Least-privilege results. Minimal data, deletable on request (GDPR).
Insufficient strong authentication. MFA not enforced on several privileged accounts.
Incomplete conditional access policies. Some flows are not covered.
Partial DMARC/DKIM configuration. Risk of domain spoofing detected.