Microsoft 365 Tenant Security Review: What I Look for During a Microsoft 365 Audit
Updated: Sep 1

Updated August 2026: Microsoft 365 has changed considerably since I first wrote this article, and the way small businesses use it has changed along with it. I have updated this article to better reflect what I currently look at during a Microsoft 365 Tenant Audit, including licensing, identity and authentication, Microsoft Defender, device management, SharePoint and OneDrive, vendor access, third-party applications, backup and recovery, documentation, and the growing importance of understanding the Microsoft environment before introducing AI tools.
I have walked into Microsoft 365 environments that, from the business owner's perspective, appeared to be working just fine. Email was flowing, employees could sign in, files were available and nobody was calling because something was broken. Once I started looking deeper into the tenant, though, the picture wasn't always as clean as it appeared from the outside.
One environment had Conditional Access policies that had been created approximately eight months earlier but were still sitting in report-only mode. Report-only mode is useful when a policy is first being evaluated because it allows us to see what would happen before we begin enforcing it. In this case, however, the policies had never moved beyond that stage, which meant the business didn't actually have the protection it thought had been implemented.
I've also found old application authorizations for products businesses stopped using years earlier. I've seen Microsoft security capabilities included in licensing that nobody ever configured, along with old devices, outdated authentication methods and permissions that made sense at one point but were never revisited as the company changed.
None of those things prevented employees from opening Outlook the next morning, which is exactly why simply asking whether Microsoft 365 is working doesn't tell me very much about whether it is being managed correctly.
“Having Microsoft 365 is different from managing Microsoft 365.” — SNL-Tech Services
A Microsoft 365 Tenant Audit gives me the opportunity to look underneath what employees see every day and understand how the environment is actually configured, what the business is paying for, what security controls are really in place, who and what can access company information, and whether all of it still makes sense for the business as it operates today.
Why Would We Need a Microsoft 365 Tenant Audit If Everything Is Working?
Microsoft 365 environments don't stay static after they are initially configured. A company hires employees, people leave, computers get replaced, vendors are brought in, SharePoint sites are created and new applications are connected. Someone may receive additional access because they are helping with a project and then keep that access long after the project ends. Microsoft changes features and licensing, while the company itself may start working remotely, move more information into the cloud or adopt applications that didn't exist when the tenant was originally configured.
Most of those changes are perfectly reasonable when they happen. The problem is that somebody needs to periodically look at what all of those individual decisions have created over time.
This is where configuration drift starts to become important. The environment a business has today may no longer look much like the one that was originally designed. That doesn't necessarily mean someone did something wrong. It can simply mean that several years of small changes have accumulated without anyone going back and reviewing the environment as a whole.
This is also why I separate having Microsoft 365 from actually managing it. I talk about that distinction in more detail in Microsoft 365 for Small Businesses: Is Anyone Actually Managing Your Environment? A Tenant Audit gives us the opportunity to establish the baseline: what is actually configured today, what still makes sense and what may need attention.
Instead of assuming that a security control, permission or application is still appropriate because it has been there for three years, I can look at the business as it operates today and determine whether the Microsoft environment still supports it.
If you're trying to understand what I believe should actually be configured in a small-business Microsoft 365 environment, I cover that separately in Microsoft 365 Security for Small Business: What Actually Needs to Be Configured. That article looks at the controls and management practices themselves. This article approaches the problem from the other direction: determining what the business actually has in place today.
Why Do You Review Our Microsoft Licensing as Part of a Security Audit?
Licensing is one of the first areas I look at because it determines which security and management capabilities are available to the business, and I frequently find that what a company owns and what it actually uses are two different things.
A business may already have Microsoft 365 Business Premium but never have fully implemented Intune, Conditional Access, Microsoft Defender or other capabilities included with that licensing. Another company may still be using Business Standard while paying separate vendors for products that overlap with capabilities available through a different Microsoft plan. Neither situation automatically means the licensing should be changed, but I want to understand what the company is paying for and whether those licenses still support what we are trying to accomplish.
Microsoft also continues to change its licensing, pricing and included features, so a licensing decision that made sense several years ago should not automatically be treated as permanent. Employee roles change too, and there may be licenses assigned to former employees, accounts that no longer need them or users whose current licensing doesn't match the security controls the business now wants to implement.
I am not looking for a reason to automatically move everyone to a more expensive plan. I am looking at the environment, the security requirements and the way the company works so that I can determine whether the licensing makes sense and, just as importantly, whether the business is actually taking advantage of the capabilities it is already paying for.
