For regulated financial & legal firms

Microsoft 365 Compromise Assessment

Seen something that doesn’t sit right — an unexpected login alert, a client replying to an email you never sent, a password reset you didn’t request? You don’t have to wonder. Our Compromise Assessment reviews the recent activity in your Microsoft 365 tenant for the specific signs of account takeover and tells you plainly whether someone has been in your environment. Provided at no cost to qualified financial and legal firms.

What We Look For

Inbox rules that hide an intruder’s tracks


Attackers who get into a mailbox often create hidden rules that quietly delete or forward mail so their activity never surfaces. We review every inbox and forwarding rule so each one can be confirmed as legitimate.

Apps granted access you didn’t approve


A common way attackers keep a foothold is by tricking a user into granting a malicious app permission to your data. We review every OAuth app consent for grants that don’t belong.

Sign-ins that don’t add up


Logins from unexpected countries, two locations minutes apart, or legacy protocols that slip past multi-factor are classic takeover indicators. We review recent sign-in activity for anomalies worth explaining.

Quiet changes to MFA and admin access


Registering a new multi-factor device or adding an administrator role is exactly what an attacker does to lock in access. We check for changes to MFA registration and privileged roles that no one on your team made.

What was opened — mail, files, and sites


Getting in is only half the question — what an intruder reached is the other half. Using the available audit and access logs, we identify which mailboxes, SharePoint sites, and OneDrive files were opened during the period in question, so you know what was actually exposed, not just that access occurred.

What was sent or taken out


We look for the signs that data left your tenant — mail auto-forwarded to outside addresses, files shared to external parties, or bulk downloads — so you have a clear picture of what may have been exfiltrated and what it means for your firm.

What You Receive

Compromise Assessment Findings Report


A concise report in plain language: either a clean bill of health, or the specific indicators we found — each one explained, with prioritized next steps.

Advisor Review


A working session with a Go West IT advisor to walk through what we found and what it means for your firm.

If we find evidence of an active or past compromise, we won’t leave you to figure out the next step. We’ll explain exactly what it means and the fastest, safest path to contain it.

SOC 2 Type II  ·  Microsoft Partner — Modern Work, Enterprise  ·  Built for RIAs, banks & law firms

Request Your Assessment


Active Incident/Breach?
We'll only use your details to arrange your assessment and follow up — no spam. Please don't include passwords or account numbers.

The owner of this website has made a commitment to accessibility and inclusion, please report any problems that you encounter using the contact form on this website. This site uses the WP ADA Compliance Check plugin to enhance accessibility.