Back to Portal
User Audit

Reading Write Alaska
Microsoft 365 Report

Licensing, user assignment, MFA registration, and Secure Score for the M365 tenant.

Report Date August 2026
Source Microsoft 365 Admin Center
Prepared By Vicinity vCIO Team
54
Licensed Users
31.52
Secure Score / 100
1
MFA Exemption
1
Licensing Summary

Reading Write Alaska's Microsoft 365 tenant holds 5 license SKUs. Assignment is tracked below against total available seats.

ProductTotal LicensesAssignedAvailable
Microsoft 365 Business Basic 43 40 3
Microsoft 365 Business Standard 17 14 3
Azure Information Protection Premium P1 54 48 6
Microsoft Entra ID P1 1 1 0
Microsoft Power Automate Free 10,000 45 9,955
2
User Licensing Status

The tenant directory contains 110 total objects. Breaking that down by licensing and account type gives a clearer picture than "licensed vs. unlicensed" alone:

Licensed Users
54
Active staff with an assigned license
Disabled / Departed
19
Named accounts, sign-in blocked, no license
Service & Shared Accounts
26
Admin, sync, printer, scheduling & similar mailboxes
Guest / External
8
Vendor & external collaborator accounts
Enabled Accounts Without a License

3 named, active (non-disabled) accounts currently have no license assigned — worth reviewing to confirm they either need a license or should be disabled:

Display NameUser Principal Name
DTS Techdtstech@readingwritealaska.com
Elizabeth Cordaroecordaro@readingwriteak.onmicrosoft.com
Jennifer Eilembergjeilemberg@readingwriteak.onmicrosoft.com
3
MFA Registration

50 users are registered for multi-factor authentication. All 50 are MFA-capable, but the strength of the method in use varies:

MFA Capable
50 / 50
All registered users
Passwordless Capable
14
Windows Hello / Authenticator passwordless
SSPR Capable
35
Self-service password reset enabled
Default: SMS/Phone
27
Weaker than app-based push
Default MFA Method Breakdown
Default MethodUsersNotes
Mobile Phone (SMS/call) 27 Weaker — susceptible to SIM-swap & interception
Microsoft Authenticator Push 16 Recommended
Software One-Time Passcode 7 Acceptable
4
Conditional Access & Secure Score
Active Conditional Access Policies
PolicyApplies ToGrant ControlStatus
Require multifactor authentication for all users All users, all resources Require MFA Active
Temp Exempt 1 specific user (Christina Panasci) Grant access (MFA not required) Active exemption
Microsoft Secure Score: 31.52 / 100

Below the 45.45 average for organizations of similar size. Category breakdown: Identity 51.62%, Data 55.56%, Apps 23.22% (the largest opportunity area). 49 recommended actions are currently marked "To address."

Top Recommended Actions
ActionScore ImpactCategory
Create Safe Links policies for email messages+3.24%Apps
Turn on Safe Attachments in block mode+2.88%Apps
Ensure intelligence for impersonation protection is enabled+2.88%Apps
Move messages detected as impersonated users to Junk+2.88%Apps
Enable impersonated domain protection+2.88%Apps
Set the phishing email level threshold to 2 or higher+2.88%Apps
Enable impersonated user protection+2.88%Apps
Enable Microsoft Entra ID Identity Protection sign-in risk policies+2.52%Identity
5
Full User Directory

Complete list of all 110 directory objects, with assigned license(s) and sign-in status. Collapsed by default — expand to review the full list.

Note: Gayle Andrus holds an active license assignment (M365 Business Standard, AIP P1, Power Automate) despite a disabled sign-in — recommend reclaiming this license if the account is confirmed departed.

6
Recommendations
  • Close the MFA exemption gap — remove or time-box the "Temp Exempt" Conditional Access policy currently covering Christina Panasci.
  • Enable Safe Links & Safe Attachments — the single highest-impact, lowest-effort improvement available to raise Secure Score.
  • Encourage stronger MFA methods — nudge the 27 users defaulting to SMS/phone toward Microsoft Authenticator push for stronger protection.
  • Clean up enabled-but-unlicensed accounts — review DTS Tech, Elizabeth Cordaro, and Jennifer Eilemberg to confirm whether they need a license or should be disabled.
  • Review guest/external accounts — 8 external accounts (including legacy DanTech staff) have standing access; confirm these are still needed.