MSP playbook

Running Microsoft 365 assessments as an MSP: packaging, pricing and QBRs

Where assessments fit in the customer lifecycle, how to package them, what to show in a quarterly business review, and how findings become scoped projects.

On this page

Most MSPs already do some form of Microsoft 365 review: at onboarding, before a renewal, after an incident. The difference between that and an assessment service is repeatability. The same checks, run the same way for every customer, on a schedule, with results you can compare over time.

This guide covers the operating model. For the pricing models themselves, see how to price Microsoft 365 security assessments.

Where assessments fit in the customer lifecycle

Assessment moments in the MSP customer lifecycle
MomentPurposeWhat the customer gets
Pre-salesShow competence with evidence, not a slide deckA summary of their top risks and a proposal
OnboardingRecord the starting point before you change anythingA baseline report and a first-90-days plan
Quarterly reviewShow progress and surface new driftTrend, what changed, next priorities
Project scopingSize remediation work accuratelyA scoped statement of work tied to findings
After a project or incidentProve the change landedA before-and-after comparison

The onboarding baseline deserves special attention. Without it, every issue you find later looks like something that happened on your watch.

Getting access the right way

An assessment should never require the customer's Global Administrator password, and it shouldn't need write access. Two patterns are common:

  • Granular delegated admin privileges (GDAP) through Microsoft Partner Center, with least-privileged, time-bound roles. Microsoft's GDAP introduction explains the model; read-only roles such as Global Reader are enough for review work.
  • Customer-approved applications, where the customer's administrator consents to an assessment app with read-only permissions, and can remove it at any time from Enterprise applications in Microsoft Entra.

Either way, tell the customer exactly what is being read and why. Security-conscious customers will ask, and a clear answer is part of the service.

Packaging the service

1. The standalone assessment (prospects and project customers)

A fixed-scope, fixed-price engagement: run the assessment, review the findings with an engineer, and present a short report and a remediation proposal. Keep the scope written down (which workloads, how many users, what's out of scope) so it can't expand into free consulting.

2. The included quarterly review (managed customers)

Build a recurring assessment into the managed service agreement. It justifies the monthly fee with visible evidence, catches configuration drift early, and gives every quarterly business review (QBR) an agenda. Customers rarely object to paying for something they see every quarter.

3. Project scoping

Use the assessment to scope and quote remediation: a Conditional Access rollout, Intune enrollment, email authentication, a sharing clean-up. Findings give you counts (devices, users, sites) that make estimates defensible.

What each deliverable should contain

  • A one-page summary for the business owner: overall posture, top three risks in plain language, and the decisions you need.
  • Prioritized findings with severity, the affected objects or counts, and a recommended fix.
  • A remediation timeline: fix now, this quarter, later.
  • Technical detail for the customer's IT contact or your own engineers, kept separate from the summary.

Pricing in brief

There's no single right price, but there are three sound models, and many MSPs combine them:

  • Fixed fee per assessment, tiered by tenant size or scope. Simple for prospects to approve; make sure the fee covers the engineer's review and the presentation, not just the run.
  • Included in the managed service, priced into the per-user or per-device fee. Best for recurring reviews, because the customer never has to approve each one.
  • Credited against remediation, where the assessment fee is deducted if the customer approves the resulting project within a set period.

Work out your own cost per assessment first (tool cost plus engineer time for review, write-up and meeting), then set a price with a margin you'd be comfortable repeating every quarter. Our guide to pricing Microsoft 365 security assessments walks through the calculation and the tiers.

Running the quarterly business review

A QBR built on assessment data has a natural structure. Keep it to 30–45 minutes:

  1. Where we are (5 minutes). The trend since the baseline: high and medium findings over time, and Microsoft Secure Score with context. Explain any jump or drop.

  2. What we fixed (5 minutes). Completed actions and the risks they removed, in business terms. "Stolen passwords can no longer be used on their own to reach email" lands better than "MFA enforced via CA".

  3. What's new (10 minutes). Findings that appeared since last quarter: new admins, new guest access, new devices out of compliance.

  4. Top three risks and the decisions needed (15 minutes). For each: the risk, the fix, the effort and cost, and what happens if it waits.

  5. Agree and record (5 minutes). Approved, deferred with a date, or risk accepted by a named person. Write it down and send it the same day.

Tip

Put the technical appendix in the pack, but don't present it. If the customer's IT contact wants to go deep, schedule a separate working session.

Turning findings into projects

A finding on its own is a problem statement. To get it approved, turn it into a project with a name, a scope and a price:

Examples of findings mapped to projects
FindingProjectScope drivers
Users without MFA; legacy authentication allowedConditional Access baselineUsers, service accounts, legacy clients to replace
Devices without compliance policies; no disk encryptionIntune compliance and encryptionDevices per platform, enrollment method
No DMARC; DKIM not enabledEmail authenticationSending domains, third-party senders
Many "Anyone" links; guests never reviewedSharing and guest clean-upSites, links, guest accounts
Permanent Global AdministratorsPrivileged access and break-glassAdmin accounts, P2 licensing

Licensing is often part of the answer. A customer on a plan without Conditional Access or Defender may need an upgrade before the project is possible. Our Business Premium vs E3 vs E5 comparison helps explain which plan includes what.

Making it repeatable

  • Standardize the checks. The same baseline for every customer, versioned, so results are comparable. Our assessment checklist is a starting point.
  • Standardize the language. A library of finding descriptions and recommended fixes keeps reports consistent across engineers.
  • Schedule it. Put the next assessment in the calendar when you present the current one.
  • Review before you send. A second pair of eyes on the summary catches findings that are technically true but misleading in context.
  • Keep the history. The value of assessment number four is that you can compare it with one, two and three.

Pitfalls to avoid

  • Handing over a 60-page export and calling it an assessment.
  • Findings with no owner or date, so nothing happens after the meeting.
  • Scoring the customer against settings they aren't licensed for without saying so.
  • Over-promising: an assessment reviews configuration; it isn't a penetration test or a compliance certification.

How M365Assessments helps

M365Assessments is built for this model. Each customer approves its own tenant with read-only modules (no shared credentials, no GDAP needed), MSP plans cover 10, 50 or 100 tenants with a monthly assessment allowance, and schedules re-assess customers automatically. Every run produces an HTML report plus Word and PowerPoint deliverables for the QBR, and comparisons show what changed. On MSP 50, MSP 100 and Enterprise, reports can carry your branding and a Sales Guide turns findings into priced projects. See M365Assessments for MSPs and pricing.

See where a tenant stands in minutes

M365Assessments runs these checks for you with read-only modules and turns them into a prioritized, plain-English report.

Requires a Microsoft Entra ID (work or school) account.