An M365 security audit is a structured review of how your Microsoft 365 tenant is set up: who can reach what, how your data is protected, and whether you would spot an attack. It checks identity, data, devices, email and logging, then ranks the gaps it finds by risk. The output is a prioritised plan, not a score.
Key Takeaways
- An audit covers the whole tenant, not just settings. Identity, data, devices, email and logging get reviewed together, because a gap in one usually depends on a gap in another.
- Microsoft 365 and Office 365 audits are the same work. The name changed in 2020. The tenant did not.
- Secure Score is a starting point, not a verdict. A high score does not mean you are secure. A low score usually does mean real exposure.
- The output should be a plan, not a list. Findings ranked by likelihood, impact and remediation effort tell your team what to fix on Monday.
- An audit covers part of the Essential 8, not all of it. It evidences multi-factor authentication, admin privilege and logging. It does not cover patching, application control or backup testing.
What Is an M365 Security Audit?
An M365 security audit is a systematic review of your Microsoft 365 tenant configuration, access controls, data protection settings and monitoring. It finds where your setup leaves you exposed, ranks those gaps, and gives you a remediation plan.
It answers four questions:
- Who can reach your systems and data, and under what conditions?
- Is sensitive information protected in a way that matches how it is actually used?
- Would you detect an intrusion, and how fast?
- Could you prove any of this to an auditor, an insurer or a client?
Most organisations do not end up exposed because someone made a bad call. They end up exposed because hundreds of small, sensible decisions piled up.
A user gets added without multi-factor authentication. An admin role is granted for a project and never removed. External sharing goes on so a supplier can see one folder. Each change made sense at the time. Nobody has looked at the whole picture since.
The audit is a point-in-time check. Its real value is the ordering it applies. A tenant with forty gaps does not need forty projects. It usually needs four or five, in the right sequence.
Is an Office 365 Security Audit the Same Thing?
Yes. An Office 365 security audit, an Office 365 security assessment and an Office 365 security risk assessment all describe the same work as a Microsoft 365 security audit.
Microsoft renamed Office 365 to Microsoft 365 in 2020 for most business subscriptions. The older name stuck. Plenty of Australian organisations still hold documentation, invoices and internal policies that say Office 365.
The tenant being reviewed is identical. The admin centres are identical. The controls are identical. The naming only matters when you are reading older guidance, where some product names and policy locations have since moved.
One thing does differ between older and current subscriptions: feature entitlements. Some controls are simply not included in certain plans. A useful audit tells you which gaps exist because a setting was never switched on, and which exist because your licence does not include the setting at all. Those are different problems with different answers.
What Does an M365 Security Audit Check?
The audit works through a fixed checklist, so nothing gets skipped on the assumption that it is probably fine.
Microsoft 365 Security Audit Checklist
- Multi-factor authentication coverage across all accounts, including service accounts, shared mailboxes and admin accounts
- Admin roles and privileged access, including how many global administrators exist and whether each is still needed
- Legacy authentication protocols, and whether they are still enabled
- Conditional access policies, including location, device state and sign-in risk conditions
- External sharing settings and guest account review
- Data loss prevention policies and sensitivity labelling
- Microsoft Defender configuration, including anti-phishing, safe links and safe attachments
- Audit logging and retention, and whether the retention period matches your obligations
- OAuth applications and third-party integrations, and what permissions each holds
- Device compliance and endpoint enrolment through Intune
The Six Domains an Audit Reviews
| Domain | What gets reviewed | Why it matters |
|---|---|---|
| Identity and access | MFA coverage, admin roles, conditional access, legacy authentication | Identity is the most common way into a Microsoft 365 tenant |
| Data protection | DLP policies, encryption, sensitivity labels, external sharing | Decides whether data can leave without anyone noticing |
| Threat protection | Defender settings, anti-phishing, safe links, safe attachments | Decides whether a malicious message reaches a user at all |
| Compliance and logging | Audit logs, retention policies, evidence availability | No logs means no investigation and no compliance evidence |
| Device security | Intune compliance, endpoint protection, unmanaged device access | Unmanaged devices bypass most tenant-level controls |
| Application access | OAuth apps, third-party integrations, API permissions | Granted app permissions outlive the person who granted them |
A review that covers only one domain gives a misleading result. Identity is usually the weakest and the most costly to get wrong, because one compromised account gives an attacker everything that account could reach.
