Who is tested
We test sampled end-user devices only (laptops and desktops used by staff).
We do not test servers or headless machines.
How access works
The user shares their screen via Microsoft Teams when it is their turn.
We do not need the user’s credentials.
The user may close or hide any confidential windows before sharing.
Each device takes about five to ten minutes.
Order and logic of the manual tests
Account separation (first)
We try to perform an administrative task from a standard user account.
This confirms least privilege is enforced.
Malware protection (second — only if test 1 passes)
We send a safe test email attachment and attempt to download safe test files from the web.
This confirms endpoint protection blocks malicious files.
Only run this test if Account separation passed.
MFA check (independent)
We attempt to sign in to cloud services to confirm multi-factor authentication is enforced.
The account owner must be present to approve any MFA prompt.
This test can be done at any time; it does not depend on the other checks.
