Your Microsoft 365, clearly explained
Glenview Accounting Ltd
A strong base with room to improve
Most of the basics are working. The remaining gaps are visible.
Focus on the priorities below, then use the next assessment to see whether the picture improved.
Your security picture
Some people still rely on a password alone
Attackers only need one unprotected account. Partial MFA coverage gives a false sense of security while leaving real gaps.
All six security areas
Strong spots, gaps and unknowns
Each bar shows the share of verified checks that passed. Anything Kinervo could not verify stays outside the score.
2 visibility limits are shown separately.
Sign-in & MFA
Mixed4 of 6 passed
Accounts & admins
Mixed3 of 4 passed
Apps & consent
Strong4 of 4 passed
Exchange & email
Mixed2 of 3 passed
Devices
Strong1 of 1 passed
Logging & detection
Not seenNot enough evidence
The short list
What deserves attention first
The important part is not the label. It is what could happen, and what deserves a closer look now.
Some people still rely on a password alone
Two enabled staff accounts still have no registered second factor, while several others rely on traditional MFA that remains phishable.
Attackers only need one unprotected account. Partial MFA coverage gives a false sense of security while leaving real gaps.
An unapproved mailbox rule can forward mail outside the company
A rule on Sarah Brennan's mailbox now forwards or redirects mail outside the organisation and appeared between stored evidence snapshots.
Quiet external forwarding is a common business-email-compromise technique because it lets an attacker read invoices, replies and password resets without staying signed in.
Your name and reputation
Could someone fake your email?
We checked the public protections that tell the world which messages are really yours. They help stop fake invoices, payroll changes and convincing impersonation.
The plain-English answer
1 of 2 domains can be spoofed today.
Checked from public domain records · no tenant change neededglenviewaccounting.ie
Main company domain
- Allowed sendersSPFOn
- Message signatureDKIMOn
- Fake-mail blockingDMARCOn
All three protections are in place.
glenviewpayroll.ie
Additional company domain
- Allowed sendersSPFOn
- Message signatureDKIMMissing
- Fake-mail blockingDMARCPartial
DMARC is only monitoring (p=none) — spoofed mail still reaches inboxes. Move to p=quarantine, then p=reject.
glenviewaccounting.onmicrosoft.com is Microsoft-managed.
A human view of sign-ins
Where people signed in from
A different country is a reason to look closer, not proof of an attack. Travel, mobile networks and VPNs can all change location.
From expected countries
94%412 successful sign-ins · last 30 days
- 388IrelandExpected
- 14United KingdomReview
- 7NigeriaReview
- 3United StatesReview
“Review” means the country sits outside the expected pattern. It needs context before anyone calls it suspicious.
After this assessment
Know what changed—without living in a dashboard
Kinervo repeats the same checks, compares the evidence and reports only the changes that matter.
Your ongoing Kinervo rhythm
Quiet in the background. Clear when it matters.
Watch sign-in signals
Available location and sign-in indicators are surfaced for review.
Compare the setup
Fresh evidence is checked against the previous assessment.
Tell the story
A visual brief shows what improved, slipped or needs a decision.
*Hourly sign-in monitoring depends on the tenant making that feed available. Other configuration areas are reassessed on schedule.
Ready for your own picture?