Who Has Administrative Access to Our Microsoft 365 Environment?
Most business owners know who works for them, but they don't necessarily know everyone who can make administrative changes inside Microsoft 365. That is a very different kind of access, and it is something I want clearly documented.
I review Global Administrators along with other privileged administrative roles because not everyone who needs some administrative capability needs unrestricted control over the tenant. I may also find accounts belonging to a previous IT provider, a vendor, a former employee or an administrator account that was created for a specific purpose and then never revisited.
The goal isn't simply to reduce the number of administrators. I need to understand why an account has a particular role and whether that role is appropriate for what the person or vendor actually needs to do. I also review emergency-access planning because tightening administrative security without considering how the company would regain access during an authentication problem can create a different kind of risk.
For the business owner, all of the Microsoft role names are secondary to a much simpler
question: Who has the ability to make important changes to our Microsoft environment, and do they still need that ability?
If We Already Have MFA, What Else Is There to Review?
I absolutely want multifactor authentication in place, but seeing that MFA is enabled doesn't tell me everything I need to know about how identities are protected. I look at the authentication methods employees are actually using, whether older methods are still available, how administrative accounts are protected and whether stronger phishing-resistant authentication methods are appropriate for the business.
That part of the Tenant Audit has become particularly timely because Microsoft is making a significant change to Entra authentication.
Beginning September 1, 2026, Microsoft is making passkeys the default authentication experience in Microsoft Entra ID. Users who are enabled for Microsoft-provided SMS or voice authentication will be automatically enabled for passkeys and brought into Microsoft's passkey registration campaign, which can prompt them to register a passkey after completing MFA.
Microsoft has also announced that beginning February 1, 2027, Microsoft-provided SMS and voice authentication delivery will be retired in Entra ID. Businesses that still have employees relying on SMS or voice therefore need to understand who those users are and develop an appropriate transition plan before the change becomes disruptive.
For a small business, this isn't something I would wait until February to investigate. During the Tenant Audit, I can identify how employees are authenticating today, determine whether people are still relying on SMS or voice and work through an appropriate transition before Microsoft's change creates unnecessary sign-in problems for employees.
Some businesses may have a legitimate operational or regulatory reason to continue using SMS or voice, and Microsoft is providing a path for those organizations to use customer-managed telecom providers. That should be an intentional business and security decision, though, rather than something the company discovers at the last minute because nobody had reviewed its authentication methods.
I have already been implementing passkeys for clients where they make sense, and I expect authentication-method reviews to become an increasingly important part of Microsoft 365 management as Microsoft's February 2027 deadline approaches.
Conditional Access is another part of that review because it allows us to make access decisions based on more than whether someone entered the correct password and completed an MFA prompt. Depending on the needs of the business, those policies can consider factors such as the user, application, location, device state and authentication requirements.
For some businesses, location-based controls make sense. I have implemented them after an email compromise where suspicious activity was coming from another country and the client's employees had no legitimate business reason to sign in from there. That doesn't mean I would apply the same restriction to a company whose employees routinely travel internationally. The security control has to match the way the company actually operates.
I also spend time looking at how Conditional Access has been implemented, not simply whether policies appear in the portal. A policy may have exclusions that are too broad, may overlap another policy or, as I found in the environment I mentioned earlier, may have been left in report-only mode long after the testing period should have ended.
The purpose of this part of the audit is to understand how employees are proving who they are, what Microsoft is actually enforcing when they sign in and whether the business is prepared for the authentication changes that are coming next.
Are There Signs That an Account May Already Be at Risk?
Depending on the Microsoft licensing in the tenant, there may be identity-risk information available around users and sign-ins that deserves attention. The amount of information and the automated risk-based capabilities available varies by Entra licensing, which is another reason licensing and security can't really be reviewed independently.
Where those capabilities are available, I look at risky users, risky sign-ins and related authentication activity to see whether Microsoft is identifying behavior that warrants a closer look. I also use the available sign-in information to understand where authentication attempts are originating, what applications are involved and whether the activity makes sense for that particular employee and business.
A suspicious sign-in doesn't automatically mean an account has been compromised, and I don't want an owner assuming every Microsoft risk notification represents an active attack. There may be a legitimate explanation for what Microsoft is seeing. What concerns me more is an environment generating security information that nobody is reviewing at all.
