1) Email Authentication Deployment
SPF, DKIM, DMARC — deployed and verified.
- SPF validation and correction
- DKIM configuration and activation
- DMARC deployment (monitor policy to start)
- Reporting mailbox configuration
- DNS alignment verification
- Header-level authentication testing
- Written deployment summary
2) Conditional Access Hardening (Microsoft 365)
Identity enforcement baseline + legacy auth control.
- Disable legacy authentication
- MFA enforcement baseline
- Geo-based restriction (optional)
- Admin account protection baseline
- Documentation summary
Requires Microsoft Entra ID P1.
3) Microsoft 365 Security Review
Focused review of identity, admin exposure, and configuration hygiene.
- MFA coverage validation
- Admin role review
- Inactive / guest account assessment
- Secure Score analysis (prioritized)
- Risk-ranked recommendations
- Executive summary
4) Google Workspace Security Baseline
Deployment validation for modern Google environments.
- Admin console configuration review
- MFA / 2SV enforcement validation
- OAuth / app access review
- Security posture recommendations
- Evidence-ready summary