Format
Remote analysis
strictly read-only access
Duration
approx. 2 weeks
zero impact on operations
Fixed price
€4,900
net · €6,900 for high complexity
Payment
50 / 50
start & delivery
The eight audit areas

Systematically through your entire portal configuration

  1. Table permissions & web roles: the heart of portal security
  2. Authentication & identity providers: Entra External ID / Azure AD B2C
  3. Lists, forms & Web API: who can really reach what?
  4. Files & documents: securing the storage locations
  5. Web application firewall & network: the outer line of defense
  6. Sensitive data in portal code: Liquid & JavaScript
  7. License efficiency: are you paying for the right usage type?
  8. Maintainability & deployment: ALM practice
What you have afterwards

A report any team can act on

  • Certainty instead of hope The written audit report captures every finding, prioritized by risk (critical / high / medium / low). You know where your portal is exposed before anyone else does.
  • A prioritized plan instead of a list of worries In the results presentation we walk through the findings together and agree on next steps. Afterwards, your team knows exactly what to tackle first.
  • Free choice of who fixes it Every recommendation is written so that any Power Platform developer can act on it: your own team, your existing partner, or me. The report makes you independent.
The principle: the audit finds, it changes nothing. The analysis runs strictly read-only, with zero impact on your operations. And the yardstick is risk: a single overly permissive table permission on a portal holding customer data can mean a reportable GDPR incident. Once the measures are implemented, an optional re-check (€1,900) verifies the fixes.

Frequently asked questions

How much of our time does the audit take?

About 2.5 hours in total: kickoff & scoping (60 to 90 minutes) and the results presentation (60 minutes). The analysis in between is my work, without burdening your team.

Why an external review, we have developers?

Not because your developers aren't good. The people who built a configuration are the worst placed to spot what is wrong with it. That is true for me too. It is why independent third-party review exists.

What do you need from us to start?

Read-only access to the portal configuration and one contact for questions. Details are settled in the kickoff, where the price tier is also confirmed bindingly.

When was your portal last independently reviewed?

Free 30-minute call. No obligation, honest assessment.

Book a call