Your IT provider keeps it running. Reading it is our job.
Your Microsoft 365 tenant was configured once, probably years ago, and whoever looks after it now inherited whatever they found. Running well and being sound are not the same thing, and only one of them shows up in a ticket queue. We read the configuration independently and tell you what is actually there.
Keeping it running is a different job
If you have an IT provider, they are measured on uptime, tickets and delivery, and mostly they do that well. Reading the security configuration they inherited from whoever came before, and checking it against what it should be, is separate work that is rarely anyone’s explicit responsibility. That is the gap we fill, and it is not an accusation against your provider.
Independent, and read-only
We are not bidding to replace anyone. The assessment is read-only. No agent, no install, nothing changed. The report goes to you, not to your provider, unless you hand it to them. Plenty of clients take our findings straight to their existing MSP and have them do the work. That is a fine outcome.
What we usually find
Multifactor authentication enforced for most people but not the accounts that matter, legacy protocols left open for equipment long since retired, administrator rights held by people who left, and no copy of the data anywhere the tenant cannot reach. Rarely anything exotic. That is what makes it worth reading.
Read
You grant read-only access from your own admin account. No agent, no install, nothing changed in your tenant. We check what is actually enforced against what everyone assumes is enforced. About forty minutes.
Report
One page, in plain language: what is exposed, what it would cost us to fix, and what you can fix yourself for nothing. No severity scores nobody can act on, and no findings padded in to make the list look longer.
Fix
We work the list in the order that actually reduces risk, starting with identity and then whatever your tenant needs. We write down what changed as we go, so the next person to read it is not starting from nothing.
We support what we configure. Changing security settings creates friction: lockouts, prompts, a restore someone needs today. Handing a client that friction with nobody to call is not a service.
What we check, and what we usually find
SS-01Rev 2026.2| No. | Check | Typical finding | Remark |
|---|---|---|---|
| 01 | Multifactor enforced, everyone | Partial | Exemptions added once and never removed |
| 02 | Legacy authentication closed | Open | Left on for equipment long since retired |
| 03 | Administrator accounts | Excess | Including people who left, and their sessions |
| 04 | Devices enrolled and encrypted | None | Personal laptops holding company records |
| 05 | A copy the tenant cannot reach | Absent | Microsoft protects the service, not your files |
These are what we find most often in tenants that were configured once and not read since. Yours takes about forty minutes to check, and the report is yours whether or not you hire us.
Microsoft 365, read properly.
Our work sits inside Microsoft 365: identity, access, data and the configuration that governs them. That focus is the reason the assessment finds things a generalist misses: it is the same surface every week, and we know what a well-run tenant is supposed to look like. When an engagement needs something outside it, we say so on the first call and either bring in someone we trust or tell you plainly that it isn't ours.
Forty minutes. No obligation. The report is yours.
We read your tenant’s configuration. Nothing is changed. We send back a plain-language list of what is exposed, what it would cost to fix, and what you can fix yourself for free.
If you hire us for the fixes, the work is priced the way the report reads: a fixed price for a project, a flat monthly fee for ongoing work, and no hourly meter.
What we can see
Configuration only: whether multifactor authentication is registered, whether legacy protocols are blocked, how many devices are enrolled, which applications are consented, and what your subscriptions include. We read the settings, not the contents.
What we cannot do
Nothing can be changed, created or deleted. The permissions granted are read-only, and the tool that uses them has no ability to write. We cannot read your mail, your files or your messages, and we cannot send anything as anyone in your organization.
How to revoke it
In the Microsoft Entra admin center, open Enterprise applications, find Saint Sync in the list, and delete it. That removes our access immediately. You do not need to tell us, and you do not need our help to do it.
Or email us directly: info@saintsync.io
We’ll use your address to send the report and arrange the assessment. Nothing else, and no mailing list.