Microsoft 365 AssessmentMicrosoft PartnerHealth Check · Tenant Review

Microsoft 365 Audit & Health Check for Businesses

We assess the real state of your Microsoft 365 tenant to identify risk, inherited configuration, governance issues, misaligned licensing, operational debt and improvement opportunities before major changes are made.

What does a Microsoft 365 audit include? A structured review of configuration, identity, Exchange, Teams, SharePoint, OneDrive, Intune, security, Purview, licensing, Copilot readiness and operations. The outcome is not a generic score: it is a set of findings with evidence, impact, priority, dependencies, recommended ownership and an actionable roadmap.
Official Microsoft image showing business professionals collaborating in a workplace environment
Microsoft 365 Health CheckConfiguration · risk · governance · licensing · operations
Discover
Assess
Prioritize
Roadmap
SpecializationMicrosoft PartnerMicrosoft 365, Azure, identity and security.
Track recordSince 2010Microsoft Cloud consulting and delivery.
Scale51.000+users across Microsoft Cloud projects.
Organizations500+customers and organizations supported.
Team25+Microsoft certifications across specialists.
Microsoft 365 Audit

A tenant review to understand what is working, what is not, and what to fix first

A tenant can operate for years while accumulating exceptions, ownerless groups, excessive permissions, outdated policies, underused licenses, unmanaged services and configuration that nobody wants to touch. A Health Check turns that complexity into decisions.

Direct answer: a Microsoft 365 audit provides a technical and operational baseline of the tenant, identifies evidence-based findings, prioritizes them by risk and impact, and turns them into a remediation roadmap. It is not an exercise in assigning blame or chasing a perfect score.
Current stateWhat exists, how it is configured and who operates it.
FindingsRisk, technical debt, inconsistencies and opportunities.
PriorityWhat should be addressed first based on impact, dependencies and effort.
RoadmapActions, ownership, sequence and next steps.
Where it fits

The audit is a defined engagement within Microsoft 365 Consulting

Consulting hub

Microsoft 365 Consulting

Assessment, architecture, strategy, governance, design and implementation for organizations that need to evolve Microsoft 365.

Explore Microsoft 365 Consulting
This service

Audit / Health Check

Structured tenant baseline, prioritized findings, evidence, recommendations and roadmap.

Specialist service

Microsoft Security Consulting

When the primary objective is to go deeper into Zero Trust, exposure, XDR/SIEM, privilege, data security or Azure Security.

Explore Microsoft Security Consulting
After the assessment

Remediation / operations

Findings can be addressed through a project, by the internal team or through managed services depending on scope.

When it makes sense

Eight situations where a Microsoft 365 audit is useful before making more changes

Microsoft 365
01 · Growth

The tenant has grown without an end-to-end review

Users, groups, sites, Teams, guests, policies and licenses have accumulated over time.

Microsoft Entra ID
02 · Identity

Access and privilege are difficult to justify

MFA, Conditional Access, roles, guests, enterprise applications or lifecycle processes need review.

Microsoft 365
03 · Renewal

A licensing renewal is approaching

Before renewal, it helps to understand what is used, what is missing and what can be reassigned.

Microsoft 365 Copilot
04 · Copilot

Copilot or AI agents are about to be deployed

Permissions, oversharing, sensitive data and governance should be reviewed before AI access expands.

Microsoft Defender
05 · Security

An incident or concerning signal has occurred

A cross-tenant review helps separate the immediate issue from structural tenant debt.

Microsoft Purview
06 · Audit

Compliance or audit requirements are approaching

You need to know which controls exist, what evidence they produce and which gaps remain open.

Microsoft Teams
07 · Governance

Collaboration has become difficult to govern

Teams, SharePoint, OneDrive, guests, sharing and ownership have become inconsistent.

Microsoft
08 · Change

The provider, operating model or architecture is about to change

An independent baseline reduces uncertainty before a migration, M&A, outsourcing or a new operating model.

