Microsoft 365 security audit
Your company's email, documents and identities live in Microsoft 365 and Entra ID. A configuration error —a global admin without strong MFA, an app with illicit consent or a poorly defined conditional access policy— can open the door to the entire business. We review your tenant with the mindset of someone trying to compromise it.
Is your Microsoft 365 secure, or does it just look secure?
Microsoft secures its platform, but your tenant configuration is your responsibility. Most Microsoft 365 compromises don't exploit a flaw in Microsoft: they exploit poorly deployed MFA, conditional access policies with gaps, OAuth apps with illicit consent, Exchange forwarding rules and unprotected global admins. A real audit doesn't just look at the Secure Score: it simulates what an attacker would do with a compromised account and shows you how far they could get.
What the Microsoft 365 audit covers
- Global admins: number, strong MFA and least privilege (PIM)
- Entra ID (Azure AD): conditional access, MFA, identity security and guest users
- OAuth apps and consent: app registrations, service principals and illicit consent
- Exchange Online: forwarding rules, mailbox permissions and anti-phishing protection
- SharePoint and OneDrive: external sharing, anonymous links and data exposure
- Microsoft Teams: external access, guests and third-party apps
- Microsoft Defender and Purview: DLP, retention and detection capabilities
- Unified Audit Log and alerts: visibility and detection
- Device management (Intune) and access from unmanaged devices
- Offboarding and orphaned accounts
How we run the audit
- Scope and access: We define the scope and obtain audit access (Global Reader role or test credentials). We agree which active tests are allowed and within which window.
- Configuration review (CIS): We evaluate the tenant against the CIS Microsoft 365 Benchmark: Entra ID, conditional access, Exchange, SharePoint, Teams and logging.
- Attack surface analysis: We enumerate app registrations, service principals, consent grants, forwarding rules and external shares to identify real attack vectors.
- Controlled offensive simulation: We reproduce real attacker techniques (AiTM phishing, illicit consent, token theft) in an agreed environment to confirm the impact.
- Report and remediation: We document every finding with evidence, severity (CVSS) and business impact, and deliver a prioritized remediation plan for the admin center.
What you get when we finish
- Executive report: risk level of the Microsoft 365 environment, for management and the CISO
- Technical report: findings with evidence, CVSS and concrete remediation steps
- Map of OAuth apps, service principals and permissions with their risk level
- Prioritized hardening checklist against the CIS Microsoft 365 Benchmark
- Closing meeting with your IT or tenant administration team
- Optional re-test to verify that critical findings have been fixed
When should you audit your Microsoft 365?
- Your company runs everything on Microsoft and has never audited the tenant configuration
- Before or after migrating to Microsoft 365, or after rapid user growth
- After an incident or suspicion of unauthorized access, phishing or CEO fraud (BEC)
- When a client, investor or auditor requires you to prove the security of the environment
- To comply with NIS2, ENS or ISO 27001 for email and collaboration
- If you connect many third-party apps without a consent review process
Frequently asked questions about the Microsoft 365 audit
Do you need admin access to our tenant?
For the configuration review, a read-only role (Global Reader) or a delegated role with audit permissions is enough. For offensive testing we agree the scope in advance and, if needed, a test account. Everything is done with explicit authorization and under a confidentiality agreement (NDA).
Does the audit disrupt employees' work?
No. Most of it is configuration and attack-surface analysis, which doesn't affect users. The few active tests are agreed and run in a controlled way.
How is this different from Microsoft's Secure Score?
Secure Score flags recommended settings, but it doesn't think like an attacker or chain vectors together. We look for the real compromise path: an app with illicit consent, a gap in conditional access or a forwarding rule that keeps access even after a password change.
Do you also audit Google Workspace?
Yes. We apply the same offensive methodology to Google Workspace. If you use both, we audit both environments and their integration points.
Is the report valid for compliance (ENS, ISO 27001, NIS2)?
Yes. The report documents the environment's security posture against recognized frameworks (CIS Benchmark) and is valid as evidence for ENS adequacy, ISO 27001 certification or NIS2 compliance.