Skip to content

Sample deliverable · No form required

See the technical findings behind the next decision.

Five review areas, evidence from the agreed inputs, and prioritized next steps your IT and security teams can act on.

Illustrative sample—not client findings. All scenarios below are fictional. No real tenant counts, scores, screenshots, or client results are presented.

What the Snapshot puts in your hands

A findings report, an M365 Group exposure exhibit, a Secure Score baseline with relevant recommended actions, and a 30-minute review. A Shadow AI exhibit is included when suitable network logs are supplied and that review is agreed.

Technical outcomes of the Snapshot: a clearer exposure baseline, identified gaps in the available evidence, and priorities with suggested owners. Remediation, control deployment, and the detailed implementation plan are separate work.

Example decision: Validate pilot-data protections and access boundaries before expanding connected AI use. Resolve the monitoring and policy questions with the internal owners during the findings review.

The priorities below illustrate how a report can read. Actual severity depends on the sensitivity, reach, likelihood, and supporting evidence in your environment. The script’s risk tiers and report severity are different measures.

Illustrative findings across the five areas

1. Data security posture

Validate protection for the pilot data

Illustrative priority: High — before pilot expansion

Evidence: An illustrative configuration review shows sensitive pilot documents without consistent labels, and the team cannot demonstrate that the relevant DLP policy is enforcing its intended restrictions.

Report output: Record the labels and policy settings reviewed, their enforcement state, and the unresolved protection question.

Recommended next step: Confirm the pilot data classification and validate the intended policy behavior before adding more users or connected data.

Suggested owner: M365 / Purview administrator, with the information owner.

Scope limit: Configuration evidence alone does not establish effective blocking. A full policy audit and control testing are outside the Snapshot.

2. Data estate and access reviews

Review broad M365 Group access

Illustrative priority: High — validate access first

Evidence: An illustrative read-only script export flags an M365 Group for review based on its access configuration. The team has not confirmed whether that access matches the intended matter boundary.

Report output: Provide M365 Group risk counts by tier from the supplied CSV, describe the indicator behind the flag, and identify the group that needs owner validation. No tenant counts are invented in this sample.

Recommended next step: Have the group and matter owners confirm intended membership, guest access, and sharing; decide whether a deeper permissions review is needed.

Suggested owner: M365 administrator and group / matter owner.

Scope limit: A script risk tier is a review signal, not proof of unauthorized access. The M365 Group view does not cover every SharePoint site or certify ethical walls.

3. Security monitoring coverage

Confirm usable AI activity evidence

Illustrative priority: Medium — resolve before wider adoption

Evidence: In this fictional scenario, the team can show some AI activity records but has not documented which tools they cover, how long records remain available, or who reviews them.

Report output: List the records demonstrated, stated retention, the monitoring owner, and gaps where evidence was unavailable or coverage remains unverified.

Recommended next step: Confirm required activity visibility and retention for the pilot; assign an owner to validate coverage and escalate gaps.

Suggested owner: Security operations / SIEM owner and the relevant AI administrator.

Scope limit: The Snapshot does not prove every AI interaction is logged, test all alerts, or implement monitoring. Available evidence depends on the tool and configuration.

4. Shadow AI exposure

Reconcile external AI activity with approved tools

Illustrative priority: Medium — investigate the context

Evidence: An illustrative client-provided network export contains connections to an external AI service that does not appear on the organization’s approved-tool list.

Report output: Identify the service domains observed, the period covered, and any usable device or user attribution, with the limitations of the supplied logs.

Recommended next step: Validate whether the activity is expected and approved. Agree on the appropriate approved-tool guidance and any further investigation.

Suggested owner: Security operations and the AI governance owner.

Scope limit: This exhibit is conditional on suitable logs and an agreed review. A domain connection does not prove a prompt was entered or confidential data was shared.

5. Secure Score baseline

Select a relevant security action for review

Illustrative priority: Medium — confirm relevance and ownership

Evidence: In this fictional live review, Microsoft Secure Score lists an identity-related recommendation as incomplete. The team has not confirmed its applicability, current configuration, or owner.

Report output: Capture the score at the time of review and the relevant recommendation, displayed status, available supporting evidence, and reason it matters for the rollout.

Recommended next step: Validate the recommendation against the actual environment and any compensating controls; assign an owner and decide the next action.

Suggested owner: Identity / M365 administrator with the security lead.

Scope limit: Secure Score is a baseline signal, not certification of AI security. The Snapshot does not implement the recommended action or guarantee a score improvement.

Use the findings to agree on priorities.

  1. Validate the data-protection and access questions that affect the proposed pilot.
  2. Assign owners for evidence gaps, monitoring, and relevant baseline security actions.
  3. Review external AI activity in context when suitable logs are available.
  4. Decide which next steps your team can own and where deeper analysis would help.

Written findings are delivered within five business days after the working session and receipt of the required inputs, followed by a 30-minute review. There is no purchase obligation.

The free Snapshot is a bounded diagnostic, not a full DLP audit, a complete permissions audit, penetration testing, regulatory certification, or an implementation plan. A paid AI Readiness Assessment can develop the deeper analysis and remediation plan under a separately agreed scope.

See what to prepare