Health Check map

Ten domains for assessing Microsoft 365 as one connected platform

Not every tenant needs the same depth. Scope is tailored, but a comprehensive audit should connect identity, collaboration, devices, data, security, licensing and operations.

Microsoft 365

Tenant & Governance

Global configuration, domains, roles, groups, owners, guests, lifecycle and conventions.

Admin center · ownership · baseline
Microsoft Entra ID

Identity

MFA, Conditional Access, PIM, applications, guests, authentication and privilege.

Entra ID · CA · PIM
Microsoft Exchange Online

Exchange Online

Mail flow, permissions, forwarding, connectors, SPF, DKIM, DMARC and email protection.

Mail · DNS · permissions
Microsoft Teams

Teams

Policies, external access, guests, meetings, apps, lifecycle, owners and governance.

Policies · guests · apps
Microsoft SharePoint

SharePoint

Sites, sharing, permissions, owners, storage, inactive sites, links and exposure.

Sites · sharing · permissions
Microsoft OneDrive

OneDrive

Sharing, external users, retention, ownership, capacity and inactive accounts.

Personal data · sharing
Microsoft Intune

Intune & Endpoints

Enrollment, compliance, configuration, baselines, apps, updates, Autopilot and BYOD.

MDM · MAM · compliance
Microsoft Defender

Security Posture

Secure Score, Defender coverage, incidents, recommendations and high-level controls.

Signal, not a final grade
Microsoft Purview

Data & Compliance

Labels, DLP, retention, Audit, eDiscovery, sensitive data and data posture.

Purview · evidence · data risk
Microsoft 365 Copilot

Copilot Readiness

Licensing, permissions, oversharing, apps, data, security and governance before adoption.

AI readiness · permissions
Tenant & Governance

Before reviewing each workload, we need to understand how the tenant is governed

Global configuration and ownership shape everything else. We review how objects and services are created, administered and retired, who can make decisions, and which inherited settings remain active.

Administration

Roles & administrative model

Global and service-specific roles, administrative accounts, separation of duties, break-glass accounts and third-party access.

Lifecycle

Users, groups & guests

Joiners, leavers, changes, ownership, abandoned groups, stale guests and accountability.

Baseline

Global configuration

Domains, organization settings, sharing, apps, inherited policies and consistency across workloads.

Governance

Standards & exceptions

Conventions, owners, expiration, exceptions, periodic reviews and operational documentation.

Microsoft Entra ID

The identity audit looks for implicit trust and privilege that is difficult to justify

We do not review MFA in isolation. We assess how users and administrators authenticate, which signals influence access, which applications have permissions and how privilege is governed.

Microsoft Entra ID
Authentication

MFA & methods

Allowed methods, registrations, sensitive accounts, legacy authentication and exceptions.

Microsoft Entra Conditional Access
Access

Conditional Access

Coverage, exclusions, report-only mode, risk, device trust and dependencies between policies.

Microsoft Entra PIM
Privilege

PIM & roles

Standing privilege, eligibility, activation, approval and access to sensitive resources.

Microsoft Entra ID Governance
Governance

Guests & applications

Enterprise apps, service principals, consent, guests, access reviews and ownership.

Exchange · Teams · SharePoint · OneDrive

Collaboration: review permissions, exposure, lifecycle and configuration without treating each service as an island

Exchange Online

Email & mail flow

Permissions, forwarding, transport rules, connectors, shared mailboxes, mail authentication, anti-phishing and dependencies on Defender for Office 365.

Microsoft Teams

Collaboration & meetings

Policies, external access, guest access, apps, meetings, lifecycle, ownership and the relationship with Microsoft 365 Groups and SharePoint.

SharePoint Online

Sites & permissions

External sharing, sharing links, owners, direct permissions, ownerless sites, storage, inactivity and content exposure.

OneDrive

Personal work data

Sharing, external users, inactive accounts, ownership, storage, retention and information risk after users leave.

A typical example: an issue that appears to be “a Teams problem” may actually be a Microsoft 365 Group, SharePoint site, guest-access or permissions problem. The audit finds the real dependency before recommending changes.
Intune & Endpoint Management

Device posture matters when it influences access and protection decisions

When Intune is in scope, we assess whether enrollment, compliance, configuration and application management reflect the organization’s reality and whether device signals are used consistently.

