Know before you need to know.

Microsoft 365 Security & Operations Assessment

A structured review of the technology your business depends on every day.

Microsoft 365 grows quietly.

“Is this actually configured the way it should be?”

Accounts are added. Employees leave. Administrators change. Files are shared. Guests accumulate. Licenses expand. New applications are connected.

And eventually someone asks that question.

icoSTL helps you answer it.

Starting at $995 Fixed fee, scoped by user count.

Assessment scope

What we review.

  • Identity
  • Authentication
  • Administrative Access
  • Email
  • SharePoint
  • OneDrive
  • Teams
  • External Sharing
  • Auditing
  • Licensing
  • Employee Lifecycle
  • Governance
  • AI Readiness

What you receive

Findings you can act on.

01

Executive Summary

A plain-language overview written for leadership, not for administrators.

02

Risk Dashboard

A structured view of what was reviewed and where attention is needed.

03

Prioritized Findings

Each finding rated by business impact, so the list has an order.

04

30-Day Roadmap

A practical sequence for what to address first, and what can wait.

What we found.

Why it matters.

How important it is.

What should happen next.

Transparent pricing

Fixed fee, scoped by size.

1–10 users

$995

51–100 users

$2,500

100+ users

Custom

Scoped with you

No forced upsell

The report stands on its own.

You can fix findings internally, hand the report to your current IT provider, or engage icoSTL for remediation.

The assessment is valuable even if icoSTL never performs another hour of work.

Common questions

Before you start.

How long does the assessment take?

Most assessments are completed within two weeks of receiving access. Larger or more complex environments may take longer, and we will tell you before starting if we expect that to be the case.

What access do you need?

The assessment is primarily read-only. We request delegated or scoped administrative access sufficient to review configuration, and we agree the specific level of access with you in writing before any review begins.

Will this disrupt our environment?

No. The assessment reviews configuration and reports on it. We do not change settings during the assessment unless you explicitly ask us to and agree the change separately.

Do we have to buy remediation work afterwards?

No. You can address findings internally, hand the report to your existing IT provider, or engage icoSTL. The report is yours either way.

Does this replace a penetration test or a compliance audit?

No. This is a configuration and operations review of your Microsoft 365 environment. It is not a penetration test, and it is not a certification or compliance audit.

Be ready before you need to be.

Start with a 20-minute conversation.

We will talk through your environment, confirm scope, and give you a fixed price before any work begins.