How Does a Microsoft 365 Security Risk Assessment Prioritise Risk?
A Microsoft 365 security risk assessment ranks each finding on three things at once: how likely it is to be exploited, what an attacker would reach through it, and what fixing it would cost you in effort and disruption.
That last factor is what stops a report gathering dust. A list of every deviation from best practice, with no weighting, gives you nothing to act on.
Here is the difference in practice.
A finding says: legacy authentication is enabled.
A risk assessment says: legacy authentication is enabled, eight accounts are using it, two of those hold elevated privileges, and turning it off will break one line-of-business integration that needs reconfiguring first.
The first is a fact. The second is a decision you can actually make.
What Microsoft Secure Score Does and Does Not Tell You
Microsoft Secure Score is a useful starting point, but it is a guidance framework rather than a risk measure.
It scores your tenant against Microsoft’s recommended controls, compares you against benchmarks, and tracks improvement over time. That last part is genuinely useful when you need to show progress to a board or an insurer.
What it cannot know is which of your data matters, who your users are, or which controls you have turned down for a sound business reason. So a high score does not mean you are secure.
A low score is the more reliable signal. It usually does point at real exposure.
What Audits Most Often Find
The same five gaps turn up across tenants of every size.
- Incomplete multi-factor authentication. MFA is enforced for staff but not for service accounts, shared mailboxes or admin accounts. Those are the accounts an attacker looks for first.
- Too much admin privilege. More global administrators than anyone can justify, roles granted for a project and never revoked, and access that survived a promotion or a resignation.
- Conditional access that creates false confidence. Policies exist, but they allow sign-in from anywhere, permit unmanaged devices, or ignore risk-based sign-in detection.
- External sharing nobody reviews. Anyone-with-the-link access switched on, guest accounts never re-checked, and SharePoint libraries reachable more widely than intended.
- Third-party apps nobody tracks. OAuth integrations holding mailbox read and write permissions, with no review of what was granted or by whom.
What Do You Receive at the End of the Audit?
You receive a report you can act on, plus the baseline to measure against later. A Kloudify Microsoft 365 security audit produces:
- Findings report. Every domain reviewed, written so your IT team and your leadership can both use it.
- Risk register. Each finding ranked by likelihood, impact and remediation effort.
- Remediation roadmap. Split into immediate actions, short-term work and longer-term posture improvements, with ownership assigned. You keep the plan whether or not Kloudify does the implementation.
- Configuration baseline. A record of your current position, so future drift can be measured against it.
- Walkthrough session. A working conversation about the findings and what happens next, rather than a document sent by email.
Where a gap cannot be closed without a licence change, we say so plainly and set out the alternative. Working out what your current subscription already includes is often the first decision to make, and our guide to Microsoft 365 security licensing shows where those boundaries fall.
How Strategix Strengthened Security with Microsoft 365
See how we worked with Strategix to improve their Microsoft 365 security posture.
How Does an M365 Security Audit Support Essential 8 Compliance?
An M365 security audit gives you the tenant-side evidence for several Essential 8 mitigation strategies at once, but it does not replace a full Essential 8 assessment.
The Essential 8 is the Australian Signals Directorate’s set of baseline mitigation strategies. It is increasingly the benchmark Australian organisations get measured against, particularly those working with government, operating in the NDIS sector, or meeting client security requirements.
The audit directly evidences three of the eight: multi-factor authentication, restricting administrative privileges, and the logging that supports both.
It does not cover the strategies that live outside Microsoft 365. Application control, patching of operating systems and applications, and backup restoration testing all sit elsewhere in your environment.
Running the audit first is usually the cheaper order. You find out what your Microsoft 365 environment already satisfies before you scope the wider piece of work. Our Essential 8 compliance page explains how the two fit together.
If your obligations go further, the reporting can be mapped to other frameworks as well: the Privacy Act 1988 and the Australian Privacy Principles, ISO 27001, the NDIS Practice Standards, or the GDPR where you hold data on people in the EU. Tell us which ones apply and the report is structured to match.