This is one of the differences between owning security technology and actually managing it. Microsoft can identify something worth investigating, but there still needs to be somebody responsible for looking at the information, understanding the context and deciding whether action is necessary.
What Do You Actually Review in Microsoft Defender?
Microsoft Defender is a good example of why I don't equate having a license with having a security solution fully implemented.
Depending on the client's Microsoft licensing, there can be a considerable amount to configure across endpoint and email protection. I look at whether devices are properly onboarded and reporting, how endpoint-security policies have been configured, whether the protection settings make sense for the business, and whether the Microsoft security tools are actually providing the visibility everyone assumes they are.
Email protection has its own set of controls. I review the applicable anti-phishing configuration, user and domain impersonation protections, Safe Links, Safe Attachments, quarantine settings and other Defender for Office 365 protections available within the client's licensing. I also look at SPF, DKIM and DMARC because protecting the company's email domain and reducing the ability for someone to impersonate it are part of the same overall conversation.
There is another piece that is easy to miss: security alerts and notifications.
A security product can be configured correctly enough to detect something and still fail the business operationally if the alert goes to an old administrator, an unmonitored mailbox or nobody at all. I review who receives the relevant security notifications and what happens after an alert is generated because detection only becomes useful when somebody knows it happened and has a process for responding to it.
What Do You Look at After an Email Account Has Been Compromised?
A compromised mailbox is one of the situations where I don't want the response to stop with changing the employee's password.
I want to understand what happened around the account and whether anything else changed while the attacker had access. Depending on the incident, that can mean reviewing authentication activity, inbox and forwarding rules, mailbox permissions, connected applications, authentication methods and other areas that could allow information to continue being redirected or access to persist after the password has been changed.
Business email compromise can be particularly dangerous when an organization regularly handles financial transactions or sensitive information. I wrote about this in more detail in Cybersecurity for Small Law Firms: Microsoft 365 and Business Email Compromise, including why securing Microsoft 365 is only part of the solution and why businesses also need procedures for independently verifying changes to payment or wire instructions.
I also look at the surrounding protections because an incident gives us an opportunity to understand where the environment can be strengthened. That may lead to changes in Conditional Access, authentication methods, email-security policies, impersonation protection or other controls depending on what happened and how the company works.
I recently performed this type of broader Microsoft 365 remediation for a small business after an employee's email account was compromised from another country. The work went well beyond resetting the account. We reviewed the tenant, upgraded the Microsoft licensing where appropriate, implemented stronger Conditional Access controls, introduced passkeys, removed older authentication methods, strengthened Defender and email protections, configured user and domain impersonation protections, and improved the management of the company's devices.
That experience is one of the reasons I look at Microsoft 365 as an environment rather than treating every security setting as a separate project.
Are Our Computers Actually Being Managed?
Once company information is living in Microsoft 365, I need to look at the computers employees are using to access it. This is particularly important for cloud-first businesses because the laptop sitting in an employee's home may effectively be one of the gateways into company information.
When the licensing and environment support it, I review Intune enrollment, Entra registration or join status, device compliance, Microsoft Defender onboarding, BitLocker encryption, firewall settings, Windows editions and other device-management controls. I also compare what Microsoft shows me with what the company actually owns because those two lists are not always the same.
If Microsoft shows 32 devices, for example, some may be current company computers while others could be old machines that were replaced, personal devices that were registered at some point or systems that appear in Entra but were never properly enrolled into Intune. A computer appearing in a Microsoft portal does not automatically tell me that it is being consistently managed, protected and monitored.
This becomes even more important when Conditional Access is being used to make decisions based on device compliance. If we are going to require a compliant device before allowing access to company information, I need confidence in the device-management policies that determine what “compliant” actually means.
How Do You Review SharePoint and OneDrive?
SharePoint and OneDrive can become complicated over time because employees are usually focused on getting their work done, not designing a long-term information architecture.
OneDrive generally makes sense as an individual's working area, while documents that belong to a department, team or the company often make more sense within an appropriately structured SharePoint environment. In a tenant that has grown organically, however, I may find important company information living in individual OneDrive accounts, SharePoint sites with unclear ownership, Teams-created sites, folders that have been shared individually for years and permissions that nobody has reviewed since they were originally granted.
I look at how the company is actually using SharePoint and OneDrive and whether the structure still makes sense. That includes reviewing site ownership, security groups, permissions, external sharing, guest access and the way employees and vendors are being given access to company information.
