Office 365 Security Audit: Process and Key Review Areas
By Gordon Graff · Published
Office 365 has been called Microsoft 365 since 2020. An Office 365 security audit is therefore a review of your Microsoft 365 configuration: where does the tenant have gaps, and what should be fixed first?
This article describes the review areas and the typical process so you know what to expect.
Process in three phases
First comes a discovery with read-only access to the tenant. Then the configuration is assessed against Microsoft recommendations and your requirements. The result is a report with findings sorted by risk and a remediation plan.
Identities and access
Administrator roles, MFA, Conditional Access, guests and apps are among the most important areas because compromised identities are a common attack path. See our Entra ID Security Baseline checklist for details.
Email protection in Exchange Online
The audit checks protection policies against phishing and malware (Microsoft provides preset Standard and Strict policies), email authentication with SPF, DKIM and DMARC, and the rules for automatic external forwarding.
Sharing in SharePoint and OneDrive
External sharing settings apply at tenant level and can only be made stricter, not looser, for individual sites. The audit checks whether “Anyone” links are allowed and how much content has been shared externally.
Devices and endpoints
This assesses whether devices are managed through Intune, compliance policies apply and access is tied to them through Conditional Access.
Logging and Secure Score
Without logs, incidents cannot be investigated. The audit checks whether audit logging is active and how long logs are retained. Microsoft Secure Score serves as an additional reference value but does not replace a risk-based assessment.
Key takeaway
A security audit covers identities, email protection, sharing, devices and logging. What matters in the end is not the number of findings but a clear order of what to fix first. The free security check gives you a first impression beforehand.