What it is
A review of your Microsoft 365 organization: identities, sharing, shared mailboxes, backup, audit log, licences and compliance, with a report that names the risks and ranks them.
Microsoft 365
A Microsoft 365 environment that works is not necessarily a well-kept one. Most of the tenants we open were set up in a hurry a few years ago, then changed with every departure and every project. This page lists the twelve points we examine, the document you receive, and what you do with it next.
A Microsoft 365 audit reviews twelve points in read-only mode: identities, admin roles, conditional access, external sharing and guests, SharePoint and Teams, shared mailboxes, email security, backup, the audit log, mobile devices, licences and Law 25. The result is a report of findings ranked by risk, with a remediation plan in three stages.
The short answer
A Microsoft 365 audit checks how a small business’s Microsoft 365 organization, its tenant, is configured, and not only whether it works. OKTO Solutions examines twelve points: identities, admin roles, conditional access, external sharing and guests, SharePoint and Teams, shared mailboxes, email security, backup, the audit log, mobile devices, licences and Law 25. The review is done in read-only mode, with no interruption for employees. It brings out what has piled up over the years with each departure and each project: a former employee’s mailbox turned into a shared mailbox, a supplier’s guest access still open after the project ended, a sharing link with no end date. The business receives a report of findings ranked by risk, along with a remediation plan in three stages. That report belongs to the business, even if it hands the fixes to someone else.
In brief
The review is done in read-only mode, with no interruption for your employees, and the report is yours even if someone else handles the fixes.
A review of your Microsoft 365 organization: identities, sharing, shared mailboxes, backup, audit log, licences and compliance, with a report that names the risks and ranks them.
A small business that inherited its tenant, changed providers, has to fill out a security questionnaire, or is about to point an assistant like Copilot at its data.
You know what is open, to whom, and since when. You walk away with an order of fixes instead of a pile of alerts with no priority.
Understanding
Microsoft 365 ships with settings meant to make everything work the first time. They are fine for getting started, and wrong for a thirty-person company five years later. Nobody picked them. They just stayed.
Then comes the buildup. An employee leaves, their mailbox becomes a shared mailbox so nothing gets lost, and three years later five people still have access. A supplier gets guest access for a project, the project ends, the access stays. Someone creates a sharing link to send a client a file, with no end date.
An audit is not about finding someone to blame. It takes stock of what has piled up, says what is risky for you, and separates what takes a few minutes to fix from what needs a project.
What is covered
For each point: what we look at, and what we most often find in a Quebec small business.
What we look at. Active accounts, former employees’ accounts, service accounts, multi-factor authentication that is enforced for good, fallback methods, passwords set to never expire.
What we often find. Multi-factor authentication on for most people, but not for the accounts that matter most: management, accounting, administrators.
What we look at. How many global administrators there are, who they are, whether a former provider is still among them, and whether those accounts double as everyday mailboxes.
What we often find. Far too many global administrators, and an admin account used every day to read email.
What we look at. What is required depending on the device, the location and the application, and whether exclusions were added to get someone unstuck and then forgotten.
What we often find. No policy at all, or a policy whose exclusion list kept growing until it meant nothing.
What we look at. Who can invite someone from outside, the real list of guest accounts, their last sign-in, and sharing links with no end date.
What we often find. Guests left over from a finished project, and links open to anyone who has them, created years ago.
What we look at. Sites shared with the whole organization, orphaned libraries, teams in Teams with no active owner, and where sensitive documents are actually stored.
What we often find. Payroll or management documents in a space everyone can open, without anyone having meant it.
What we look at. Mailboxes converted when someone left, who can still open them, automatic forwarding rules and delegations.
What we often find. A forwarding rule to a personal address, set up by an employee who left long ago.
What we look at. SPF, DKIM and DMARC, phishing protection, quarantine rules, and how senders allowed by default are handled.
What we often find. DMARC missing or left in monitoring mode, so someone can write to your clients in your name.
What we look at. What is backed up outside the service, how often, where the copies are kept, and whether a restore has ever been tested.
What we often find. The belief that Microsoft backs everything up. The recycle bin and retention are not a backup, and they have an end date.
What we look at. Whether logging is turned on, since when, how long it is kept, and whether anyone actually receives the alerts.
What we often find. Alerts sent to an address nobody reads anymore.
What we look at. Which devices connect to your environment, which ones are managed, and what happens when a personal phone gets lost.
What we often find. Company email on personal phones, with nothing in place to wipe it remotely.
What we look at. Licences assigned to inactive accounts, duplicates, plans bought for a need that went away, and features already paid for but never turned on.
What we often find. Security features included in the plan you already pay for, never switched on.
What we look at. Where personal information sits, who can reach it, how an incident would be noticed and logged, and what exists as a register.
What we often find. A written policy that does not match what the environment actually does.
How it works
Four stages. Collection is read-only: no setting is changed during the review.
A short meeting to understand what your organization does, what cannot go down, and what you owe your clients or your insurer. That is what decides what counts as a serious risk for you.
A survey of your Microsoft 365 organization through the admin tools: identities, sharing, mailboxes, policies, logs, licences. A read account is enough, and it is removed at the end.
Each finding is scored on two axes: how likely it is to be exploited, and what it would do to your business if it were. That combination sets the order, not the severity a tool displays.
A meeting where we go through the findings without jargon, with a plan spread over time: what gets fixed right away, what needs a project, what needs a budget.
The deliverable
The report is written for management, not only for a technician. It fits in one document, and every finding comes with its evidence.
Afterwards
A good share of the immediate fixes gets done in the admin centre, with no project and no interruption: removing guests, closing links, cutting the number of administrators, turning on logging. That is often half the findings.
Questions and answers
We set the scope together, collect in read-only mode, analyze, and present the findings with an order of fixes. The first meeting comes with no obligation.
Reviewed by Antonio Pazzi, president of OKTO Solutions · updated
We use cookies that are strictly necessary for the site to work. Only with your consent do we add measurement cookies that tell us which pages get read. Refusing costs you nothing, and you can change your mind at any time from the bottom of any page. Cookie details.