Microsoft 365 Security Audit

Your Microsoft 365, checked setting by setting.

Microsoft 365 is built for convenience out of the box, and every tenant drifts as people, apps and administrators come and go. We audit your tenant against the CIS Microsoft 365 Foundations Benchmark and tell you, in plain English, exactly what to change.

Cyber Scheme Team Leader qualified No changes, no disruption Free re-audit once fixed
The new perimeter

Your most valuable accounts don't live on your network.

They live in Microsoft 365. Email, files, Teams chats and the keys to every other system your staff sign in to, all reachable from anywhere with a username and password.

That is why attackers go there first: a phished password on an account without multi-factor authentication, a mailbox rule quietly forwarding invoices to an outside address, a user granting a malicious app access to their mail. Microsoft gives you the controls to stop all of it, but they are spread across half a dozen admin centres, many are not switched on by default, and nothing tells you when a setting has drifted.

A Microsoft 365 security audit finds those gaps and tells you exactly how to close them. It is carried out through access your administrator sets up and can remove at any time, used only to read your settings, so there is nothing to install, nothing is changed and your users will not notice a thing.

At a glance

What the audit does

  • Checks well over a hundred tenant settings, not a sample
  • Finds gaps in MFA, Conditional Access and admin roles
  • Spots risky forwarding, sharing and app permissions
  • Takes the licences you already have into account
  • Gives you the exact setting to change for each finding
Scope

What we review

Identity

Sign-in and identity protection

Multi-factor authentication for every user and administrator, Conditional Access policies, legacy authentication that bypasses MFA, and password and self-service reset settings in Microsoft Entra ID.

Privilege

Administrator accounts and roles

Who holds Global Administrator and other powerful roles, whether admin accounts are kept separate from everyday accounts, and how emergency access is protected.

Email

Exchange Online and email security

Anti-phishing and anti-malware policies, automatic forwarding to outside addresses, mailbox auditing, and SPF, DKIM and DMARC for your domains.

Sharing

SharePoint, OneDrive and Teams

External and anonymous sharing links, guest access, and the Teams settings that decide who outside your organisation can chat, call and join meetings.

Apps

Third-party app permissions

Whether staff can grant apps access to company data on their own, and which apps already hold permissions to mailboxes and files that they should not.

Visibility

Logging, alerting and devices

Unified audit logging, alert policies and log retention, so an incident can actually be investigated, plus Intune device compliance and enrolment settings where you use them.

We cover Microsoft 365 Business and Enterprise plans, including Microsoft Entra ID, Exchange Online, SharePoint Online, OneDrive, Teams and Intune, and can extend the audit to your Azure subscriptions against the CIS Microsoft Azure Foundations Benchmark.

Delivered to a recognised standard

Audited by a qualified tester, not just a tool

Your audit is carried out by a tester holding The Cyber Scheme's Team Leader qualification for infrastructure testing, which is recognised by the NCSC against UK government testing standards. Our lead tester is also a UK Cyber Security Council registered Principal (PriCSP) for Security Testing.

Settings are assessed against the CIS Microsoft 365 Foundations Benchmark and related CIS Benchmarks for Microsoft Entra ID, Intune and Azure where they are in scope. Automated compliance checks give complete, repeatable coverage; the judgement about which findings genuinely matter, and which fixes make sense for your licences and the way your team works, comes from the person doing the audit.

Deliverables

A report you can act on, and a re-audit to prove it worked

The report

Written for the board and the technical team

  • An executive summary in plain English
  • Each finding graded by severity, with what it exposes and why it matters
  • The specific setting to change and where to find it, ready for your team or IT provider to apply
Afterwards

A walkthrough and a free re-audit

  • A short call to talk through the findings and agree priorities
  • A full re-audit of your tenant once the changes are made
  • Included as standard, not sold as an add-on
How it works

Straightforward from first email to re-audit

  1. Tell us about your tenant

    A short enquiry, answered by a tester rather than a sales team.

  2. A quick scoping call

    15 to 30 minutes to confirm your user numbers, licences and the services in scope.

  3. A fixed-price quote

    Clear scope, clear price, clear dates, typically within 48 hours.

  4. Grant access, get the report

    We send your administrator a step-by-step guide to set up access for the audit, then review your tenant and report back.

