Microsoft 365 Audit for Small Businesses
For businesses running Microsoft 365 but unsure if it's configured correctly.
What Is This?
A Microsoft 365 Audit is a detailed review of how your Microsoft 365 environment is currently configured and managed. I review areas such as identity and administrative access, email security, authentication, Conditional Access, sharing, Microsoft Defender, Intune and device management, SharePoint, OneDrive, and other settings that are relevant to the business and the Microsoft 365 licensing it has in place. The goal is to identify security gaps, configuration issues, unused capabilities, and areas where the environment may not match the way the business actually operates.
I also refer to this type of review as a Microsoft 365 Tenant Security Review because the purpose is to look beyond whether Microsoft 365 is simply working and understand how the tenant is actually configured, secured, and managed. Owning Microsoft 365 licensing gives a business access to security and management capabilities, but those capabilities still need to be appropriately configured and reviewed.
The result is a clear report documenting what I found, what needs attention, and the recommendations I would prioritize based on the business and its environment.
Why You Need It
Most businesses activate M365 out of the box using default settings. Default settings prioritize ease of use over security. You might have external sharing turned on too broadly. MFA might not be enforced. Conditional access policies might not be in place. Email security might lack anti-phishing protections. File retention might not match your compliance requirements.
A tenant audit finds all of this and tells you exactly what to fix.
Who This Is For
Any small business running Microsoft 365. Businesses that set up M365 themselves without IT expertise. Companies that inherited an M365 setup from someone who left or didn't document it. Organizations preparing for cyber insurance renewal and uncertain their M365 configuration matches their application. Regulated businesses (healthcare, financial services) that need M365 configured to compliance standards. Companies that have had a security incident and want to know if M365 played a role.
What Happens When M365 Isn't Configured Properly
External sharing is too permissive. A customer file or internal document gets shared with a link and the link spreads beyond your control.
MFA isn't enforced. A staff member's password is compromised and an attacker gains access to company email and files with no second factor stopping them.
Data loss prevention policies aren't in place. Confidential customer data, financial records, or client information can be downloaded to personal devices or emailed outside the organization without triggering an alert.
Conditional access policies are missing. Someone accessing M365 from a compromised device or an unusual location isn't being blocked.
Email security is weak. Phishing attacks get through to staff inboxes because anti-phishing protections aren't configured. A BEC attack happens because DMARC isn't preventing domain spoofing.
Audit logging isn't enabled. If something goes wrong, you have no record of who did what and when.
Retention policies aren't set. You're storing data longer than required, creating liability, or deleting data you need to keep for compliance.
Guest access isn't managed. Former contractors or partners still have access to company files.
Cyber insurance denies a claim because your M365 configuration doesn't match your application. You stated you have MFA and conditional access but they're not actually configured.
What's Included
Email Security Review
-
MFA enforcement status
-
Email forwarding rules and external access
-
Anti-phishing and Safe Links/Safe Attachments configuration
-
DMARC, SPF, and DKIM setup
-
External recipient warnings and attachment handling
Access Control & Conditional Access
-
MFA requirements and enforcement
-
Conditional access policies and their effectiveness
-
Device compliance requirements
-
Location-based access restrictions
Data Sharing & Collaboration
-
External sharing settings for OneDrive and SharePoint
-
Guest access policies and permissions
-
Link sharing permissions and expiration
-
Power BI and Teams sharing configuration
Data Loss Prevention & Retention
-
DLP policies in place and coverage gaps
-
Email retention policies
-
OneDrive and SharePoint retention
-
Teams data retention and deletion policies
-
Compliance with regulations (if applicable)
Compliance & Audit Logging
-
Audit logging enabled and retention
-
Mailbox auditing for individual accounts
-
SharePoint and OneDrive audit logs
-
Teams audit logging
-
eDiscovery and litigation hold capabilities
Device Management & Intune
-
Device management enrollment and compliance
-
Mobile device management policies
-
Conditional access enforcement on devices
-
Endpoint protection configuration
Prioritized Recommendations
-
Critical gaps and quick wins
-
Configuration improvements with high security impact
-
Compliance alignment
-
Cyber insurance readiness improvements
What You Get
Written Audit Report
Comprehensive documentation of your M365 configuration with findings, gaps, and specific recommendations.
Executive Summary
High-level overview of your current security posture and the top 5-10 items that need attention.
Detailed Configuration Review
Complete audit of email security, access controls, data sharing, retention, compliance, and device management settings.
Gap Analysis
Specific gaps identified with severity rating (Critical, High, Medium, Low) and security impact.
Prioritized Action Plan
Clear recommendations for what to fix and in what order, with step-by-step guidance where applicable.
Cyber Insurance Readiness
Assessment of how your configuration aligns with what insurance carriers require.
Compliance Alignment (if applicable)
Review against HIPAA, FTC Safeguards, or other regulatory requirements your business faces.
Consultation Call
30-minute call to walk through the audit findings, answer questions, and discuss implementation options.
Pricing
$995 flat
No hourly billing. Fixed price regardless of tenant size or complexity.
Timeline
Audit typically takes 1-2 weeks. I'll review your configuration, test access controls, validate policies, and compile the report. You get the written audit and a 30-minute consultation call to review findings.
What Happens After
You get the audit report. You can:
-
Use it to make configuration improvements yourself
-
Use it for cyber insurance applications or renewal
-
Use it as justification to hire IT support to implement the recommendations
-
Share it with another IT provider for implementation
This audit stands on its own. It's yours to use however you want.
Frequently Asked Questions
How is this different from just reviewing M365 myself?
You could review settings manually, but it's time-consuming and easy to miss configuration gaps. An external audit also carries credibility with cyber insurance carriers and compliance auditors. I also provide specific recommendations and prioritization you might not come up with on your own.
Will you tell me what to do to fix these issues?
Yes. The audit includes specific recommendations for fixing each gap, prioritized by security impact. Some recommendations include step-by-step guidance you can follow. Others are more complex and might benefit from IT support to implement correctly.
How bad is it usually?
Most small businesses have M365 set up with default or partially optimized settings. Common gaps include MFA not enforced everywhere, external sharing too permissive, and conditional access policies missing. Usually nothing catastrophic, but usually multiple things worth fixing.
Can this audit be used for cyber insurance renewal?
Yes. That's actually a common use case. Many businesses use the audit to document their M365 security posture for insurance applications. If the audit identifies gaps, you can fix them before renewing or use the audit to justify a premium increase to the carrier.
What if I'm also running Google Workspace?
I offer a separate Google Workspace Audit for $995. Many businesses use both M365 and Google Workspace. You can audit them separately or together.
Do I need to do this every year?
Microsoft makes changes to M365 regularly, and attackers are always finding new ways in. An annual audit is good practice, especially before cyber insurance renewal. If you're implementing recommendations from this audit, you might want a follow-up audit after implementation to verify everything's working correctly.
What if the audit finds something we need to fix immediately?
I'll flag critical issues so you can address them right away. You won't wait for the final report to find out about a serious problem.
Can you implement the recommendations for us?
Yes. I can do that as a separate engagement. The audit findings become the foundation for implementation work, either as a standalone project or as part of an ongoing managed IT relationship.
