Skip to content

A network nobody can explain isn't safe.

Wi-Fi and network access accumulate exceptions the same way a tenant does—one guest code, one temporary rule, one departing VPN account at a time. A sanity check is a plain review of whether the current setup still makes sense together.

Book a scoping call

Four patterns worth naming out loud.

  • Guest Wi-Fi

    Guest access that never expires

    A visitor network created years ago still hands out the same password to anyone who asks, with no record of who currently has it.

  • Firewall

    Firewall rules nobody can explain

    A port-forwarding or exception rule is still active, and no one currently at the business can say why it was added.

  • Remote access

    VPN access left open after someone leaves

    A departed employee's remote-access account wasn't part of the offboarding checklist, so nobody thought to close it.

  • Segmentation

    One flat network for everyone

    Guests, personal devices, and business systems all sit on the same network with nothing separating them.

Sanity check, not a network audit.

A sanity check, not a formal network audit or penetration test.

This is a plain-language look at whether the current network setup still makes sense: does guest access expire and get reissued, do firewall rules still map to a real, current reason, and would anyone notice if remote access were left open by mistake? It does not produce a compliance score, test for exploitable vulnerabilities, or replace a dedicated network engineer, a managed firewall service, or a formal penetration test.

It also does not extend Microsoft 365 tenant administration to routers, switches, or on-premises firewalls—that hardware stays outside the recurring plan. The goal is narrower: catch the obviously stale exception before it becomes the reason something goes wrong, and give you a plain answer about whether the physical network needs its own closer look.

Five recurring checks.

  • Guest Wi-Fi passwords are rotated on a known schedule, not left unchanged indefinitely
  • Every firewall exception has a documented reason and a name attached to it
  • VPN and remote-access accounts are part of the standard leaver checklist, not a separate afterthought
  • Guest and personal devices sit on a separate network from business systems where practical
  • Anything that looks like a genuine vulnerability gets escalated, not quietly left for next time

A managed network, firewall, or wiring project is a separate, defined scope.

Redesigning network segmentation, deploying a managed firewall, wiring a new office, or responding to an active incident on the network deserves its own written scope and its own specialist—not an assumption folded quietly into Microsoft 365 tenant administration. A sanity check tells you whether that conversation is worth having; it isn't a substitute for having it.