The goal isn't to lock everything down until nobody can work. Employees still need to collaborate, and businesses still need to exchange information with clients and vendors. I am trying to make that collaboration intentional so that access reflects what people actually need rather than years of accumulated sharing decisions.
This has also become much more important as businesses begin thinking about Microsoft Copilot and other AI tools because AI can make information employees already have permission to access considerably easier to discover and use.
What About Vendors and Outside IT Providers?
Microsoft 365 rarely contains only employee accounts.
There may be an outside accountant collaborating through SharePoint, a software company providing support, a backup provider connected to Microsoft 365, an IT company with administrative access, a consultant working inside Teams or a vendor whose application uses Microsoft Entra for authentication.
Those relationships can be completely legitimate. I still want them documented.
Part of the Tenant Audit is understanding which outside organizations and individuals have access, how that access was provided and whether it is still required. If a vendor was given access for a project that ended eighteen months ago, there may no longer be a business reason for that access to remain.
This is particularly important when a company changes IT providers. A new provider taking over Microsoft 365 doesn't automatically mean every account, delegated relationship or administrative permission associated with the previous provider disappeared.
The purpose isn't to treat vendors as a threat. The purpose is to make sure the business understands who is connected to its environment and why.
What About Applications That Employees Have Connected to Microsoft 365?
This is an area that business owners and office managers often don't realize they should be asking about.
Microsoft identities are used to sign into an enormous number of third-party applications, and some of those applications can request permission to interact with Microsoft 365 information. Over time, the tenant can accumulate Enterprise Applications and other authorizations that reflect software the business used years ago rather than what it uses today.
I've seen this firsthand. During one tenant cleanup, I found an old WordPress-related application authorization even though the business hadn't used WordPress for several years. There was also an old QuickBooks authorization after the company had moved away from QuickBooks roughly a year and a half earlier.
Neither application was automatically malicious simply because it was old. The important part was that the business no longer needed the integrations and didn't know they were still present.
During the audit, I review the third-party applications and relevant Enterprise Applications connected to the environment, what access they have, whether the company still uses them and how application consent is being handled. I also want to understand how new applications are being introduced so that we don't clean up several years of old authorizations only to let the same problem begin accumulating again.
What Does Any of This Have to Do With AI?
More every year. Businesses are beginning to use Microsoft Copilot, ChatGPT Business or Enterprise, Claude for Teams or Enterprise, AI meeting assistants and AI capabilities that are being built into software they already use. Some of those tools may simply be used separately, while others may use Microsoft Entra for SSO or integrate more directly with company systems and information.
That means I increasingly need to understand AI as another part of the environment rather than treating it as a completely separate technology conversation.
If a client decides to implement an approved AI platform and we configure SSO through Microsoft Entra, I want that implementation documented. The run book should show when the application was introduced, why the business approved it, how authentication was configured, which users or security groups have access and what permissions or integrations were authorized. A year later, I shouldn't have to rediscover why an Enterprise Application exists or rely on someone's memory of how it was originally configured.
The same principle applies before rolling out Microsoft Copilot. If SharePoint permissions have been allowed to grow unchecked for years, introducing a tool that makes information much easier for employees to find can expose problems that already existed in the permission structure. The AI didn't create those permissions, but it can make the consequences of overly broad access much more apparent.
This is where my Microsoft 365 security work and AI governance work naturally come together.
“Responsible AI adoption doesn't start with choosing an AI product. It starts with understanding the business, securing the environment underneath it and then deciding how AI fits into it.” — SNL-Tech Services
I go further into that side of the conversation in AI Governance for Small Business, including why a business needs to understand which AI tools employees are using, what company information those tools can access and what rules need to be established around their use.
For businesses considering AI, I would much rather discover and correct an access, data or application-governance problem before a larger AI rollout than explain it afterward.
Does Microsoft 365 Back Up Our Data?
This is another area where terminology can create confusion.
Microsoft 365 is a productivity and collaboration platform. Microsoft provides resiliency and native capabilities such as retention, version history, recycle bins and other recovery features within its services, but I don't treat those features by themselves as the company's backup strategy.
Microsoft also offers Microsoft 365 Backup, but that is a separate backup service rather than something a business automatically receives simply because it subscribes to Microsoft 365 Business Standard or Business Premium.