  5. A free re-audit

    Once the changes are made, we re-run the audit at no extra cost.

Working towards Cyber Essentials?

Cloud services are in scope. So is your Microsoft 365.

Cyber Essentials covers the cloud services you use and expects multi-factor authentication, secure configuration and tightly controlled administrator accounts across them. An audit checks those controls in your tenant and fixes the gaps before your assessment.

It also pairs naturally with an internal infrastructure penetration test: the audit secures the cloud accounts your staff sign in with, and the test shows how far an attacker could get from a compromised laptop.

Cyber Essentials certification
Where it fits

An audit supports

  • Cyber Essentials and Cyber Essentials Plus readiness
  • ISO 27001 access control and cloud security controls
  • Cyber insurance, supplier and customer security questionnaires
  • A clean handover when you change IT provider
  • Tidying up after a migration, merger or rapid growth
Common questions

Microsoft 365 security audits, answered.

What is a Microsoft 365 security audit?

It is a detailed review of how your Microsoft 365 tenant is configured: sign-in and multi-factor authentication, administrator roles, email security, file sharing, Teams, connected apps, logging and device management. Every setting is checked against the CIS Microsoft 365 Foundations Benchmark, and you get a prioritised list of the specific changes to make.

How do you get access to our tenant?

Your IT administrator or provider creates a dedicated app registration in your tenant using our step-by-step guide, which usually takes around 15 minutes. We use it only to read your security settings: we never change anything, read anyone's email or open your files, and you remove it as soon as the audit is finished. We never ask for a user account or an administrator password.

Will the audit disrupt our users?

No. Nothing is installed on your devices, nothing in your tenant is changed, and your users will not notice anything. The audit only reads configuration, so it carries no risk of downtime.

What standard do you audit against?

The CIS Microsoft 365 Foundations Benchmark, the independent, consensus-based standard for securing Microsoft 365, together with related CIS Benchmarks for Microsoft Entra ID, Intune and Azure where they are in scope. Each finding references the control it relates to, so it stands up to scrutiny from auditors, insurers and customers.

Who carries out the audit?

An experienced, senior tester carries out your audit from scoping to report. Our lead tester holds The Cyber Scheme's Team Leader qualification for infrastructure testing, which is recognised by the NCSC against UK government testing standards, and is a UK Cyber Security Council registered Principal (PriCSP) for Security Testing. Every result is reviewed by that person, not passed straight from a tool to your inbox.

We already have Microsoft Secure Score. Is this different?

Yes. Secure Score is a useful indicator, but it is generated by Microsoft, weighted towards its own products and silent on how much each gap actually matters to your business. An audit checks your real settings against an independent benchmark, explains each finding in plain English, and prioritises the fixes by risk and effort rather than by points.

Do we need Microsoft 365 E5 licences?

No. We audit the tenant you have, whether that is Business Basic, Business Standard, Business Premium or an Enterprise plan. The report makes clear which recommendations you can apply with the licences you already pay for, and where an upgrade would genuinely be worth it.

Does it help with Cyber Essentials?

Yes. Cyber Essentials covers the cloud services you use, including Microsoft 365, and expects multi-factor authentication, secure configuration and properly controlled administrator accounts. An audit checks those controls across your tenant and fixes the gaps before your assessment.

What do we get at the end?

A clear report with an executive summary and each finding graded by severity, alongside the specific setting to change, where to find it and why it matters. We talk it through with you on a short call, and once you have made the changes we re-run the audit at no extra cost so you can see the improvement.

How much does a Microsoft 365 security audit cost?

It depends on the size of your tenant and which services are in scope, so there is no fixed public price. Tell us roughly how many users you have and which plan you are on, and we will come back with a fixed-price quote, typically within 48 hours.

Get a quote

Find out what your Microsoft 365 audit would cost

Tell us roughly how many users you have and which Microsoft 365 plan you're on. We'll recommend a sensible scope and come back with a no-obligation, fixed-price quotation.

  1. We read your enquiry

    A real tester, not a sales team, so the first reply is already useful.

  2. A short scoping call

    15 to 30 minutes to understand your tenant and what you need to prove.

  3. A fixed-price quote

    Clear scope, clear price, clear dates, typically within 48 hours.

Not sure whether you need an audit, a penetration test or both? Tell us what you're trying to achieve and we'll help you scope it.