No charge, no obligation
A written review of your Microsoft 365 tenant.
Access you grant and revoke, no obligation, and you keep what we find whether or not you ever speak to us again.
Most businesses have no clear picture of how their Microsoft 365 tenant is configured. Not through negligence — it accumulates. Someone enables a feature, a consultant sets up a policy, a starter is given a licence nobody reviews, a folder is shared with a link that never expires.
What we look at
Where sign-in is protected and where it can be bypassed. What is shared inside the organisation and outside it. Where licences are going. Who holds administrative rights. Whether your domain can currently be used to impersonate you.
We follow what we find rather than working a fixed checklist, because the thing worth telling you about is rarely the same twice — and it often turns out to be your devices, or an application somebody connected years ago and nobody has looked at since, rather than anything in the list above. Oversharing is usually the one that causes the most surprise.
What we can and cannot see
You install an application into your tenant, and you remove it when you are done. No password, no account created for us, nothing left behind — a consent you grant and can withdraw in a couple of clicks, including the moment you have the report.
The reading is done by a tool rather than a person with your credentials, and it is built to collect and nothing else. There is no part of it that creates, edits or deletes, because we never wrote one.
Access to read one thing sometimes comes bundled with more. Where it does, we use only the part we need — so the consent screen can list more than we will ever touch. Read it before you approve. It is the accurate list, and it is in front of you rather than in a paragraph on our website.
We ask for no access to your mail, so reading it is not something we could do. We do not open your documents — that one is a commitment rather than a limit, and we would rather say so than let you assume otherwise.
You do not have to take our word for either. Everything the application does appears in your own audit log, under its own name, during and after.
What it does not cover
- Your network, firewalls and servers. This is your Microsoft 365, not your infrastructure.
- Line-of-business applications that sit outside Microsoft 365.
- A penetration test. It is a configuration review, not an attempt to break in.
- A compliance audit. It will tell you a good deal about how you would fare in one, but it is not certification against anything.
What you get
We come back to you with what we found and what we would do about it, in plain English and in the order we would deal with it. What we will not hand you is a list of settings to go and change: security settings have consequences that are not visible from the setting itself, and the quickest way to lock a company out of its own systems is to tighten the wrong one on a Friday afternoon. Where you want something put right, we will tell you what it takes.
You get that whether or not you become a customer. We will follow up once to ask what you made of it — that is why we offer it — and if the answer is no, or not now, that is where it ends.
If you cannot grant the access
Approving an application needs an administrator, and you may not hold that — your current provider may. Say so when you ask rather than going round the houses with them: there is a less formal version we can do from what can be seen without it, and some of what is worth knowing needs no access at all.
The same goes if you are not on Microsoft 365. Tell us what you do run and we will say honestly whether we can be useful about it.
How to get one
We run a limited number of these each month, because the analysis is quick and writing something genuinely useful about it is not. Ask here and we will come back with a date and the access request.
Request a review
This form needs JavaScript, because the spam check does — so rather than have you fill it in and find there is no way to send it, we have taken it away.
Email hello@puzzletech.co.uk for anything to do with sales, or help@puzzletech.co.uk if you are already a customer and need support. Or call 01480 570339. All of them reach the same place, and none of them is slower.
Questions people ask
- What access do you need?
- Access to your Microsoft 365 tenant, granted by you to an application and revocable at any point. You do not hand over a password, and a tool does the reading rather than a person. We read; we do not change anything. Access to read one thing is sometimes bundled with more, so the consent screen may list more than we use — read it before you approve, and check what we did in your own audit log afterwards.
- How long does it take?
- We agree a date with you when you ask. Most of the analysis is quick; the time goes into reading the results and working out which of them actually matter to you.
- Is there a catch?
- No obligation to buy anything. We will follow up once to ask what you made of it, because we are an IT company rather than a charity and that is the point of offering it — but a no, or a not now, ends it there. If you take the report and fix things yourself, that is a fine outcome.
- What if you find nothing?
- That has not happened yet. Nobody's tenant is clean, including the well-run ones. What varies is whether the findings are serious, and we will tell you plainly when they are not.
Request the review
Tell us roughly how many users you have and we will send you the access request.