Microsoft 365 Audit & Health Check for Businesses
We assess the real state of your Microsoft 365 tenant to identify risk, inherited configuration, governance issues, misaligned licensing, operational debt and improvement opportunities before major changes are made.
A tenant review to understand what is working, what is not, and what to fix first
A tenant can operate for years while accumulating exceptions, ownerless groups, excessive permissions, outdated policies, underused licenses, unmanaged services and configuration that nobody wants to touch. A Health Check turns that complexity into decisions.
The audit is a defined engagement within Microsoft 365 Consulting
Microsoft 365 Consulting
Assessment, architecture, strategy, governance, design and implementation for organizations that need to evolve Microsoft 365.
Explore Microsoft 365 ConsultingAudit / Health Check
Structured tenant baseline, prioritized findings, evidence, recommendations and roadmap.
Microsoft Security Consulting
When the primary objective is to go deeper into Zero Trust, exposure, XDR/SIEM, privilege, data security or Azure Security.
Explore Microsoft Security ConsultingRemediation / operations
Findings can be addressed through a project, by the internal team or through managed services depending on scope.
Eight situations where a Microsoft 365 audit is useful before making more changes
The tenant has grown without an end-to-end review
Users, groups, sites, Teams, guests, policies and licenses have accumulated over time.
Access and privilege are difficult to justify
MFA, Conditional Access, roles, guests, enterprise applications or lifecycle processes need review.
A licensing renewal is approaching
Before renewal, it helps to understand what is used, what is missing and what can be reassigned.
Copilot or AI agents are about to be deployed
Permissions, oversharing, sensitive data and governance should be reviewed before AI access expands.
An incident or concerning signal has occurred
A cross-tenant review helps separate the immediate issue from structural tenant debt.
Compliance or audit requirements are approaching
You need to know which controls exist, what evidence they produce and which gaps remain open.

Collaboration has become difficult to govern
Teams, SharePoint, OneDrive, guests, sharing and ownership have become inconsistent.

The provider, operating model or architecture is about to change
An independent baseline reduces uncertainty before a migration, M&A, outsourcing or a new operating model.
Ten domains for assessing Microsoft 365 as one connected platform
Not every tenant needs the same depth. Scope is tailored, but a comprehensive audit should connect identity, collaboration, devices, data, security, licensing and operations.
Tenant & Governance
Global configuration, domains, roles, groups, owners, guests, lifecycle and conventions.
Admin center · ownership · baselineIdentity
MFA, Conditional Access, PIM, applications, guests, authentication and privilege.
Entra ID · CA · PIM
Exchange Online
Mail flow, permissions, forwarding, connectors, SPF, DKIM, DMARC and email protection.
Mail · DNS · permissions
Teams
Policies, external access, guests, meetings, apps, lifecycle, owners and governance.
Policies · guests · apps
SharePoint
Sites, sharing, permissions, owners, storage, inactive sites, links and exposure.
Sites · sharing · permissionsOneDrive
Sharing, external users, retention, ownership, capacity and inactive accounts.
Personal data · sharing
Intune & Endpoints
Enrollment, compliance, configuration, baselines, apps, updates, Autopilot and BYOD.
MDM · MAM · complianceSecurity Posture
Secure Score, Defender coverage, incidents, recommendations and high-level controls.
Signal, not a final gradeData & Compliance
Labels, DLP, retention, Audit, eDiscovery, sensitive data and data posture.
Purview · evidence · data riskCopilot Readiness
Licensing, permissions, oversharing, apps, data, security and governance before adoption.
AI readiness · permissionsBefore reviewing each workload, we need to understand how the tenant is governed
Global configuration and ownership shape everything else. We review how objects and services are created, administered and retired, who can make decisions, and which inherited settings remain active.
Roles & administrative model
Global and service-specific roles, administrative accounts, separation of duties, break-glass accounts and third-party access.
Users, groups & guests
Joiners, leavers, changes, ownership, abandoned groups, stale guests and accountability.
Global configuration
Domains, organization settings, sharing, apps, inherited policies and consistency across workloads.
Standards & exceptions
Conventions, owners, expiration, exceptions, periodic reviews and operational documentation.
The identity audit looks for implicit trust and privilege that is difficult to justify
We do not review MFA in isolation. We assess how users and administrators authenticate, which signals influence access, which applications have permissions and how privilege is governed.
MFA & methods
Allowed methods, registrations, sensitive accounts, legacy authentication and exceptions.
Conditional Access
Coverage, exclusions, report-only mode, risk, device trust and dependencies between policies.
PIM & roles
Standing privilege, eligibility, activation, approval and access to sensitive resources.
Guests & applications
Enterprise apps, service principals, consent, guests, access reviews and ownership.
Collaboration: review permissions, exposure, lifecycle and configuration without treating each service as an island

Email & mail flow
Permissions, forwarding, transport rules, connectors, shared mailboxes, mail authentication, anti-phishing and dependencies on Defender for Office 365.