As part of the Tenant Audit, I look at what the business actually has in place for Exchange, OneDrive and SharePoint, how retention is configured, what recovery capabilities exist and whether there is a separate backup solution protecting the Microsoft tenant. I also want to understand the company's expectations because a backup strategy needs to be designed around what the business needs to recover and how it expects recovery to work after a deletion, compromise or other incident.
For clients using the Microsoft 365 backup solution I provide, I monitor the protected backups daily and provide a monthly backup report. I also perform quarterly test restores and document those results because I don't consider a green “successful” status by itself enough to tell me that the business has a working recovery strategy. Ultimately, I need to know that we can recover an email, file or SharePoint document when the client actually needs it.
Do You Look at Microsoft Secure Score?
I do, and I think Secure Score is useful when it is put in the proper context.
I capture the Microsoft Secure Score during the initial Tenant Audit because it gives us another point-in-time measurement of the environment and can identify recommendations that deserve further investigation. I don't, however, configure a client's Microsoft environment simply to chase a higher number.
A recommendation still has to make sense for the business, and there may be situations where another security product or control is already addressing the underlying concern. I am more interested in understanding why a recommendation exists and whether it is appropriate for that client than I am in trying to make a dashboard show 100%.
Secure Score becomes particularly useful when I also perform the remediation because I can document the score before the work begins and capture it again after implementation. That gives the client a before-and-after reference while the run book provides the more important detail about what was actually changed and why.
What Do You Receive From a Microsoft 365 Tenant Security Review?
One of the things I don't want to do is finish an audit, hand the business owner a screenshot from a Microsoft dashboard and leave them with twenty technical recommendations they don't understand. The audit needs to create something useful.
One of the primary deliverables I provide is a run book documenting the environment as I found it. The exact contents depend on the client because no two Microsoft environments are identical, but the documentation can include licensing, administrative access, authentication methods, Conditional Access, Defender configuration and alerting, device management, Intune, SharePoint and OneDrive, vendor access, external sharing, Enterprise Applications, third-party integrations, email security, backup and recovery, Secure Score and other relevant parts of the tenant.
The run book also gives me somewhere to document context, which is something a configuration screen can't tell me. If a vendor has access to part of the environment, I want the documentation to explain why. If a Conditional Access exception exists because an application requires it, I want to know that. If the company has integrated an outside platform through SSO, I want the integration and the business reason behind it documented.
That turns the audit into more than a list of things that need to be fixed. It creates a point-in-time record of what the business actually has.
What Happens If You Find Things That Need to Be Fixed?
The Tenant Audit can stand on its own. The client receives the findings and documentation and can decide what it wants to do with the recommendations.
If the business chooses SNL-Tech Services to perform the remediation, the cost of the Microsoft 365 Tenant Audit is credited toward the implementation work. I think that makes sense because I've already spent the audit learning the environment, documenting what is there and determining what needs attention. That work becomes the starting point for implementation instead of being discarded and performed again.
As I implement the changes, I update the run book so that it documents the controls that were put in place, the configuration decisions that were made and why those decisions were appropriate for the business. I also capture the Microsoft Secure Score again after implementation so the client has a documented before-and-after measurement alongside the much more detailed record of the actual work.
Depending on what the audit finds, remediation may involve relatively small changes, or it may become a larger project involving licensing, authentication, Conditional Access, Defender, Intune, device enrollment, BitLocker, SharePoint permissions, application cleanup, email security or other areas. I don't know what the remediation project should look like until I understand what is already there, which is one of the reasons I prefer to audit the environment first.
What Happens to the Run Book If You Continue Managing Microsoft 365?
For clients whose Microsoft 365 environments I continue to manage, the run book doesn't become a document that gets filed away after the remediation project. It becomes a living guide to the environment.
When a meaningful change is made, I document what changed, when it changed and why the decision was made. That gives me a history to work from when I come back to the environment months later instead of relying on memory or trying to reverse-engineer the reason a particular configuration exists.
Suppose the company decides eight months after remediation to implement an approved AI platform and use Microsoft Entra for SSO. That integration can be added to the run book along with the users or security groups involved, the authentication configuration, the relevant Enterprise Application and the reason the business approved the platform. The same applies if the company changes an accounting system, brings in a new vendor, modifies SharePoint access, changes a Conditional Access policy or replaces a backup solution.
A year later, that history gives me context. I can see how the environment has evolved since the original audit, which is considerably more useful than taking another snapshot and trying to figure out why everything changed.
