Trois-Rivières, serving all of Quebec 450 231-3836 info@oktosolutions.ca
FR

Microsoft 365

Microsoft 365 audit for Quebec SMBs: the twelve points we check

A Microsoft 365 environment that works is not necessarily a well-kept one. Most of the tenants we open were set up in a hurry a few years ago, then changed with every departure and every project. This page lists the twelve points we examine, the document you receive, and what you do with it next.

A Microsoft 365 audit reviews twelve points in read-only mode: identities, admin roles, conditional access, external sharing and guests, SharePoint and Teams, shared mailboxes, email security, backup, the audit log, mobile devices, licences and Law 25. The result is a report of findings ranked by risk, with a remediation plan in three stages.

The short answer

What does a Microsoft 365 audit check in a small business?

A Microsoft 365 audit checks how a small business’s Microsoft 365 organization, its tenant, is configured, and not only whether it works. OKTO Solutions examines twelve points: identities, admin roles, conditional access, external sharing and guests, SharePoint and Teams, shared mailboxes, email security, backup, the audit log, mobile devices, licences and Law 25. The review is done in read-only mode, with no interruption for employees. It brings out what has piled up over the years with each departure and each project: a former employee’s mailbox turned into a shared mailbox, a supplier’s guest access still open after the project ended, a sharing link with no end date. The business receives a report of findings ranked by risk, along with a remediation plan in three stages. That report belongs to the business, even if it hands the fixes to someone else.

In brief

The Microsoft 365 audit in three points

The review is done in read-only mode, with no interruption for your employees, and the report is yours even if someone else handles the fixes.

What it is

A review of your Microsoft 365 organization: identities, sharing, shared mailboxes, backup, audit log, licences and compliance, with a report that names the risks and ranks them.

Who it is for

A small business that inherited its tenant, changed providers, has to fill out a security questionnaire, or is about to point an assistant like Copilot at its data.

What it changes

You know what is open, to whom, and since when. You walk away with an order of fixes instead of a pile of alerts with no priority.

Understanding

Why can a tenant that works be wide open?

Microsoft 365 ships with settings meant to make everything work the first time. They are fine for getting started, and wrong for a thirty-person company five years later. Nobody picked them. They just stayed.

Then comes the buildup. An employee leaves, their mailbox becomes a shared mailbox so nothing gets lost, and three years later five people still have access. A supplier gets guest access for a project, the project ends, the access stays. Someone creates a sharing link to send a client a file, with no end date.

An audit is not about finding someone to blame. It takes stock of what has piled up, says what is risky for you, and separates what takes a few minutes to fix from what needs a project.

  • What piled up with departures and projects
  • What is risky for you, not in theory
  • What can be fixed in a few minutes, kept apart from the rest

What is covered

What are the twelve points examined?

For each point: what we look at, and what we most often find in a Quebec small business.

01

Identities and authentication

What we look at. Active accounts, former employees’ accounts, service accounts, multi-factor authentication that is enforced for good, fallback methods, passwords set to never expire.

What we often find. Multi-factor authentication on for most people, but not for the accounts that matter most: management, accounting, administrators.

02

Admin roles

What we look at. How many global administrators there are, who they are, whether a former provider is still among them, and whether those accounts double as everyday mailboxes.

What we often find. Far too many global administrators, and an admin account used every day to read email.

03

Conditional access policies

What we look at. What is required depending on the device, the location and the application, and whether exclusions were added to get someone unstuck and then forgotten.

What we often find. No policy at all, or a policy whose exclusion list kept growing until it meant nothing.

04

External sharing and guests

What we look at. Who can invite someone from outside, the real list of guest accounts, their last sign-in, and sharing links with no end date.

What we often find. Guests left over from a finished project, and links open to anyone who has them, created years ago.

05

SharePoint, OneDrive and Teams

What we look at. Sites shared with the whole organization, orphaned libraries, teams in Teams with no active owner, and where sensitive documents are actually stored.

What we often find. Payroll or management documents in a space everyone can open, without anyone having meant it.

06

Shared mailboxes and former employees

What we look at. Mailboxes converted when someone left, who can still open them, automatic forwarding rules and delegations.

What we often find. A forwarding rule to a personal address, set up by an employee who left long ago.

07

Email security

What we look at. SPF, DKIM and DMARC, phishing protection, quarantine rules, and how senders allowed by default are handled.

What we often find. DMARC missing or left in monitoring mode, so someone can write to your clients in your name.