Collaboration & meetings
Policies, external access, guest access, apps, meetings, lifecycle, ownership and the relationship with Microsoft 365 Groups and SharePoint.

Sites & permissions
External sharing, sharing links, owners, direct permissions, ownerless sites, storage, inactivity and content exposure.
Personal work data
Sharing, external users, inactive accounts, ownership, storage, retention and information risk after users leave.
Device posture matters when it influences access and protection decisions
When Intune is in scope, we assess whether enrollment, compliance, configuration and application management reflect the organization’s reality and whether device signals are used consistently.

Inventory & ownership
Corporate/personal ownership, platforms, enrollment methods, Autopilot and unmanaged devices.

Device state
Compliance policies, noncompliance, grace periods and the relationship with Conditional Access.

Baselines & configuration
Configuration profiles, security baselines, conflicts, legacy settings and drift.

Apps & updates
Deployments, assignments, update rings, reporting, ownership and exception management.
Secure Score helps surface signals; it does not replace an audit
Microsoft Secure Score, Defender recommendations, incident data and other native signals are useful for discovering gaps. But a recommendation may deserve a different priority depending on the asset, license, user impact, compensating controls and real architecture.
Secure Score
A posture indicator and source of recommended actions; useful for discovery and tracking, not as the tenant’s final grade.
Defender
Coverage, alerts, incidents, onboarding and configuration based on available products and licenses.
Identity signals
User/sign-in risk, privilege, methods and policies where those signals are available.
Real-world usage
A configuration can be technically valid and still be wrong for how the organization actually works.
A modern audit should also ask what data exists, who can share it, and what evidence remains
Depth depends on licensing and scope, but we review the information strategy and controls that affect exposure, retention, investigation and AI readiness.
Information Protection
Sensitivity labels, publication, scope, adoption and relationship with Microsoft 365 services.
DLP
Policies, locations, actions, alerts, exceptions and operational capability.
Retention & Records
Retention, deletion, records and alignment with real obligations and business requirements.
Audit / eDiscovery
Search and investigation capability, permissions, log retention and operational readiness.
Auditing before Copilot deployment reduces surprises around permissions, data and licensing
Technical & governance readiness
AI does not magically create new permissions, but it can make information a user can already access more discoverable. We therefore review sharing, sites, sensitive data, apps, identity, licensing and governance before adoption at scale.
A Microsoft 365 audit should also explain what is paid for, assigned and actually used
We do not reduce the analysis to “removing licenses.” We review editions, assignment, critical features, add-ons, dependencies and normalization opportunities so technical recommendations have a realistic commercial foundation.
What you own · who has it · what is used · what the roadmap will require.
- Microsoft 365 and Office 365 suites.
- Entra, Intune, Defender and Purview.
- Teams Phone/Rooms where applicable.
- Copilot and add-ons.
- Capabilities available but not deployed.
A healthy tenant depends on more than configuration: it also needs a clear operating model
We review operational signals that are often missed by a purely technical assessment: who monitors the service, who receives changes, who documents exceptions and how lifecycle is controlled. The Microsoft 365 Health dashboard also provides service health, update, security, usage and license-utilization signals that we put into context during the assessment.
Incidents & advisories
How service status is reviewed, how issues are escalated and who communicates business impact.
Microsoft changes
Ownership, change tracking, impact, testing and coordination with affected teams.
Runbooks & ownership
Procedures, owners, recurring administration and knowledge concentrated in specific individuals.
Periodic reviews
Guests, roles, groups, sites, licenses, exceptions and controls that need a review cadence.
Retention, native recovery and backup solve different problems: the audit reviews the full strategy
A Microsoft 365 environment can have retention, versioning and recycle-bin capabilities and still need a dedicated recovery or backup strategy. We review requirements, existing capabilities, ownership and restore scenarios without assuming one feature covers every case.
Preserve or delete
Policies and labels for lifecycle, regulatory and business requirements.
Versions & recovery
What each workload can recover and where the operational limits are.
Microsoft 365 Backup / third party
Need for rapid recovery, isolation, scope, RPO/RTO and protection model.