Can the Run Book Help With Cyber-Insurance Readiness?
It can, although I am careful not to imply that having a run book guarantees insurance coverage or satisfies a particular carrier's requirements.
Cyber-insurance applications and renewals can ask detailed questions about MFA, endpoint protection, encryption, backups, administrative access, email security and other controls. If the business has been actively managing and documenting those controls, we are in a much better position to answer those questions accurately than if the owner or office manager has to guess about what the IT environment is doing.
I go into that problem in much greater detail in Cyber Insurance Requirements for Small Businesses: Can You Answer the IT Questions on Your Application?, including the types of technical controls and documentation a business may be asked about when preparing for a renewal.
The change history can be useful as well. If we implemented a control after the previous year's assessment, changed an authentication method, introduced a new security platform or added an important third-party integration, we have a record of what happened and why.
The run book doesn't replace the insurer's assessment or requirements. It gives us documentation we can reference while preparing for them.
Can This Documentation Help With Compliance?
It can support a larger compliance-readiness effort, but a Microsoft 365 Tenant Audit does not make an organization compliant with CMMC, HIPAA, GLBA or another regulatory or contractual framework by itself.
Microsoft 365 is one part of the business's overall technology environment, and compliance requirements can extend into policies, procedures, physical security, employee training, vendors, networks, applications and other areas outside the Microsoft tenant.
What the audit and run book can provide is documentation around controls that may be relevant to those larger requirements. If we have documented authentication, device-management policies, BitLocker, Defender, administrative access, data access, vendor integrations and configuration changes, the business has a much better technical baseline than it would have if all of that information existed only inside different Microsoft portals.
That can also help identify where additional work is needed before a company begins pursuing a particular compliance requirement.
How Does the Run Book Relate to an Incident Response Plan?
I view the run book and Incident Response Plan as complementary documents with different purposes.
The Incident Response Plan establishes how the organization intends to respond when something goes wrong, including who needs to be involved and what processes should be followed. The run book provides technical context about the environment in which that response has to happen.
If I am responding to an incident, current documentation can help me understand how identities are configured, which security controls should be operating, which vendors or applications are connected, how backups are configured and whether any recent changes could be relevant. That can reduce the amount of time spent reconstructing the environment while an incident is already underway.
The run book doesn't replace an Incident Response Plan, but having both gives the business a much better foundation for responding to an event than trying to build that understanding after something has already happened.
How Often Should a Microsoft 365 Tenant Be Reviewed?
There isn't one review schedule that makes sense for every company because a heavily managed environment is different from a tenant that nobody has looked at closely in several years.
I do think certain changes should cause a business to consider another review. A security incident is an obvious one, but changing IT providers, making a significant licensing change, moving more company information into SharePoint, adding major vendors, preparing for a cyber-insurance renewal or compliance requirement, and introducing AI across the organization can all change enough of the environment to justify another look.
Microsoft's upcoming authentication transition is a good example of why these reviews matter even when the business itself hasn't intentionally changed anything. A company could have configured SMS-based MFA years ago and continued using it without a problem, but Microsoft's September 2026 and February 2027 changes mean that authentication strategy now needs to be revisited.
For clients whose environments I actively manage, the ongoing run book and change documentation help reduce the amount of rediscovery required because I already have a record of what has happened since the previous review.
The larger point is that Microsoft 365 isn't something I expect to configure once and leave untouched indefinitely. Microsoft changes its platform, the business changes how it works, employees and vendors change, and new applications continue to enter the environment. The management and documentation need to keep up with those changes.
What I Want a Business Owner to Know After the Audit
When I finish a Microsoft 365 Tenant Audit, I want the business owner or office manager to understand the environment better than they did when I started.
They don't need to become Microsoft administrators, and I don't expect them to understand every Conditional Access setting or Defender policy. They should understand what they are paying for, whether the important security capabilities are actually being used, who has administrative and outside access, how company devices are being managed, how business information is being shared, what third-party applications are connected and where I see risks that deserve attention.
They should also have documentation they can refer back to instead of depending on someone's memory of how Microsoft 365 was configured several years ago.
If they decide to move forward with remediation, that documentation becomes the foundation for the implementation and the audit cost is credited toward that work. If I continue managing the environment afterward, the run book becomes the ongoing record of how the environment is configured and how it changes over time.
For me, that's ultimately the value of the Tenant Audit. It gives us a chance to stop assuming we know what is inside the Microsoft 365 environment, document what is actually there and make informed decisions about what should happen next.