Microsoft Intune
Enrollment

Inventory & ownership

Corporate/personal ownership, platforms, enrollment methods, Autopilot and unmanaged devices.

Microsoft Intune
Compliance

Device state

Compliance policies, noncompliance, grace periods and the relationship with Conditional Access.

Microsoft Intune
Configuration

Baselines & configuration

Configuration profiles, security baselines, conflicts, legacy settings and drift.

Microsoft Intune
Operations

Apps & updates

Deployments, assignments, update rings, reporting, ownership and exception management.

Microsoft Intune security baselines
Security posture

Secure Score helps surface signals; it does not replace an audit

Microsoft Secure Score, Defender recommendations, incident data and other native signals are useful for discovering gaps. But a recommendation may deserve a different priority depending on the asset, license, user impact, compensating controls and real architecture.

Signal

Secure Score

A posture indicator and source of recommended actions; useful for discovery and tracking, not as the tenant’s final grade.

Coverage

Defender

Coverage, alerts, incidents, onboarding and configuration based on available products and licenses.

Risk

Identity signals

User/sign-in risk, privilege, methods and policies where those signals are available.

Context

Real-world usage

A configuration can be technically valid and still be wrong for how the organization actually works.

Security specialtyDo you need a much deeper security review?If the primary objective is Zero Trust, exposure, privilege, XDR/SIEM, Defender, Sentinel, Purview or Azure Security, the workstream should move into Microsoft Security Consulting.
Microsoft Secure Score
Microsoft Purview

A modern audit should also ask what data exists, who can share it, and what evidence remains

Depth depends on licensing and scope, but we review the information strategy and controls that affect exposure, retention, investigation and AI readiness.

Microsoft Purview
Protect

Information Protection

Sensitivity labels, publication, scope, adoption and relationship with Microsoft 365 services.

Microsoft Purview
Prevent

DLP

Policies, locations, actions, alerts, exceptions and operational capability.

Microsoft Purview
Lifecycle

Retention & Records

Retention, deletion, records and alignment with real obligations and business requirements.

Microsoft Purview
Evidence

Audit / eDiscovery

Search and investigation capability, permissions, log retention and operational readiness.

Microsoft Purview Data Security Posture Management
Copilot Readiness

Auditing before Copilot deployment reduces surprises around permissions, data and licensing

Microsoft 365 Copilot
Microsoft 365 Copilot

Technical & governance readiness

AI does not magically create new permissions, but it can make information a user can already access more discoverable. We therefore review sharing, sites, sensitive data, apps, identity, licensing and governance before adoption at scale.

OversharingPermissionsPurviewAppsLicensingGovernance
The question is not only “do we have licenses?”It also matters whether users may discover content that should not be so exposed, whether owners exist and whether data controls can be operated effectively.
The audit is not an adoption project.It identifies readiness and risk. Deployment, change management and adoption can be addressed afterwards through Consulting or Modern Workplace.
Microsoft now provides a Content Management Assessment to help prepare for Copilot and agents. Among other things, it helps surface potentially overshared content, inactive or ownerless sites and readiness findings. Where these capabilities are available, they can become part of the Health Check evidence.
Microsoft: prepare SharePoint for Copilot and agents
Licensing & Utilization

A Microsoft 365 audit should also explain what is paid for, assigned and actually used

We do not reduce the analysis to “removing licenses.” We review editions, assignment, critical features, add-ons, dependencies and normalization opportunities so technical recommendations have a realistic commercial foundation.

License review
4 questions

What you own · who has it · what is used · what the roadmap will require.