Restore testing
Who can restore, how requests are made, what is tested and how it is documented.
Every finding should explain evidence, impact, priority and next action
A useful audit does not deliver disconnected screenshots. Every finding needs enough context for another person to understand it, make a decision and act on it.
Configuration, condition or missing control.
Configuration, report, signal or reproducible evidence.
Risk, cost, operations or user experience.
Criticality, dependencies, effort and compensating controls.
Recommendation, owner and next step.
We can summarize maturity by domain without pretending one number describes the tenant
A scorecard can help leadership understand priorities when it is backed by evidence and is not presented as a certification or as the probability of an incident.
A traceable audit from scope to roadmap
The process adapts to size and depth while keeping discovery, evidence, analysis and decisions clearly separated.
Define scope
Objectives, tenants, workloads, exclusions, stakeholders and drivers.
Inventory
Architecture, licensing, users, groups, services, devices and dependencies.
Collect evidence
Configuration, reports, signals and interviews using the minimum access required.
Assess
Findings, inconsistencies, debt, risk, governance and utilization.
Contextualize
Real impact, licensing, business context, users, exceptions and compensating controls.
Prioritize
Risk, dependencies, effort, cost and execution capability.
Validate
Technical workshop to confirm context, false positives and decisions.
Deliver roadmap
Actions, owners, quick wins, projects, dependencies and next steps.
What should remain when a Microsoft 365 Health Check is complete
The value is that IT, leadership and remediation teams can work from the same evidence and priorities.
Executive Health Summary
Overall health, key risks, decisions and leadership priorities.
Tenant Assessment
Structured review by domain, scope and relevant configuration.
Findings Register
Findings with evidence, impact, priority, owner and recommendation.
Domain Scorecard
Maturity summary and key gaps by domain where useful.
Licensing Review
Licensing dependencies, available capabilities and optimization opportunities.
Quick Wins
Lower-risk, lower-effort actions that can be completed before the full roadmap.
Prioritized Roadmap
Remediation sequence, workstreams, dependencies and decisions.
Implementation Backlog
Actions defined well enough to estimate and execute afterwards.
The Health Check can be end-to-end or focused on the domains that actually need review
Microsoft 365 Health Check
Cross-tenant review with findings by domain, priorities and roadmap.
- Tenant-wide current state.
- Core workloads.
- Licensing + governance.
- Prioritized roadmap.
Focused assessment
Identity, collaboration, Intune, Purview, licensing, Copilot readiness or another defined domain.
- Defined scope.
- Greater depth.
- Focused backlog.
Baseline before transformation
Tenant baseline before a migration, M&A, provider change, Copilot deployment or a new operating model.
- Objective baseline.
- Risks and dependencies.
- Inputs for the subsequent project.
What a Microsoft 365 audit is—and what it should not promise
It can include
- Tenant configuration and posture.
- Identity, collaboration, devices, data and security.
- Licensing and utilization.
- Governance and operations.
- Findings, evidence and roadmap.
- Technical validation with stakeholders.
It does not automatically include
- Penetration testing or red teaming.
- ISO/ENS certification or another accreditation.
- Automatic remediation of every finding.
- 24x7 SOC or managed monitoring.
- Microsoft 365 backup included by default.
- A guarantee that an incident will not occur.
Audit, security consulting, implementation and operations answer different questions
How healthy is our tenant and what should we fix first?
Findings + roadmap.
How should we design, govern or evolve Microsoft 365?
Architecture + decisions + plan.
What security risks do we have and what Zero Trust/XDR/SIEM architecture do we need?
Security assessment + target state.
Who implements the agreed changes?
Configuration, pilot, rollout and validation.
Who maintains, reviews and optimizes it afterwards?
Ongoing operations.
An audit delivered by specialists who also understand implementation and operations
A finding is more valuable when the assessor understands its impact on Exchange, Teams, SharePoint, Entra, Intune, Defender, Purview, licensing and real users. That cross-platform perspective reduces theoretical recommendations that are difficult to execute later.
What we need to prepare a useful Microsoft 365 audit proposal
We do not need tenant access to prepare an initial scope. These inputs are enough to define depth, workstreams and effort.
Microsoft 365 Audit & Health Check: frequently asked questions
What is a Microsoft 365 audit?
It is a structured tenant review designed to establish current state, identify risk, inherited configuration, governance issues, misaligned licensing and improvement opportunities, and turn the findings into a prioritized roadmap.