08

Backup of Microsoft 365 data

What we look at. What is backed up outside the service, how often, where the copies are kept, and whether a restore has ever been tested.

What we often find. The belief that Microsoft backs everything up. The recycle bin and retention are not a backup, and they have an end date.

09

Audit log and detection

What we look at. Whether logging is turned on, since when, how long it is kept, and whether anyone actually receives the alerts.

What we often find. Alerts sent to an address nobody reads anymore.

10

Devices and mobile access

What we look at. Which devices connect to your environment, which ones are managed, and what happens when a personal phone gets lost.

What we often find. Company email on personal phones, with nothing in place to wipe it remotely.

11

Licences and wasted spending

What we look at. Licences assigned to inactive accounts, duplicates, plans bought for a need that went away, and features already paid for but never turned on.

What we often find. Security features included in the plan you already pay for, never switched on.

12

Law 25 in the tenant

What we look at. Where personal information sits, who can reach it, how an incident would be noticed and logged, and what exists as a register.

What we often find. A written policy that does not match what the environment actually does.

How it works

How does the Microsoft 365 audit unfold?

Four stages. Collection is read-only: no setting is changed during the review.

01

Scoping

A short meeting to understand what your organization does, what cannot go down, and what you owe your clients or your insurer. That is what decides what counts as a serious risk for you.

02

Read-only collection

A survey of your Microsoft 365 organization through the admin tools: identities, sharing, mailboxes, policies, logs, licences. A read account is enough, and it is removed at the end.

03

Analysis and ranking

Each finding is scored on two axes: how likely it is to be exploited, and what it would do to your business if it were. That combination sets the order, not the severity a tool displays.

04

Presentation and plan

A meeting where we go through the findings without jargon, with a plan spread over time: what gets fixed right away, what needs a project, what needs a budget.

The deliverable

What does the audit report contain?

The report is written for management, not only for a technician. It fits in one document, and every finding comes with its evidence.

  • A one-page summary for management, with the major risks stated as consequences for the business
  • The real inventory of what was found: accounts, guests, open shares, shared mailboxes, devices, licences
  • Each finding with its evidence, its risk level and what would happen if it were exploited
  • A remediation plan in three stages: immediate, to schedule, to budget
  • What is already done well, named plainly, so nothing that works gets undone
A read role is enough. We tell you which role is requested and when, and the access is removed at the end of the mandate. You can see the trace of our sign-ins in your own audit log.
The report is yours. You can hand the fixes to your internal team, to your current provider or to us. That is a deliberate choice on our part: an audit whose conclusions only serve to sell next quarter’s service is worth nothing.
  • What you need to answer a security questionnaire from a client or an insurer
  • A baseline for measuring progress at the next review

Afterwards

What do you do with the report?

A good share of the immediate fixes gets done in the admin centre, with no project and no interruption: removing guests, closing links, cutting the number of administrators, turning on logging. That is often half the findings.

Questions and answers

Frequently asked questions about the Microsoft 365 audit

Do we have to give you full administrator access?
No. A read role on your Microsoft 365 organization covers most of the collection. We tell you exactly which role is requested and when, and the access is removed at the end of the mandate. You can see the trace of our sign-ins in your own audit log.
Does the audit get in the way of employees?
No. Collection is done in read mode, with no configuration change and no service interruption. What takes time on your side is the scoping meeting at the start and the presentation meeting at the end.
Do we have to be an OKTO client to get an audit?
No. The audit is a standalone mandate. The report belongs to you and stays usable even if the fixes go to someone else or to your internal team.
How is this different from the security score Microsoft shows?
Microsoft’s security score is a good reference, but it does not know your business. It grades settings without knowing which ones matter for you, and it ignores what lives next to the tenant: your backups, your devices, your obligations to your clients. We start from your situation, then use those indicators as one source among others.
What does the audit rely on?
On Microsoft’s administration documentation for the settings, on the baseline cyber security controls of the Canadian Centre for Cyber Security for setting priorities, and on the requirements of Law 25 for the personal information side.
How often should the review be repeated?
An environment keeps changing: employees arrive and leave, applications get added, access is granted to sort out a problem. Repeating the review confirms that the fixes held. For our managed services clients, part of that check is continuous rather than one-off.

Have your Microsoft 365 environment reviewed

We set the scope together, collect in read-only mode, analyze, and present the findings with an order of fixes. The first meeting comes with no obligation.

Reviewed by , president of OKTO Solutions · updated