EXEMPLE : entreprise et chiffres inventés. Ce document montre la forme exacte du rapport livré, ce n’est pas un audit réel.
Les 5 lectures du même audit : Pour le dirigeant · Pour le RSSI · Pour l'informaticien · Pour le DPO / la conformité · Pour l'assureur / le donneur d'ordre
SYAGA AuditMicrosoft 365 · Édition souveraine
Entreprise Démonstration (exemple, non client)
Reference SYAGA-DEMO-QUESTIONNAIRE-0001
Audit date 17 juillet 2026
Issued by SYAGA CONSULTING
Diagnostic de posture

Your 85 gaps are not 85 problems.

They come down to four root causes. Address them in order and you neutralize the bulk of the risk with focused effort, without redoing everything.

70/100
To be strengthened
a real foundation, but one critical gap remains open
67
Sujets distincts
4
Chantiers
280
Contrôles tranchés
63
Non collectés (angle mort)
92%
Correctifs gratuits
The 63 controls not collected. They could not be measured during this scan: neither failure nor compliance, a blind spot excluded from the score. The reason for each one appears in your audit's collection log.
Répartition par gravité

Severity is what counts, not just the number.

Your 85 gaps come down to 67 distinct issues, broken down by severity (one setting = one severity, taken at its worst level) on the NIST SP 800-30 impact scale.

Critique 1
Élevée 22
Moyenne 41
Faible 3
Critique : 1Élevée : 22Moyenne : 41Faible : 3
1 écart critique à traiter en priorité
Objectif non atteint aujourd'hui : MFA exigé pour tous les utilisateurs via une politique d'accès conditionnel
Par quoi commencer

4 chantiers, un seul ordre logique.

Positioned by their impact (risk reduction) and their effort. Impact comes first (higher = higher priority); at equal impact, effort decides (further left = faster).

Vite fait, fort impact
Fort impact, plus lourd
Rapide, impact ciblé
À planifier
1
2
3
4
Impact fort ↑
Impact faible
Effort faible
Effort élevé →
  1. 1Configuration & compliance34 écarts
  2. 2Identity & access31 écarts
  3. 3Detection & monitoring14 écarts
  4. 4Data & exposure6 écarts
Bubble size = number of gaps in the workstream. Order of treatment: impact first (from top to bottom), effort decides at equal impact (leftmost first).
La réduction

85 contrôles en écart, 67 sujets distincts, 4 chantiers.

The same weakness reappears in several places. Deal with the cause and you close several gaps at once.

1
Configuration & compliance
Moderate34
2
Identity & access
Major31
3
Detection & monitoring
High14
4
Data & exposure
High6
Your first three decisions

Concentrate the effort where it pays.

1

Configuration hardening

an unhardened baseline silently widens the attack surface, with no visible alert.

Écarts
34
No purchase
33 / 34
Impact
Moderate
2

Identity and access

account takeover is the most common entry point for an attack; it is the only theme where a limited effort closes an entire class of risks at once.

Écarts
31
No purchase
30 / 31
Impact
Major
3

Monitoring and logging

without active detection or complete logs, an attack can succeed without being blocked, spotted in time, or proven afterward: a direct handicap in the event of an incident, a regulatory inspection, or an insurance claim.

Écarts
14
No purchase
12 / 14
Impact
High
Why our score, not Microsoft's
Microsoft's Secure Score measures the adoption of Microsoft controls, not real risk. A vendor cannot be both judge and party in the matter of its own security: our reading is independent.
Our reading is based on the public and neutral NIST SP 800-30 Rev.1 scale. Source : csrc.nist.gov/pubs/sp/800/30/r1/final
What remediation really costs

What matters most cannot be bought.

Of your 85 costed gaps, the share that is fixed by configuration alone, with no licence.

78
correctifs gratuits : simple configuration, 0 € (MFA, authentification forte, journalisation)
7
licence Microsoft

The 7 gaps that require a licence

  • Microsoft Purview DLP (Office 365 E3/E5)3
  • Microsoft Defender pour Office 365 P13
  • Microsoft Entra ID P11

Audit indépendant. We separate what can be fixed at no cost from what requires a purchase from Microsoft, and every licensed gap can also be handled with a alternative tierce ou souveraine, depending on your context. You decide with full knowledge of the facts.

Acting: the price of peace of mind

Presque rien.

