MSP playbook
Running Microsoft 365 assessments as an MSP: packaging, pricing and QBRs
Where assessments fit in the customer lifecycle, how to package them, what to show in a quarterly business review, and how findings become scoped projects.
Most MSPs already do some form of Microsoft 365 review: at onboarding, before a renewal, after an incident. The difference between that and an assessment service is repeatability. The same checks, run the same way for every customer, on a schedule, with results you can compare over time.
This guide covers the operating model. For the pricing models themselves, see how to price Microsoft 365 security assessments.
Where assessments fit in the customer lifecycle
| Moment | Purpose | What the customer gets |
|---|---|---|
| Pre-sales | Show competence with evidence, not a slide deck | A summary of their top risks and a proposal |
| Onboarding | Record the starting point before you change anything | A baseline report and a first-90-days plan |
| Quarterly review | Show progress and surface new drift | Trend, what changed, next priorities |
| Project scoping | Size remediation work accurately | A scoped statement of work tied to findings |
| After a project or incident | Prove the change landed | A before-and-after comparison |
The onboarding baseline deserves special attention. Without it, every issue you find later looks like something that happened on your watch.
Getting access the right way
An assessment should never require the customer's Global Administrator password, and it shouldn't need write access. Two patterns are common:
- Granular delegated admin privileges (GDAP) through Microsoft Partner Center, with least-privileged, time-bound roles. Microsoft's GDAP introduction explains the model; read-only roles such as Global Reader are enough for review work.
- Customer-approved applications, where the customer's administrator consents to an assessment app with read-only permissions, and can remove it at any time from Enterprise applications in Microsoft Entra.
Either way, tell the customer exactly what is being read and why. Security-conscious customers will ask, and a clear answer is part of the service.
Packaging the service
1. The standalone assessment (prospects and project customers)
A fixed-scope, fixed-price engagement: run the assessment, review the findings with an engineer, and present a short report and a remediation proposal. Keep the scope written down (which workloads, how many users, what's out of scope) so it can't expand into free consulting.
2. The included quarterly review (managed customers)
Build a recurring assessment into the managed service agreement. It justifies the monthly fee with visible evidence, catches configuration drift early, and gives every quarterly business review (QBR) an agenda. Customers rarely object to paying for something they see every quarter.
3. Project scoping
Use the assessment to scope and quote remediation: a Conditional Access rollout, Intune enrollment, email authentication, a sharing clean-up. Findings give you counts (devices, users, sites) that make estimates defensible.
What each deliverable should contain
- A one-page summary for the business owner: overall posture, top three risks in plain language, and the decisions you need.
- Prioritized findings with severity, the affected objects or counts, and a recommended fix.
- A remediation timeline: fix now, this quarter, later.
- Technical detail for the customer's IT contact or your own engineers, kept separate from the summary.
Pricing in brief
There's no single right price, but there are three sound models, and many MSPs combine them:
- Fixed fee per assessment, tiered by tenant size or scope. Simple for prospects to approve; make sure the fee covers the engineer's review and the presentation, not just the run.
- Included in the managed service, priced into the per-user or per-device fee. Best for recurring reviews, because the customer never has to approve each one.
- Credited against remediation, where the assessment fee is deducted if the customer approves the resulting project within a set period.
Work out your own cost per assessment first (tool cost plus engineer time for review, write-up and meeting), then set a price with a margin you'd be comfortable repeating every quarter. Our guide to pricing Microsoft 365 security assessments walks through the calculation and the tiers.
Running the quarterly business review
A QBR built on assessment data has a natural structure. Keep it to 30–45 minutes:
Where we are (5 minutes). The trend since the baseline: high and medium findings over time, and Microsoft Secure Score with context. Explain any jump or drop.
What we fixed (5 minutes). Completed actions and the risks they removed, in business terms. "Stolen passwords can no longer be used on their own to reach email" lands better than "MFA enforced via CA".
What's new (10 minutes). Findings that appeared since last quarter: new admins, new guest access, new devices out of compliance.
Top three risks and the decisions needed (15 minutes). For each: the risk, the fix, the effort and cost, and what happens if it waits.
Agree and record (5 minutes). Approved, deferred with a date, or risk accepted by a named person. Write it down and send it the same day.
Tip
Put the technical appendix in the pack, but don't present it. If the customer's IT contact wants to go deep, schedule a separate working session.
Turning findings into projects
A finding on its own is a problem statement. To get it approved, turn it into a project with a name, a scope and a price:
| Finding | Project | Scope drivers |
|---|---|---|
| Users without MFA; legacy authentication allowed | Conditional Access baseline | Users, service accounts, legacy clients to replace |
| Devices without compliance policies; no disk encryption | Intune compliance and encryption | Devices per platform, enrollment method |
| No DMARC; DKIM not enabled | Email authentication | Sending domains, third-party senders |
| Many "Anyone" links; guests never reviewed | Sharing and guest clean-up | Sites, links, guest accounts |
| Permanent Global Administrators | Privileged access and break-glass | Admin accounts, P2 licensing |
Licensing is often part of the answer. A customer on a plan without Conditional Access or Defender may need an upgrade before the project is possible. Our Business Premium vs E3 vs E5 comparison helps explain which plan includes what.
Making it repeatable
- Standardize the checks. The same baseline for every customer, versioned, so results are comparable. Our assessment checklist is a starting point.
- Standardize the language. A library of finding descriptions and recommended fixes keeps reports consistent across engineers.
- Schedule it. Put the next assessment in the calendar when you present the current one.
- Review before you send. A second pair of eyes on the summary catches findings that are technically true but misleading in context.
- Keep the history. The value of assessment number four is that you can compare it with one, two and three.
Pitfalls to avoid
- Handing over a 60-page export and calling it an assessment.
- Findings with no owner or date, so nothing happens after the meeting.
- Scoring the customer against settings they aren't licensed for without saying so.
- Over-promising: an assessment reviews configuration; it isn't a penetration test or a compliance certification.
How M365Assessments helps
M365Assessments is built for this model. Each customer approves its own tenant with read-only modules (no shared credentials, no GDAP needed), MSP plans cover 10, 50 or 100 tenants with a monthly assessment allowance, and schedules re-assess customers automatically. Every run produces an HTML report plus Word and PowerPoint deliverables for the QBR, and comparisons show what changed. On MSP 50, MSP 100 and Enterprise, reports can carry your branding and a Sales Guide turns findings into priced projects. See M365Assessments for MSPs and pricing.