Most organisations running Microsoft 365 have never had anyone independent look at how it is configured. The tenant was set up during a migration, by someone solving a migration problem, and it has been accumulating settings, accounts, guests and exceptions ever since.
An audit is how you find out what state it is actually in. This is what one should cover, and what to expect from it.
What is not an audit
Before the checklist, the thing it is most often confused with.
Microsoft Secure Score is useful, and it is not an audit. It measures how many of Microsoft’s recommended settings are enabled, weighted by Microsoft’s view of their value. It cannot tell you whether a setting makes sense for how your organisation actually works, it does not know which of your accounts matter most, and it rewards enabling features whether or not they are configured well. A tenant can score respectably while the Global Administrator reads email and a forgotten guest account holds access to the finance site.
A genuine audit starts where Secure Score stops: it asks whether the configuration is appropriate, not merely present.
The ten areas
| Area | What should be checked | Why it matters |
|---|---|---|
| Administrative access | How many Global Administrators exist, whether administrative accounts are separate from daily-use accounts, whether roles are least privilege | The account worth stealing, and in most small tenants it is also somebody’s mailbox |
| Authentication | Multi-factor authentication coverage across every account, phishing-resistant methods on administrators, how registration of new methods is protected | Codes can be intercepted or approved in error; stronger methods cannot |
| Legacy authentication | Whether older protocols that bypass modern controls are blocked | One enabled legacy protocol can quietly undo the rest of the authentication work |
| Conditional Access | Whether policies exist, whether they are enforced or left in report-only mode, and what has been excluded from them | Exclusions are where the gaps usually live |
| Guest and external access | Guest accounts still active, what they can reach, and who invited them | Guests accumulate silently and are rarely reviewed |
| Sharing | SharePoint and OneDrive sharing defaults, links set to anyone, content shared externally | Links shared once for convenience tend to outlive their purpose by years |
| Email security | Defender for Office 365 configuration, domain authentication records, automatic forwarding to external addresses, suspicious mailbox rules | Forwarding rules are a favourite way to keep reading mail after an account is recovered |
| Application consent | Which third-party applications hold permissions to mail and files, and whether users can grant consent themselves | Application permissions are administrative-grade access that never appears on a list of administrators |
| Devices | Intune enrolment against the real device count, compliance policies, protection for personal phones reading work email | Unmanaged devices sit outside every control you have configured |
| Logging and alerting | Whether audit logging is on, how long it is retained, and whether alerts reach a person | Without it, an incident discovered two months late cannot be investigated |
What each area is really asking
A list of settings is easy to produce. The value lies in the questions behind them.
Who could do the most damage, and how well protected are they? Administrative access and authentication are one question, examined from two directions. The audit should identify every account with meaningful privilege, including service accounts and applications, and establish how each is protected.
What has been left open for convenience? Legacy authentication, Conditional Access exclusions, anonymous sharing links and user application consent are almost always configured the way they are because something needed to work quickly once. The audit should find those decisions and ask whether they still need to stand.
Who has access that nobody remembers granting? Guests, former staff, consultants from the original migration, suppliers, and applications consented to by a single user. Accumulated access is rarely malicious and frequently dangerous.
Would you know if something went wrong? Logging, retention and alerting determine whether an incident is found in hours or in a quarterly review, and whether it can be understood once it is.
Every finding should say what was found, why it matters to your organisation specifically, what evidence supports it, and what to do about it. A finding that says only "enable this setting" has been copied from a recommendation list, not produced by somebody who looked at your tenant.
What you should receive
The deliverable matters as much as the scope. At minimum:
- A clear statement of scope, including anything that could not be examined and why
- Findings ranked by risk to your organisation, not by a generic severity score
- Evidence for each finding, so your team can verify it rather than take it on trust
- Specific remediation, written for your environment rather than lifted from documentation
- A prioritised order of work, because a list of forty findings with no sequence produces paralysis
- A conversation, delivered by the person who did the review, where the questions that only arise afterwards can be answered
Audit, then harden
An audit tells you where you stand. Hardening is the work of fixing it, and it is a separate exercise with its own sequencing, because some changes can lock you out of your own tenant if they are made in the wrong order.
We cover the hardening work itself in how to harden Microsoft 365 in 2026, including the order to make changes in. For the individual areas, Conditional Access, administrator account security in Microsoft 365 and what Business Premium actually includes go deeper.
How we approach it
Our Microsoft 365 Security review examines each of the areas above against how your organisation actually works, rather than against a generic baseline. It is independent: we have no licences to sell you and no managed service to follow it with, so the findings are written to be useful rather than to generate further work.
If your tenant has never been looked at by anyone other than the people who built it, that is usually the best reason to start. Get in touch or call 01722 445972.