Frequently Asked Questions
What Is a Microsoft 365 Tenant Audit?
A Microsoft 365 Tenant Audit is a point-in-time review of how a company's Microsoft 365 environment is licensed, configured, secured and being used. The areas I review depend on the environment, but they can include licensing, administrative access, authentication, Conditional Access, Microsoft Defender, email security, devices, Intune, SharePoint, OneDrive, vendor access, third-party applications, backup and recovery, and other controls that are relevant to the business.
Do We Need an Audit If Microsoft 365 Seems to Be Working?
Microsoft 365 can work normally while important security or management issues exist underneath it. Employees may still receive email and access their files even though a Conditional Access policy was never enabled, a former vendor still has access, an old application remains authorized or company computers aren't being managed consistently. The audit gives us a way to verify the environment instead of assuming that because employees can work, everything behind the scenes is configured correctly.
Do You Review Our Microsoft 365 Licensing?
Yes. Licensing is part of the review because it determines which Microsoft security and management capabilities are available, and I want to know whether the company is using what it is paying for. I also look at whether the existing licensing still makes sense based on the company's current technology and security requirements.
Do You Review Microsoft Defender and Its Security Policies?
Yes. Where the client's licensing provides the relevant Defender capabilities, I review how those protections are configured rather than simply verifying that Defender appears in the Microsoft portal. That can include endpoint configuration, device onboarding, email-security policies, phishing and impersonation protections, alerts, notifications and other applicable Defender settings.
Do You Review Risky Users and Risky Sign-ins?
Where the client's Microsoft licensing provides the appropriate identity-risk information, I review risky users, risky sign-ins and related authentication information that may deserve investigation. The capabilities available vary by Microsoft Entra licensing, so this is also something I consider when reviewing the tenant's licenses.
Is Microsoft Getting Rid of SMS Authentication?
Microsoft is retiring Microsoft-provided SMS and voice authentication delivery in Microsoft Entra ID on February 1, 2027. Beginning September 1, 2026, Microsoft is moving users enabled for SMS or voice toward its passkey registration experience.
Businesses should review which authentication methods employees are currently using and develop an appropriate transition before the retirement date rather than waiting for employees to encounter the change during sign-in.
Do You Review Vendor and Outside IT Access?
Yes. I review relevant outside access so that the business has a clearer understanding of which vendors, guests, service providers and IT providers can access the Microsoft environment, how that access works and whether it is still required.
Do You Review Third-Party Applications?
Yes. I review relevant Enterprise Applications and third-party integrations to better understand what has been connected to the Microsoft environment, whether the business still uses those applications and how access or consent is being managed.
Can the Audit Help Us Prepare for Copilot or Other AI Tools?
It can be an important part of that preparation. Before a business expands its use of AI, I want to understand the identity, data, SharePoint permissions, external access and third-party applications underneath it. The Tenant Audit isn't a complete AI-governance program, but it can give us a technical baseline and identify areas that should be addressed before AI is more deeply integrated into the business.
Does Microsoft 365 Automatically Provide the Backup Strategy We Need?
I don't assume that it does. Microsoft 365 includes native retention and recovery capabilities, and Microsoft offers Microsoft 365 Backup as a separate service, but the business still needs to determine what it expects to be protected and recoverable. Backup and recovery are areas I review separately during the Tenant Audit.
What Is Included in the Run Book?
The contents depend on the environment, but the run book can document licensing, administrative access, authentication, Conditional Access, Defender, devices, SharePoint and OneDrive, vendor access, third-party integrations, backup and other important Microsoft 365 configurations. If I perform remediation, I update the run book to document the controls and configuration changes I implement along with the reasons behind those decisions.
Do You Document Microsoft Secure Score?
Yes. I capture Microsoft Secure Score as a point-in-time measurement during the audit and again after remediation when I perform the implementation. I don't make security decisions solely to increase the score, however, because each recommendation still needs to make sense for the client's environment.
Does the Cost of the Tenant Audit Apply Toward Remediation?
Yes. If the business chooses SNL-Tech Services to perform the remediation identified through the Microsoft 365 Tenant Audit, the cost of the audit is credited toward the implementation work. The audit can also stand on its own if the business decides not to proceed with remediation.
Do We Have to Use SNL-Tech Services for the Remediation?
No. The client receives the audit findings and documentation regardless of whether it chooses SNL-Tech Services to implement the recommendations.
