“Uses Microsoft 365” is a segment, not a sales reason
Microsoft 365 is common enough that targeting every detected tenant quickly becomes another generic list. The better approach is to treat Workspace as the base filter and add signals that change the service fit.
Step 1: establish the Workspace with evidence
Use direct Microsoft MX when available. When a gateway hides the backend, combine Entra ID, Autodiscover and Microsoft DKIM evidence. Keep confidence visible so a sales rep knows whether the classification is direct or inferred.
Step 2: identify the incumbent email-security layer
A detected Proofpoint, Mimecast, Hornetsecurity or Barracuda gateway changes the account story. The prospect already buys a dedicated control, which may create a management, migration or displacement angle. No recognized gateway is a different signal, but it must not be translated into “no email security.”
Step 3: add policy posture
DMARC and SPF can surface concrete operational questions. A monitoring-only DMARC policy, complex SPF provider footprint or inconsistent public configuration can help prioritize which Microsoft 365 accounts deserve a closer look.
Workspace = Microsoft 365, DMARC = p=none, Email Security = no recognized gateway, target market = your chosen geography/segment. This is a hypothesis generator, not a vulnerability list.
Step 4: map the signals to what your MSP sells
| Signal combination | Possible service conversation |
|---|---|
| M365 + no recognized SEG | Email-security architecture / Defender / managed protection discovery |
| M365 + existing SEG | Gateway management, migration or consolidation |
| M365 + DMARC p=none | DMARC reporting, alignment and enforcement planning |
| M365 + visible identity signals | Identity/security discovery, subject to your service scope |
Step 5: write outreach that respects the evidence boundary
Do not tell a prospect that you found a “security issue” when the signal only supports an infrastructure classification. Use the data to make the outreach relevant: mention the technology category you specialize in, ask a concise discovery question, and reserve deeper conclusions for a conversation.
The long-term advantage is timing
Static Microsoft 365 detection tells you who fits. Historical collection can eventually tell you when the account changes: a gateway appears, a DMARC policy moves, or a provider migration occurs. Those changes can be materially stronger buying signals than the static presence of Microsoft 365 itself.
Turn the signal into a prospecting workflow.
SecuTest attaches public infrastructure evidence to each prospect so your team can qualify the account without turning an inference into a claim.