The challenge
General Fusion is developing commercially viable fusion energy, and its Microsoft 365 tenant is where its scientists and engineers collaborate every day. For an organization like that, tenant configuration is a security boundary.
The organization wanted an evidence-based picture of how the tenant actually stood: which controls were enforced, which existed only on paper, and where configuration had drifted from intent. And it wanted that picture in a form its team could act on.
Our approach
BITSUMMIT ran a full-tenant assessment that examined the environment as it behaves in practice.

Every workload examined
The assessment covered identity and Conditional Access policies in Microsoft Entra ID, Exchange Online mail flow and protection settings, SharePoint and OneDrive external sharing posture, and endpoint management and device compliance in Intune.
Every finding verified live
Each finding was documented with its evidence and severity, producing a prioritized register instead of a generic best-practice checklist. The register was later re-tested against the live tenant, so follow-on work started from confirmed facts.
From assessment into action
The priority items moved into a scoped follow-on engagement, with the same team carrying full context from assessment into execution.
The outcome
General Fusion's leadership left the engagement with a verified map of its tenant: every finding documented with evidence and severity across four workloads, then re-tested against the live environment.
The register doubles as a repeatable baseline the organization can re-run as the tenant evolves, and a scoped follow-on engagement built on it directly.




