FR — EN Get in touch
The method — non-intrusive, written, remote

How it works, day by day.

An audit shouldn't break anything, slow anyone down or demand your team's time. Here is exactly what you provide, what I look at, what I never do — and when you receive what.

D + 0

Scoping — thirty minutes, on a call or in writing

We pin down the need and I send you the written scope: what will be examined, what won't, and the timeline. Nothing starts without your sign-off on that document.

YOU PROVIDE — ONE READ-ONLY ACCOUNT (GUIDED, 10 MIN)
D + 2

Analysis — remote, zero disruption

I review the fifteen checks: authentication, privileged accounts, dormant accounts, external sharing, audit logs, leavers. Your team sees nothing, feels nothing.

BASELINES — CIS M365 FOUNDATIONS · ANSSI HYGIENE GUIDE
D + 7

Report and debrief

You receive the scored report and the prioritized action plan, then forty-five minutes to walk through it — recordable. Every verdict justified, every recommendation actionable, in plain language.

YOUR ACCESS IS REVOKED — WITH WRITTEN PROOF
What I never do
  • Change anything in your environment
  • Read the content of your email or files
  • Attempt intrusion or exploit a flaw
  • Keep your data after the engagement

Ethics and GDPR

The read-only account is created by you, logged by Microsoft, and revoked at the end of the engagement — the revocation is recorded in the report. Findings are covered by a confidentiality agreement signed at scoping. No personal data about your employees is extracted: the audit looks at configuration, not people. The report is yours; Aegiren keeps only an encrypted copy, for twelve months, for follow-up.

The analysis relies on public baselines — the CIS Microsoft 365 Foundations Benchmark and the ANSSI hygiene guide — cited check by check in the report. You can verify everything.

A question about the method? Thirty minutes, no strings — reply within 48 h.

Get in touch