we trust or tell you plainly that it isn't ours.

Start with the assessment

Forty minutes. No obligation. The report is yours.

We read your tenant’s configuration. Nothing is changed. We send back a plain-language list of what is exposed, what it would cost to fix, and what you can fix yourself for free.

If you hire us for the fixes, the work is priced the way the report reads: a fixed price for a project, a flat monthly fee for ongoing work, and no hourly meter.

What we can see

Configuration only: whether multifactor authentication is registered, whether legacy protocols are blocked, how many devices are enrolled, which applications are consented, and what your subscriptions include. We read the settings, not the contents.

What we cannot do

Nothing can be changed, created or deleted. The permissions granted are read-only, and the tool that uses them has no ability to write. We cannot read your mail, your files or your messages, and we cannot send anything as anyone in your organization.

How to revoke it

In the Microsoft Entra admin center, open Enterprise applications, find Saint Sync in the list, and delete it. That removes our access immediately. You do not need to tell us, and you do not need our help to do it.

Or email us directly: info@saintsync.io

We’ll use your address to send the report and arrange the assessment. Nothing else, and no mailing list.