What is the difference between a Microsoft 365 Health Check and Microsoft 365 consulting?
A Health Check is a diagnostic engagement with defined scope and deliverables. Consulting is broader and can include strategy, architecture, design, implementation and ongoing evolution.
Which services can be reviewed?
Depending on scope: tenant/governance, Microsoft Entra ID, Exchange Online, Teams, SharePoint Online, OneDrive, Intune, Defender, Purview, Copilot readiness, licensing and operations.
Do you assess Microsoft Entra ID?
Yes. We can review MFA, Conditional Access, roles, PIM, enterprise applications, guests, authentication methods, sensitive accounts and identity-governance processes based on available licensing.
Does the audit include Exchange Online?
It can include mail flow, permissions, shared mailboxes, forwarding, connectors, transport rules, domain authentication and email-protection controls depending on scope.
Do you assess Teams, SharePoint and OneDrive?
Yes. We review policies, external/guest access, sharing, owners, lifecycle, sites, groups, permissions, sharing links and information exposure, among other areas.
Does it include Intune?
It can include enrollment, compliance, configuration profiles, security baselines, applications, updates, Autopilot, BYOD and the relationship with Conditional Access.
Do you use Microsoft Secure Score?
Yes, as a posture signal and source of recommendations. We do not treat a Secure Score percentage as a complete representation of tenant risk or chase a universal target.
Is this a cybersecurity audit?
It includes a security review proportionate to scope, but it is broader: collaboration, governance, licensing, operations and readiness are also assessed. For a deep review of Zero Trust, XDR/SIEM, exposure or Azure Security, we use Microsoft Security Consulting.
Is it a penetration test?
No. Offensive testing is not performed by default. Penetration testing has a different objective and methodology and can complement a Health Check.
Can it support ISO 27001, ENS, NIS2, DORA or GDPR readiness?
It can help identify technical gaps and Microsoft 365 evidence relevant to a compliance program. It does not certify the organization or replace the auditor, legal adviser or certification body.
Do you review Microsoft 365 licensing?
Yes, when included in scope. We review assignment, dependencies, available capabilities, usage signals and possible normalization opportunities before recommending changes.
Is an audit useful before a licensing renewal?
Yes. It is a useful point to review what is deployed, what is underused and which future requirements could change the license mix.
Does it include Copilot readiness?
It can include licensing, permissions, oversharing, SharePoint/OneDrive, sensitive data, identity, apps and governance before Microsoft 365 Copilot or agents are expanded.
Do you review backup and recovery?
We can review recovery requirements, retention, native capabilities and backup strategy. Backup services or licensing are not automatically included with the audit.
Do you need Global Administrator permissions?
We do not assume Global Administrator by default. We define read-only roles or the minimum permissions required for each domain and agree access, duration and accounts with the customer.
Do you make changes during the audit?
The Health Check is designed as a diagnostic exercise. Urgent changes can be agreed separately; broader remediation is planned afterwards to avoid uncontrolled changes while evidence is being collected.
What deliverables do we receive?
Depending on scope: executive summary, tenant assessment, findings register, domain scorecard, licensing review, quick wins, prioritized roadmap and implementation backlog.
How are findings prioritized?
We combine impact and risk with criticality, dependencies, effort, cost, user experience, compensating controls and real execution capability.
Can we implement the roadmap ourselves?
Yes. The audit can end with a backlog for the internal team, continue into an MSAdvance project, or transition selected tasks into managed services.
The audit is a starting point; each need can then follow the right path
Microsoft 365 Consulting
Architecture, strategy, governance and tenant evolution.
Explore Microsoft 365 ConsultingMicrosoft Security Consulting
Zero Trust, Defender, Sentinel, Purview, exposure and Azure security.
Explore Microsoft Security ConsultingSuccess Stories
Real and anonymized Microsoft 365, Azure and security projects.
View success storiesTrust Center
Access, least privilege, confidentiality, change control and offboarding.
View Trust CenterManaged Services
Ongoing operations to keep the environment healthy after remediation.
Explore Managed ServicesGet a clear view of your tenant before deciding on the next project
Tell us the size of the environment, the main workloads and what triggered the need for review. We will define a Health Check with enough depth to produce useful findings and an actionable roadmap.