  • Microsoft 365 and Office 365 suites.
  • Entra, Intune, Defender and Purview.
  • Teams Phone/Rooms where applicable.
  • Copilot and add-ons.
  • Capabilities available but not deployed.
01
AssignmentLicenses by user, groups, exceptions and profiles.
02
UsageAvailable signals for adoption and service utilization.
03
DependenciesRecommendations that require P1/P2, E5, an add-on or additional consumption.
04
OptimizationOpportunities that should be validated before contracts or assignments are changed.
Operations & Change

A healthy tenant depends on more than configuration: it also needs a clear operating model

We review operational signals that are often missed by a purely technical assessment: who monitors the service, who receives changes, who documents exceptions and how lifecycle is controlled. The Microsoft 365 Health dashboard also provides service health, update, security, usage and license-utilization signals that we put into context during the assessment.

Service health

Incidents & advisories

How service status is reviewed, how issues are escalated and who communicates business impact.

Message center

Microsoft changes

Ownership, change tracking, impact, testing and coordination with affected teams.

Operations

Runbooks & ownership

Procedures, owners, recurring administration and knowledge concentrated in specific individuals.

Review

Periodic reviews

Guests, roles, groups, sites, licenses, exceptions and controls that need a review cadence.

Retention · Backup · Recovery

Retention, native recovery and backup solve different problems: the audit reviews the full strategy

A Microsoft 365 environment can have retention, versioning and recycle-bin capabilities and still need a dedicated recovery or backup strategy. We review requirements, existing capabilities, ownership and restore scenarios without assuming one feature covers every case.

Retention

Preserve or delete

Policies and labels for lifecycle, regulatory and business requirements.

Native recovery

Versions & recovery

What each workload can recover and where the operational limits are.

Backup

Microsoft 365 Backup / third party

Need for rapid recovery, isolation, scope, RPO/RTO and protection model.

Operations

Restore testing

Who can restore, how requests are made, what is tested and how it is documented.

We do not prescribe backup by default. We first understand loss, recovery and compliance scenarios. Then we decide whether native capabilities are sufficient or whether an additional solution is required.
Findings model

Every finding should explain evidence, impact, priority and next action

A useful audit does not deliver disconnected screenshots. Every finding needs enough context for another person to understand it, make a decision and act on it.

FindingWhat we found

Configuration, condition or missing control.

EvidenceWhat proves it

Configuration, report, signal or reproducible evidence.

ImpactWhy it matters

Risk, cost, operations or user experience.

PriorityWhen to act

Criticality, dependencies, effort and compensating controls.

ActionWhat happens next

Recommendation, owner and next step.

Priority does not come from a template. Two tenants with the same configuration may receive different priorities if asset criticality, exposure, licensing, users or operational capability are different.
A scorecard without score theatre

We can summarize maturity by domain without pretending one number describes the tenant

A scorecard can help leadership understand priorities when it is backed by evidence and is not presented as a certification or as the probability of an incident.

01FoundationalBasic controls or ownership are not yet consistently established.
02ManagedAn operating baseline exists, but gaps, exceptions or debt remain.
03ControlledControls are consistent, ownership is clear and reviews are regular.
04OptimizedAutomation, measurement and continuous improvement where they add value.
Metodología

A traceable audit from scope to roadmap

The process adapts to size and depth while keeping discovery, evidence, analysis and decisions clearly separated.

01 · Scope

Define scope

Objectives, tenants, workloads, exclusions, stakeholders and drivers.

02 · Discover

Inventory

Architecture, licensing, users, groups, services, devices and dependencies.

03 · Collect

Collect evidence

Configuration, reports, signals and interviews using the minimum access required.

04 · Assess

Assess

Findings, inconsistencies, debt, risk, governance and utilization.

05 · Contextualize

Contextualize

Real impact, licensing, business context, users, exceptions and compensating controls.

06 · Prioritize

Prioritize

Risk, dependencies, effort, cost and execution capability.

07 · Validate

Validate

Technical workshop to confirm context, false positives and decisions.

08 · Roadmap

Deliver roadmap

Actions, owners, quick wins, projects, dependencies and next steps.

Technical references: we validate findings against current Microsoft Learn guidance, native tenant signals and applicable good practices. Final recommendations are adapted to customer context rather than automatically copying every vendor suggestion.
Entregables

What should remain when a Microsoft 365 Health Check is complete

The value is that IT, leadership and remediation teams can work from the same evidence and priorities.

