6 min read
What a GoDaddy Defederation Is and How It Works
If your business runs email through GoDaddy, there may come a point where you need more than it can give you. Tighter security, real admin...
4 min read
Nicole Walker
:
Updated on August 19, 2026
Every renewal season, IT teams spend thousands upgrading Microsoft 365 SKUs to close security gaps the new license does not necessarily fix.
The phishing wave that triggered the purchase may have come through a misconfigured tenant, not a missing feature. A bigger bundle sits on top of the same open doors, and the invoice grows without risk changing.
That pattern is showing across Microsoft 365 environments right now. An incident hits, a vendor sends a quote, and the response is a bigger SKU. A Microsoft 365 security assessment changes that sequence. It tells you what is broken before anything new gets added to the bill.
Microsoft includes meaningful security capability inside Business Premium, E3, E5, and the Defender Suite. The problem is what those bundles assume.
Tenants are not hardened by default. Microsoft prioritizes usability in its out-of-box configuration. Legacy authentication is often still enabled. Audit logging is not fully turned on. External sharing runs wide open. Default mail flow lets a surprising amount of unwanted traffic through.
Configuration drift is the second issue. Tenants quietly lose ground as users are added, sites are created, and sharing links are generated. The average enterprise tenant has been running for years without a thorough security review. Most of the gaps found in a first assessment are not exotic attacks. They are settings nobody revisited.
A Microsoft 365 security assessment is a structured review of how identity, email, devices, data, and monitoring are configured, ending with a prioritized list of recommendations. It is not a vulnerability scan. It is not a sales motion in a report.
Done correctly, it separates findings into three categories: exposures already covered by existing licenses but not turned on, exposures that require a new license, and exposures created by drift or misconfiguration. Most of what organizations try to buy their way out of falls into the first bucket.
A credible assessment also benchmarks the tenant against a recognized baseline. Microsoft Secure Score is the most accessible starting point inside the Defender portal and gives a directional read on posture. The CIS Microsoft 365 Foundations Benchmark and Zero Trust deployment guidance are the deeper references most assessments map their findings against.
As a Microsoft Solutions Partner with a Security designation, Sourcepass MCOE consistently sees the highest impact findings surface in the domains below.
Identity is the perimeter. Microsoft telemetry shows that over 99% of account compromises involve no malware. Attackers steal credentials and sign in.
A Microsoft 365 security assessment reviews MFA coverage, Conditional Access policy design, legacy authentication exposure, admin role assignment, and sign-in risk activity. MFA on global admins only is not enough, and admin accounts without MFA remain one of the most common findings in first time audits. Every user needs to be enrolled, and Conditional Access is what enforces it. Phishing-resistant MFA has gone from a new feature to a requirement to prevent account compromise. Attacks against features like Device Code Flow are becoming a very common issue.
Phishing remains the dominant attack vector for small and mid-sized organizations. Two patterns deserve specific attention.
Self-spoofing through weak DMARC is the first. Phishing mail appears to come from the recipient's own domain because SPF, DKIM, and DMARC were never fully enforced. An assessment validates each record and reports the enforcement mode, not just its presence.
Direct send abuse is the second. Direct send is a legitimate Microsoft 365 feature, enabled by default, that lets internal looking mail bypass several inbound protections. Threat actors are now using it to deliver phishing at volume. Disabling it takes one PowerShell command. Finding it takes an assessment.
The Defender for Office 365 Plan 1 policies (anti-phishing, anti-spam, anti-malware, Safe Links, Safe Attachments) get reviewed here as well. They should be tuned, not left at default. This capability was recently added to multiple bundles including Microsoft 365 E3, but many tenants do not have it configured properly.
Defender for Business, Defender for Endpoint Plan 1, and Defender for Endpoint Plan 2 cover endpoint security. The right choice depends on what is already deployed and how the environment is managed.
Defender for Business, included in Business Premium, delivers roughly 80-85% of Plan 2 capability. Larger environments and regulated industries more often need Plan 2 for advanced hunting, vulnerability management, and richer incident history. Deployment can run through Intune, Group Policy, scripts, or an RMM tool. A Microsoft 365 security assessment confirms which method is in use and verifies onboarding coverage, which is where most real-world gaps live.
SharePoint and Teams external sharing settings, default OneDrive permissions, and audit log retention all get reviewed here. These settings determine whether an investigation is even possible after an incident.
Once the gaps are documented, each finding falls into one of three buckets.
|
Finding category |
Typical action |
Licensing impact |
|---|---|---|
|
Feature already licensed, not configured |
Configure during a hardening engagement |
None, the cost is already sunk |
|
Feature partially licensed across users |
Consolidate to a bundle |
Often net neutral or net savings |
|
Capability genuinely missing |
Targeted add-on or bundle upgrade |
Justified spend, mapped to a specific risk |
A tenant on E3 with multiple standalone security add-ons often consolidates into Business Premium (under 300 seats) or Business Premium plus the Defender Suite, frequently at a lower total cost. A tenant already on Business Premium with heavy phishing pressure rarely needs a new license. It needs Defender for Office 365 Plan 1 properly configured and email authentication fully enforced. A tenant facing advanced threats may genuinely need Defender Office 365 Plan 2 capabilities and Entra ID Plan 2 controls that come with Defender suite.
An assessment turns licensing into a decision grounded in evidence.
An assessment without remediation loses value quickly. Pair it with a hardening engagement that closes the high impact, low effort findings first. Those typically include addressing MFA coverage gaps, baseline Conditional Access, legacy authentication blocking, DMARC enforcement, direct send, audit logging, external sharing defaults, and Defender policy tuning.
More complex controls belong on a roadmap rather than in a sprint. They require business input and testing. Closing the straightforward gaps first delivers more security value than perfecting the harder ones.
There is no fixed cadence that fits every environment, but a yearly review is a reasonable floor, with an out of cycle assessment any time the tenant changes shape. If any of the following is true, the next move is an assessment, not a purchase order.
Any one of these is enough to justify an assessment first.
The right Microsoft 365 license mix is a decision, not a default. An assessment shows what is already owned, what is needed, and what is about to be overspent on. Skipping is not a faster path. It usually leads to higher cost and weaker protection.
Sourcepass MCOE runs these assessments as a Microsoft Solutions Partner with designations in Modern Work and Security, and a Secure AI Productivity specialization.
If a renewal is on the horizon or a recent incident is pushing a bigger SKU into the conversation, an assessment is the step that comes first.
6 min read
If your business runs email through GoDaddy, there may come a point where you need more than it can give you. Tighter security, real admin...
5 min read
Plenty of teams are paying for Exchange add-ons, third-party security tools, and separate compliance licenses that Business Premium now covers on...
5 min read
Microsoft Copilot changes almost every day, and that speed leaves many IT leaders unsure how to train their teams, budget for usage, or prove a...