Skip to content

Microsoft 365 security audit

Who can sign in, from where, and what can they reach?

We read your Microsoft 365 tenant end to end, with read-only access: every sign-in policy, every admin role, every mail rule, every sharing setting. Then we tell you which gaps matter, in the order to close them.

Who needs a Microsoft 365 security audit

  • Businesses that run on Microsoft 365 and have never had it checked by anyone other than the people who set it up.
  • Organisations after a phishing scare or a compromised mailbox that want to know what else is open.
  • Owners and boards who want an independent view of their IT provider’s work.
  • Firms facing a cyber-insurance questionnaire or a client’s security review.

What we check

  • Identity

    Who has accounts, which are stale or shared, and how each one signs in. MFA coverage and strength, including phishing-resistant methods.

  • Conditional Access

    Which sign-ins are allowed from where and on what devices, and whether risky flows such as legacy authentication and device-code sign-in are blocked.

  • Devices

    Which devices can reach company data, and whether they are managed, encrypted and up to date.

  • Admin roles

    Who holds admin roles, whether that is more than the job needs, and whether admin access is protected and time-limited.

  • App consent

    Which third-party apps have been granted access to mail and files, and whether users can grant more on their own.

  • Exchange rules and forwarding

    Inbox rules and forwarding that send mail outside the business, a common sign of a compromised mailbox.

  • Outbound spam

    Outbound spam policies and sending limits, so one compromised account cannot mass-mail your clients.

  • Sharing

    SharePoint, OneDrive and Teams sharing settings, guest access and anonymous links.

  • Logging and retention

    Whether audit logging is on, how long logs are kept, and whether you could reconstruct an incident from them.

  • Response readiness

    Who would notice a compromise, who can act, and how quickly an account can be locked down.

How it works

The audit only reads. Nothing in your tenant changes unless you ask us to fix something afterwards.
  1. Scope call

    We agree what is in scope and the read-only access we need, and fix the fee before we start.

  2. Read-only access

    You grant a read-only role for the period of the audit, and remove it when we finish.

  3. The engine reads everything

    Every policy, role, rule and setting in scope is pulled and checked against the same rule set, not a sample. Every command that touches your tenant is read by one of us before it runs.

  4. Review and report

    We read every finding, rank it by risk and write the report, with the evidence for each finding and the exact setting to change.

What you get

  • A short summary for owners and boards: what is exposed, and what to fix first.
  • Findings ranked by risk, each with the evidence and the setting behind it.
  • A step-by-step fix list your IT provider can act on.
  • A walkthrough call with both of us.
  • If you want it, we make the changes with you afterwards.

Talk to us about an audit

A short call to scope it. A fixed fee before we start. A fraction of a Big Four engagement, in days not months.