Most organisations running Microsoft 365 have never had anyone independent look at how it is configured. The tenant was set up during a migration, by someone solving a migration problem, and it has been accumulating settings, accounts, guests and exceptions ever since.

An audit is how you find out what state it is actually in. This is what one should cover, and what to expect from it.

TenAreas a genuine audit should examine
Secure ScoreIs a starting indicator, not an audit
EvidenceEvery finding should come with it

What is not an audit

Before the checklist, the thing it is most often confused with.

Microsoft Secure Score is useful, and it is not an audit. It measures how many of Microsoft’s recommended settings are enabled, weighted by Microsoft’s view of their value. It cannot tell you whether a setting makes sense for how your organisation actually works, it does not know which of your accounts matter most, and it rewards enabling features whether or not they are configured well. A tenant can score respectably while the Global Administrator reads email and a forgotten guest account holds access to the finance site.

A genuine audit starts where Secure Score stops: it asks whether the configuration is appropriate, not merely present.

The ten areas

AreaWhat should be checkedWhy it matters
Administrative accessHow many Global Administrators exist, whether administrative accounts are separate from daily-use accounts, whether roles are least privilegeThe account worth stealing, and in most small tenants it is also somebody’s mailbox
AuthenticationMulti-factor authentication coverage across every account, phishing-resistant methods on administrators, how registration of new methods is protectedCodes can be intercepted or approved in error; stronger methods cannot
Legacy authenticationWhether older protocols that bypass modern controls are blockedOne enabled legacy protocol can quietly undo the rest of the authentication work
Conditional AccessWhether policies exist, whether they are enforced or left in report-only mode, and what has been excluded from themExclusions are where the gaps usually live
Guest and external accessGuest accounts still active, what they can reach, and who invited themGuests accumulate silently and are rarely reviewed
SharingSharePoint and OneDrive sharing defaults, links set to anyone, content shared externallyLinks shared once for convenience tend to outlive their purpose by years
Email securityDefender for Office 365 configuration, domain authentication records, automatic forwarding to external addresses, suspicious mailbox rulesForwarding rules are a favourite way to keep reading mail after an account is recovered
Application consentWhich third-party applications hold permissions to mail and files, and whether users can grant consent themselvesApplication permissions are administrative-grade access that never appears on a list of administrators
DevicesIntune enrolment against the real device count, compliance policies, protection for personal phones reading work emailUnmanaged devices sit outside every control you have configured
Logging and alertingWhether audit logging is on, how long it is retained, and whether alerts reach a personWithout it, an incident discovered two months late cannot be investigated

What each area is really asking

A list of settings is easy to produce. The value lies in the questions behind them.

Who could do the most damage, and how well protected are they? Administrative access and authentication are one question, examined from two directions. The audit should identify every account with meaningful privilege, including service accounts and applications, and establish how each is protected.

What has been left open for convenience? Legacy authentication, Conditional Access exclusions, anonymous sharing links and user application consent are almost always configured the way they are because something needed to work quickly once. The audit should find those decisions and ask whether they still need to stand.

Who has access that nobody remembers granting? Guests, former staff, consultants from the original migration, suppliers, and applications consented to by a single user. Accumulated access is rarely malicious and frequently dangerous.

Would you know if something went wrong? Logging, retention and alerting determine whether an incident is found in hours or in a quarterly review, and whether it can be understood once it is.

The test of a good audit

Every finding should say what was found, why it matters to your organisation specifically, what evidence supports it, and what to do about it. A finding that says only "enable this setting" has been copied from a recommendation list, not produced by somebody who looked at your tenant.

What you should receive

The deliverable matters as much as the scope. At minimum:

  • A clear statement of scope, including anything that could not be examined and why
  • Findings ranked by risk to your organisation, not by a generic severity score
  • Evidence for each finding, so your team can verify it rather than take it on trust
  • Specific remediation, written for your environment rather than lifted from documentation
  • A prioritised order of work, because a list of forty findings with no sequence produces paralysis
  • A conversation, delivered by the person who did the review, where the questions that only arise afterwards can be answered

Audit, then harden

An audit tells you where you stand. Hardening is the work of fixing it, and it is a separate exercise with its own sequencing, because some changes can lock you out of your own tenant if they are made in the wrong order.

We cover the hardening work itself in how to harden Microsoft 365 in 2026, including the order to make changes in. For the individual areas, Conditional Access, administrator account security in Microsoft 365 and what Business Premium actually includes go deeper.

How we approach it

Our Microsoft 365 Security review examines each of the areas above against how your organisation actually works, rather than against a generic baseline. It is independent: we have no licences to sell you and no managed service to follow it with, so the findings are written to be useful rather than to generate further work.

If your tenant has never been looked at by anyone other than the people who built it, that is usually the best reason to start. Get in touch or call 01722 445972.