01

Executive Health Summary

Overall health, key risks, decisions and leadership priorities.

02

Tenant Assessment

Structured review by domain, scope and relevant configuration.

03

Findings Register

Findings with evidence, impact, priority, owner and recommendation.

04

Domain Scorecard

Maturity summary and key gaps by domain where useful.

05

Licensing Review

Licensing dependencies, available capabilities and optimization opportunities.

06

Quick Wins

Lower-risk, lower-effort actions that can be completed before the full roadmap.

07

Prioritized Roadmap

Remediation sequence, workstreams, dependencies and decisions.

08

Implementation Backlog

Actions defined well enough to estimate and execute afterwards.

Engagement models

The Health Check can be end-to-end or focused on the domains that actually need review

Scope & boundaries

What a Microsoft 365 audit is—and what it should not promise

It can include

  • Tenant configuration and posture.
  • Identity, collaboration, devices, data and security.
  • Licensing and utilization.
  • Governance and operations.
  • Findings, evidence and roadmap.
  • Technical validation with stakeholders.

It does not automatically include

  • Penetration testing or red teaming.
  • ISO/ENS certification or another accreditation.
  • Automatic remediation of every finding.
  • 24x7 SOC or managed monitoring.
  • Microsoft 365 backup included by default.
  • A guarantee that an incident will not occur.
Which service do you need?

Audit, security consulting, implementation and operations answer different questions

Service
Primary question
Outcome
Microsoft 365 Audit

How healthy is our tenant and what should we fix first?

Findings + roadmap.

Microsoft 365 Consulting

How should we design, govern or evolve Microsoft 365?

Architecture + decisions + plan.

Microsoft Security Consulting

What security risks do we have and what Zero Trust/XDR/SIEM architecture do we need?

Security assessment + target state.

Implementation project

Who implements the agreed changes?

Configuration, pilot, rollout and validation.

Managed Services

Who maintains, reviews and optimizes it afterwards?

Ongoing operations.

Official Microsoft image showing professionals collaborating in a workplace
Why MSAdvance

An audit delivered by specialists who also understand implementation and operations

A finding is more valuable when the assessor understands its impact on Exchange, Teams, SharePoint, Entra, Intune, Defender, Purview, licensing and real users. That cross-platform perspective reduces theoretical recommendations that are difficult to execute later.

Microsoft PartnerFocused on Microsoft technologies.
25+Microsoft certifications across the team.
Since 2010experience in consulting and project delivery.
51.000+users across Microsoft Cloud projects.
Scoping the Health Check

What we need to prepare a useful Microsoft 365 audit proposal

We do not need tenant access to prepare an initial scope. These inputs are enough to define depth, workstreams and effort.

01
UsersNumber of users, countries, business units and primary user profiles.
02
TenantOne or more tenants, domains, hybrid identity and relevant dependencies.
03
WorkloadsExchange, Teams, SharePoint, OneDrive, Intune, Defender, Purview and Copilot.
04
LicensingPrimary suites, add-ons and upcoming renewals.
05
DevicesVolume, platforms, Intune and management state.
06
DriversSecurity, licensing, Copilot, audit, M&A, migration or provider change.
07
DepthEnd-to-end Health Check or specific domains.
08
Target outcomeExecutive review, remediation backlog, roadmap or support for a subsequent project.
Frequently Asked Questions

Microsoft 365 Audit & Health Check: frequently asked questions

What is a Microsoft 365 audit?

It is a structured tenant review designed to establish current state, identify risk, inherited configuration, governance issues, misaligned licensing and improvement opportunities, and turn the findings into a prioritized roadmap.

What is the difference between a Microsoft 365 Health Check and Microsoft 365 consulting?

A Health Check is a diagnostic engagement with defined scope and deliverables. Consulting is broader and can include strategy, architecture, design, implementation and ongoing evolution.

Which services can be reviewed?