78 of your 85 gaps are settled by configuration alone, at 0 €. What matters most in your security cannot be bought.

  • MFA, authentification forte, journalisation : gratuits, quelques heures de paramétrage.
  • 7 gaps call for a Microsoft licence, or an equivalent sovereign alternative.
  • The effort concentrates on the first 3 causes: risk falls quickly.
Doing nothing: the bill arrives 3 times

Three bills, not one.

Refusing to act now does not save you the compliance work: you will pay for it quand même, after the incident, on top of everything else.

  • 1The ransom. Ransomware encrypts your data: pay, or rebuild everything.
  • 2The DPC fine. Up to EUR 20 million or 4% of annual worldwide turnover (GDPR Art. 83).
  • 3The hardening refused today. Still to be done afterwards, in a rush and at full price.
Penalty ceiling: Regulation (EU) 2016/679 (GDPR), art. 83. The rest depends on your line of business.
Outside public frameworks

What we measured, without being able to hold it against a standard.

These 29 findings are real and measured on your tenant, but no public framework names them: this is our reading, not an enforceable rule. They are therefore excluded from the score and from the attestation. We give them to you because they are true.

Hardening measures we recommend (29)
  • La méthode d'authentification par code à usage unique envoyé par e-mail (E-mail OTP) est-elle désactivée ?
  • Des limites de messages sortants sont-elles définies dans la politique anti-spam sortante pour contenir un compte compromis ?
  • Les utilisateurs standards sont-ils empêchés de créer eux-mêmes des groupes de sécurité ?
  • La consultation en libre-service des clés de récupération BitLocker par les utilisateurs est-elle restreinte ?
  • Le rôle Global Administrator est-il exclu de l'attribution automatique d'administrateur local lors de la jonction d'un appareil à Entra ID ?
  • and 24 more, detailed in the technical reading
Le plan

Trois temps, un cap.

First

Configuration hardening

The strongest risk-eliminated / effort ratio. Until this is done, the rest protects a house whose door remains open.

Then

Identity and access

Once the first lever is secured, we reduce the surface through which the risk materializes.

Then

Monitoring and logging

What remains is to anchor these gains over time: governance, regular reviews and retained evidence, so the posture holds over time and not just on audit day.

Optional SharePoint add-on (3 control(s))
Complément optionnel : Microsoft ne propose pas de mode lecture seule pour ces réglages SharePoint par site - y accéder exige un droit d'écriture (limite Microsoft, pas la nôtre). Désactivé par défaut, disponible en option de votre côté, et hors score tant que non activé.
These controls count as NEITHER compliant, NOR non-compliant, NOR uncollected: they remain out of the score until you enable the add-on (at your initiative, on your side, never on ours).
Not applicable: feature not present on the tenant (24 control(s))
These controls do not apply to your tenant: the relevant feature (Microsoft Entra ID P2 / Governance license, or a product like Copilot, Sentinel, Defender for Endpoint, Power Platform...) is not present. There is therefore nothing to measure: this is neither a failure nor a blind spot.
These controls count as NEITHER compliant NOR non-compliant: this is an observation, not a failure. We do not encourage you to buy an additional license: the security objective targeted can often be achieved otherwise (configuration, internal procedure, or a third-party tool sometimes free and less costly). They would become measurable again if the resource were present on your tenant.
6 point(s) de vigilance organisationnels
These requirements (physical security, network segmentation, awareness, governance) belong to the organisation and are NOT measurable by a read-only Microsoft 365 scan. They are reported separately, outside the score and outside the gap count: to be checked by an internal review.
To go further
This audit measures your posture. It does not yet say whether an attack is possible - or already underway silently.
The coverage above answers: where are you exposed? Two higher-value questions remain open:
Is an attack POSSIBLE? Privilege escalation paths: accounts, roles, OAuth consents, federation, external invitations.
Is an attack ALREADY UNDERWAY? Silent compromise: forwarding rules, over-consents, administrator additions, audit bypasses.
Answering these requires a dedicated manual investigation, carried out on the same signals and without exposing your data. Request a quote for a targeted penetration test.
SYAGA AuditDiagnostic de posture Microsoft 365 · système zéro-knowledge · lecture indépendante NIST SP 800-30
Audit reproductible
Your data in plain text is never transmitted
Reading calibrated for executive management. The same audit comes in CISO, technician, compliance and insurer versions: one measurement, five narratives, plus a complete file.