Can the Run Book Help With Cyber-Insurance Readiness?
The run book can provide useful documentation when preparing for a cyber-insurance assessment or renewal because it gives the business a reference for security controls and configuration decisions that have been implemented. It doesn't guarantee coverage or replace an insurer's requirements, but it can help the business answer technical questions more accurately and identify areas that need additional work.
Does a Microsoft 365 Tenant Audit Make Our Business Compliant?
No. A Tenant Audit can identify Microsoft 365 configurations and controls that may be relevant to CMMC, HIPAA, GLBA or another regulatory or contractual requirement, but the Microsoft tenant is only one part of the broader compliance environment. The audit and run book can support a compliance-readiness effort without representing that the audit itself establishes compliance.
How Often Should We Have Microsoft 365 Reviewed?
The answer depends on how actively the environment is being managed and how much it changes. A new review can make sense after a security incident, a change in IT providers, a significant licensing change, a SharePoint project, introduction of new vendors, preparation for cyber-insurance or compliance requirements, or before a significant AI rollout.
Additional Information & Resources
I use Microsoft's own documentation when evaluating and configuring Microsoft 365 environments because features, licensing and recommended security practices continue to change. The following Microsoft resources provide additional technical information on several of the areas discussed in this article.
Microsoft — Passkeys by Default and Retirement of Microsoft-Provided SMS and Voice Authentication Microsoft's current guidance on the September 1, 2026 move toward passkeys and the February 1, 2027 retirement of Microsoft-provided SMS and voice authentication in Entra ID.
Microsoft — Microsoft Secure Score Microsoft's documentation explaining Secure Score, recommended actions and how the score can be used to measure and improve an organization's Microsoft security posture. Microsoft also makes clear that Secure Score should not be interpreted as a guarantee against a security breach.
Microsoft — Microsoft Entra Conditional Access Microsoft's overview of Conditional Access, including how identity, device, location, application and other signals can be used when deciding how users are allowed to access company resources.
Microsoft — Microsoft Entra ID Protection Microsoft's documentation for identifying and investigating identity risks, including risky users, risky sign-ins and risk detections.
Microsoft — Risky Users and Risky Sign-ins Additional Microsoft guidance explaining the risk reports and the information administrators can use when investigating potentially suspicious authentication activity.
Microsoft — Microsoft Defender for Business Microsoft's overview of Defender for Business, including endpoint detection and response, next-generation protection, vulnerability management and centralized device security. Defender for Business is included with Microsoft 365 Business Premium.
Microsoft — Microsoft Defender for Office 365 Microsoft's documentation covering email and collaboration security, including anti-phishing protections, Safe Links, Safe Attachments and email authentication technologies such as SPF, DKIM and DMARC.
Microsoft — SharePoint and OneDrive External Sharing Microsoft guidance covering external sharing controls for SharePoint and OneDrive, including organization-level and site-level sharing settings.
Microsoft — User and Administrator Application Consent Microsoft's explanation of how users and administrators can authorize third-party applications to access Microsoft-protected resources and why application permissions and consent should be reviewed.
Microsoft — Managing Application Consent and Consent Requests Microsoft's guidance for managing application consent, reviewing tenant-wide application permissions and controlling how new applications are authorized within an organization.
Microsoft — Microsoft 365 Backup Microsoft's documentation for Microsoft 365 Backup, including protection and recovery for Exchange Online mailboxes, OneDrive accounts and SharePoint sites. Microsoft 365 Backup is a pay-as-you-go offering rather than a backup entitlement automatically included simply because a company has Microsoft 365 Business Standard or Business Premium.





Bài của bạn trình bày ngắn gọn mà dễ hiểu, mình đọc liền một lượt là nắm được ý, cảm ơn bạn đã chia sẻ. Mình thì ngày nào cũng có thói quen xem thống kê XSMB, nhưng trước giờ cứ phải mở nhiều chỗ để so lại nên hơi mất thời gian. Thế là mình tự gom các thông tin cần thiết vào một chỗ cho tiện theo dõi, kiểu khi cần chỉ việc mở ra là xem ngay, lưu lại cũng đỡ quên. Mình để chung trên một trang ở soicau247.com để lúc muốn tra nhanh thì quay lại, khỏi phải nhớ từng nguồn lặt vặt. Bạn nào cũng hay cập nhật số liệu theo ngày như mình…