Network and Wi-Fi sanity check
A network nobody can explain isn't safe.
Wi-Fi and network access accumulate exceptions the same way a tenant does—one guest code, one temporary rule, one departing VPN account at a time. A sanity check is a plain review of whether the current setup still makes sense together.
Book a scoping callWhat a sanity check looks for
Four patterns worth naming out loud.
- Guest Wi-Fi
Guest access that never expires
A visitor network created years ago still hands out the same password to anyone who asks, with no record of who currently has it.
- Firewall
Firewall rules nobody can explain
A port-forwarding or exception rule is still active, and no one currently at the business can say why it was added.
- Remote access
VPN access left open after someone leaves
A departed employee's remote-access account wasn't part of the offboarding checklist, so nobody thought to close it.
- Segmentation
One flat network for everyone
Guests, personal devices, and business systems all sit on the same network with nothing separating them.
What this is—and is not
Sanity check, not a network audit.
A sanity check, not a formal network audit or penetration test.
This is a plain-language look at whether the current network setup still makes sense: does guest access expire and get reissued, do firewall rules still map to a real, current reason, and would anyone notice if remote access were left open by mistake? It does not produce a compliance score, test for exploitable vulnerabilities, or replace a dedicated network engineer, a managed firewall service, or a formal penetration test.
It also does not extend Microsoft 365 tenant administration to routers, switches, or on-premises firewalls—that hardware stays outside the recurring plan. The goal is narrower: catch the obviously stale exception before it becomes the reason something goes wrong, and give you a plain answer about whether the physical network needs its own closer look.
What belongs in a periodic review
Five recurring checks.
- Guest Wi-Fi passwords are rotated on a known schedule, not left unchanged indefinitely
- Every firewall exception has a documented reason and a name attached to it
- VPN and remote-access accounts are part of the standard leaver checklist, not a separate afterthought
- Guest and personal devices sit on a separate network from business systems where practical
- Anything that looks like a genuine vulnerability gets escalated, not quietly left for next time
When the question is deeper than a sanity check
A managed network, firewall, or wiring project is a separate, defined scope.
Redesigning network segmentation, deploying a managed firewall, wiring a new office, or responding to an active incident on the network deserves its own written scope and its own specialist—not an assumption folded quietly into Microsoft 365 tenant administration. A sanity check tells you whether that conversation is worth having; it isn't a substitute for having it.
Connect this to the rest of care