Depending on scope: tenant/governance, Microsoft Entra ID, Exchange Online, Teams, SharePoint Online, OneDrive, Intune, Defender, Purview, Copilot readiness, licensing and operations.

Do you assess Microsoft Entra ID?

Yes. We can review MFA, Conditional Access, roles, PIM, enterprise applications, guests, authentication methods, sensitive accounts and identity-governance processes based on available licensing.

Does the audit include Exchange Online?

It can include mail flow, permissions, shared mailboxes, forwarding, connectors, transport rules, domain authentication and email-protection controls depending on scope.

Do you assess Teams, SharePoint and OneDrive?

Yes. We review policies, external/guest access, sharing, owners, lifecycle, sites, groups, permissions, sharing links and information exposure, among other areas.

Does it include Intune?

It can include enrollment, compliance, configuration profiles, security baselines, applications, updates, Autopilot, BYOD and the relationship with Conditional Access.

Do you use Microsoft Secure Score?

Yes, as a posture signal and source of recommendations. We do not treat a Secure Score percentage as a complete representation of tenant risk or chase a universal target.

Is this a cybersecurity audit?

It includes a security review proportionate to scope, but it is broader: collaboration, governance, licensing, operations and readiness are also assessed. For a deep review of Zero Trust, XDR/SIEM, exposure or Azure Security, we use Microsoft Security Consulting.

Is it a penetration test?

No. Offensive testing is not performed by default. Penetration testing has a different objective and methodology and can complement a Health Check.

Can it support ISO 27001, ENS, NIS2, DORA or GDPR readiness?

It can help identify technical gaps and Microsoft 365 evidence relevant to a compliance program. It does not certify the organization or replace the auditor, legal adviser or certification body.

Do you review Microsoft 365 licensing?

Yes, when included in scope. We review assignment, dependencies, available capabilities, usage signals and possible normalization opportunities before recommending changes.

Is an audit useful before a licensing renewal?

Yes. It is a useful point to review what is deployed, what is underused and which future requirements could change the license mix.

Does it include Copilot readiness?

It can include licensing, permissions, oversharing, SharePoint/OneDrive, sensitive data, identity, apps and governance before Microsoft 365 Copilot or agents are expanded.

Do you review backup and recovery?

We can review recovery requirements, retention, native capabilities and backup strategy. Backup services or licensing are not automatically included with the audit.

Do you need Global Administrator permissions?

We do not assume Global Administrator by default. We define read-only roles or the minimum permissions required for each domain and agree access, duration and accounts with the customer.

Do you make changes during the audit?

The Health Check is designed as a diagnostic exercise. Urgent changes can be agreed separately; broader remediation is planned afterwards to avoid uncontrolled changes while evidence is being collected.

What deliverables do we receive?

Depending on scope: executive summary, tenant assessment, findings register, domain scorecard, licensing review, quick wins, prioritized roadmap and implementation backlog.

How are findings prioritized?

We combine impact and risk with criticality, dependencies, effort, cost, user experience, compensating controls and real execution capability.

Can we implement the roadmap ourselves?

Yes. The audit can end with a backlog for the internal team, continue into an MSAdvance project, or transition selected tasks into managed services.

Related services

The audit is a starting point; each need can then follow the right path

Consulting Hub

Microsoft 365 Consulting

Architecture, strategy, governance and tenant evolution.

Explore Microsoft 365 Consulting
Security

Microsoft Security Consulting

Zero Trust, Defender, Sentinel, Purview, exposure and Azure security.

Explore Microsoft Security Consulting
Evidence

Success Stories

Real and anonymized Microsoft 365, Azure and security projects.

View success stories
Trust

Trust Center

Access, least privilege, confidentiality, change control and offboarding.

View Trust Center
Operations

Managed Services

Ongoing operations to keep the environment healthy after remediation.

Explore Managed Services
Microsoft 365 Health Check

Get a clear view of your tenant before deciding on the next project

Tell us the size of the environment, the main workloads and what triggered the need for review. We will define a Health Check with enough depth to produce useful findings and an actionable roadmap.