Public network access enabled
Address this first. It is the highest-severity common finding and usually a configuration change rather than a project.
Twenty checks on an Azure workload holding patient data, covering network, identity, keys and the evidence an auditor will ask for.
Cloud workloads holding patient data accumulate configuration drift the way any estate does, and the drift is invisible until somebody audits it or exploits it.
Most of the items below are cheap to fix and expensive to have missed. Run this per workload rather than across the estate, so the findings are actionable.
CIO or CISO
Cloud architects and security engineers
Privacy officer
Tick only what you can genuinely evidence today. An item you intend to do is not an item you have done, and scoring yourself generously here only produces a comfortable number and an uncomfortable project.
The surface an attacker reaches first.
Where most real intrusions progress.
What determines the severity if something does go wrong.
Whether you could demonstrate any of the above in six months.
These bands are deliberately blunt. The middle band is where most organizations honestly sit, and it is a perfectly reasonable place to proceed from — provided the gaps are written down with owners rather than carried as optimism.
Do not proceed yet. More than four in ten items are unaddressed, and the ones that fail here are usually the foundational ones that make everything after them harder.
Proceed on a defined scope, with the outstanding items written into the plan as risks with owners and dates. This is the most common honest position.
The remaining gaps are small enough to handle during delivery rather than before it. Confirm the unticked items are genuinely minor rather than simply unexamined.
Your score highlights automatically as you tick items above. Nothing is saved, sent or tracked — refreshing the page clears it.
The four items below are the ones whose absence causes the most trouble downstream. If your unticked items include any of these, they are worth addressing before the rest.
Address this first. It is the highest-severity common finding and usually a configuration change rather than a project.
Move to managed identities. This removes a whole class of credential leak and is straightforward for most services.
Convert to policy. Manual configuration covers what existed on the day somebody did it and nothing created since.
Build it. This is the document that turns a two-week audit scramble into an afternoon.
We will run this review against one workload and produce a prioritised remediation plan mapped to your specific regulatory obligations.
Twenty checks to run before assigning a single Microsoft 365 Copilot licence in a healthcare organization.
Twenty checks framed around the only question that matters in a provider organization: how long can you deliver safe care without systems?
Describe the situation in your own words.