How Often Should You Run a Microsoft 365 Security Audit?
Between once a quarter and once a year, depending on how fast your environment changes and how regulated you are.
| Organisation type | Suggested frequency |
|---|---|
| Highly regulated, including healthcare, finance and NDIS providers | Quarterly |
| Medium-risk organisations | Every six months |
| Low-risk, stable environments | Annually |
| After a significant change or incident | Immediately |
Some events warrant an immediate review whatever the schedule says. A security incident. A merger that brings a second tenant into play. A major change to who holds admin rights. Any material shift in your compliance obligations.
Between formal audits, keep monitoring running. Our overview of Microsoft Defender XDR explains how continuous detection works alongside periodic auditing.
When an Audit Is Not What You Need
Sometimes a configuration audit is the wrong instrument. Three situations call for something else.
- You need adversarial testing. An audit reviews configuration against good practice. It does not attempt to break in. If you need to know whether a determined attacker could get through, that is penetration testing, which is a separate discipline.
- You need formal certification against a standard. An audit helps you improve and evidence your position. It does not certify you, and no managed service provider can certify you against a standard they also help you meet. That requires an independent certification body.
- You already know what is wrong and nobody has fixed it. If a previous review is sitting unactioned, a second review will not change the outcome. The constraint is remediation capacity, not visibility.
Kloudify focuses on Microsoft-centred security work for Australian small and medium businesses. If your requirement sits outside that, a specialist will serve you better, and any provider worth appointing will say so.
How Kloudify Delivers Microsoft 365 Security Audits
Kloudify works with businesses across Australia. Delivery is remote, with onsite support when a piece of work needs it.
We review identity controls, data governance, Defender configuration, compliance alignment and tenant complexity, then translate what we find into a plan your team can actually deliver. We prioritise on the basis of your size, sector and regulatory exposure, rather than handing over an undifferentiated best-practice checklist.
Smaller organisations in particular do better fixing five things properly than opening twenty workstreams. That is why our small business IT support engagements usually start with an audit rather than a migration.
Published examples include a Microsoft 365 security engagement with Strategix, an Essential 8 audit for Thrive House supporting NDIS compliance, and security and endpoint management work for Spectrum Medical Imaging.
The Bottom Line
The bottom line: an M365 security audit is most useful when you already run on Microsoft 365 but nobody has reviewed the whole tenant against your actual risk. It will not tell you that you are secure. It will tell you which five things to fix first, why those five, and what each one costs to close.
If your environment has not been formally reviewed in the past twelve months, that is the signal to run one. Start with the audit, then decide on licensing and compliance work once you can see what you are dealing with.
Book a consultation, or read more about our cyber security services if you want the wider picture first.
Frequently Asked Questions
It is a structured review of how your Microsoft 365 tenant is configured across identity, data protection, devices, email and logging. It finds where your setup leaves you exposed, ranks those gaps by risk, and gives you a remediation plan. It is a point-in-time check, not an ongoing monitoring service.
In practice, none. Both describe the same review of your tenant. Where people do draw a line, assessment tends to mean the evaluation itself and audit tends to imply a formal report suitable for a compliance process. Kloudify delivers both as one engagement and adjusts the reporting to whichever outcome you need.
The same work as a Microsoft 365 security audit. Microsoft renamed Office 365 to Microsoft 365 in 2020 for most business subscriptions, but the old name is still in wide use. The tenant, the admin centres and the controls reviewed are identical.
The same domains as the audit, but with each finding weighted by how likely it is to be exploited, what an attacker would reach through it, and what fixing it would cost. The output is a ranked risk register rather than a flat list of configuration deviations, so your team can sequence the work.
Yes, for the parts of the Essential 8 that sit inside Microsoft 365. It evidences multi-factor authentication, restricted administrative privileges, and the audit logging that supports both. It does not cover application control, operating system patching or backup restoration testing, which live outside the tenant.
No, and you do not need to sort out licensing before the audit either. Some controls do require a particular subscription tier, and the report states clearly where a gap cannot be closed without a licence change and what the alternative is. Identifying those constraints is part of what the audit is for.




