Tenant Security & Compliance Audit

Perform a comprehensive audit of your Microsoft 365 tenant across eight security and compliance domains. This assessment is designed to be completed using least-privilege, read-only permissions — no elevated roles or write access required.

Least Privilege: All information needed for this audit can be gathered with Global Reader, Security Reader, and Reports Reader roles — plus read-only Microsoft Graph API permissions. No Global Admin or write access is required.

Identity & Access Management

How identities, authentication, and privileged access are secured.

Phish-resistant = FIDO2, Windows Hello, passkeys, or certificate-based auth.

PIM provides just-in-time role activation instead of standing admin access.

Conditional Access & Zero Trust

Policies governing access decisions and session security.

Legacy protocols (POP, IMAP, SMTP AUTH) bypass MFA entirely.

Data Protection & Information Governance

Classification, labelling, DLP, and retention policies.

Email Security

Anti-phishing, email authentication (DMARC/DKIM/SPF), and Defender for Office 365.

DMARC protects your domain from being spoofed in phishing emails.

Requires Defender for Office 365 Plan 1 or higher.

Endpoint Management

Device enrolment, compliance, app protection, and update management.

Collaboration Security

External sharing, guest access, Teams governance, and SharePoint controls.

Compliance & Governance

Audit logging, alert policies, eDiscovery, and insider risk.

Backup & Resilience

Break-glass accounts, backup strategy, disaster recovery, and incident response.

Cloud-only accounts excluded from Conditional Access, with secure credential storage.