Skip to main content
Microsoft 365 Security Audit, India

A read-only audit of your Microsoft 365 tenant: what is exposed, what you can prove, and exactly what to fix first.

We examine identity and MFA posture, Entra ID configuration, conditional access, Exchange Online protection, external sharing, DLP, audit logging, and Secure Score across roughly 140 checks. You receive a scored findings report, a prioritized remediation roadmap, and a Secure Score uplift plan. The assessment is remote-first, read-only, and users notice nothing.

  • 140+Tenant checks
  • 5-10 daysScoping to walkthrough
  • Read-onlyAssessment access
  • Remote-firstAcross India
What we examine

Nine areas of the tenant, in the order attackers care about them.

A Microsoft 365 security audit is not a Secure Score screenshot. Secure Score is a useful index, not evidence. What matters is whether the controls are configured correctly for how your organization actually works, and whether you could reconstruct what happened if someone asked. Every check below produces a written, severity-scored finding.

Identity and MFA posture

Every account, every authentication method. Which accounts have MFA enforced rather than merely enabled, which use phishing-resistant methods, which legacy authentication protocols are still open, and which stale accounts have not signed in for 90 days but still hold a live credential. Most tenant compromises in India start with a password, not an exploit, so this section runs first.

Entra ID tenant configuration

Security defaults, password protection and banned-password lists, self-service password reset, user consent settings for third-party applications, and the app registrations and enterprise apps that hold standing permissions in your tenant. Consented apps are an access path that survives password resets, and most organizations have never reviewed the list.

Conditional access, read as a set

Policies look reassuring in a list. The risk lives in what they do not cover: excluded accounts that were meant to be temporary, service accounts outside every policy, untested break-glass accounts, and condition combinations that leave one path open. We read the policy set the way an attacker encounters it, as a whole, and report the gaps between the policies.

Privileged roles and admin access

How many Global Administrators exist, whether privileged access is permanent or activated on demand, whether it is reviewed, and who granted it. Admin counts are consistently higher than anyone expects, usually because a consultant or vendor was given the role during a project and nobody removed it afterwards. We inventory every privileged role, not just the global one.

Exchange Online protection

Anti-phishing, anti-spoofing, and anti-malware policies, SPF, DKIM, and DMARC posture on every sending domain, transport rules, connectors, and the external forwarding and mailbox rules that quietly move messages out of sight. Invoice fraud in India runs almost entirely on forwarding rules created after a mailbox was accessed. We look for the ones that exist now.

Sharing and guest access

SharePoint and OneDrive sharing settings, anonymous links that never expire, sites shared externally years ago, Teams external access, and the guest accounts that accumulate in every long-lived tenant. Each guest is a credential outside your control with a path into your data. We inventory them, establish which are live, and recommend a review cadence.

DLP and sensitivity labels

Whether data loss prevention policies exist, whether they are in test mode or actually enforcing, whether sensitivity labels are published and used, and whether the data your DPDP obligations care about, personal data of Indian data principals, is identifiable and protected or scattered and unlabelled. Most tenants we audit have licensing for controls that were never switched on.

Audit logging and retention

How far back your audit log actually reaches, which is the one setting almost nobody has checked. The Microsoft default is 180 days on Audit Standard, and one year only for E5-licensed users on four workloads. CERT-In directions separately expect 180 days of system logs. We check what your policies actually retain and run a real historical search to prove the capability works.

Secure Score and licence-to-feature gaps

Your current Secure Score, which recommendations genuinely apply to your organization, and the controls you are already paying for but not using. The licence-to-feature gap is the most common finding overall: Business Premium and E3 tenants routinely run with Defender, Intune, and Purview capabilities included in the subscription and sitting idle.

Check this before you need it

You may have 180 days of evidence and believe you have a year.

The single most valuable finding a tenant audit produces is the honest answer to one question: how far back can you actually see? The figures below are Microsoft published defaults, not our estimates, and they catch organizations at the worst possible moment, mid-incident.

  • Audit (Standard) retains records for 180 days by default. Audit (Premium) retains Exchange Online, SharePoint, OneDrive, and Microsoft Entra records for one year, but only for users assigned an E5 licence or an equivalent add-on. All other activities default to 180 days.
  • Mixed licensing means mixed retention, per user. If some staff are on Business Premium or E3 and some on E5, your evidence trail is uneven in ways nobody has mapped.
  • Custom audit retention policies override the default in both directions. A custom policy shorter than the default silently reduces what you retain. We check what policies exist, not what the licence brochure promises.
  • CERT-In directions require covered entities to maintain ICT system logs for a rolling 180 days and to report qualifying incidents on a very short clock. If your tenant retention, your log export, and your incident process have never been checked against that expectation, the audit checks all three.
Ask how far back your tenant can actually see
How we audit

Four things that separate an audit from a settings export.

Anybody can run a script and hand you two hundred findings. The value is in knowing which settings matter for your organization, which findings are noise, and what your team can realistically fix in the next 90 days.

Your context, not a generic baseline

A generic benchmark produces a wall of findings, most of which do not apply to you, and the important five get lost. We spend the first call understanding how your organization works, then score findings against that reality. A shorter report that gets acted on beats a comprehensive one that gets filed.

Read-only, zero disruption

The assessment runs on read-only reporting roles you grant and can revoke at any time. No configuration changes during the audit, no agent installs, no user interruptions. If we find an indicator of active compromise, we tell you within hours rather than saving it for the report.

No reflexive licence upselling

It is easy to answer every finding with an E5 recommendation. Often the same risk closes with configuration you already own, and the licence-to-feature gap list usually shows you are underusing what you already pay for. We separate findings that cost money from findings that cost attention, clearly.

We can also do the fixing

The roadmap is written so your own team can execute it, and many clients do exactly that. If you would rather hand it over, we run the remediation as a scoped follow-on engagement and re-measure the tenant afterwards so the improvement is documented rather than assumed. Either path is fine with us.

What you receive

Three deliverables, written so your team can act on them.

The engagement ends with documents your administrators can execute and your leadership can read, not a configuration dump that requires us to interpret it. Every finding states what it is, why it matters in your context, what to change, and roughly what the change takes.

Scored findings report

Every finding from the 140+ checks, scored by severity and grouped by the nine assessment areas. Two tiers in one document: a short executive summary for leadership and the full technical detail for whoever does the work.

  • Severity rating per finding, critical to informational
  • Evidence for each finding, setting and value as observed
  • Why it matters in your context, not a generic baseline lecture
  • Executive summary readable by a non-technical founder or CFO
  • Mapping to DPDP, CERT-In, ISO 27001, and SOC 2 where relevant

Prioritized remediation roadmap

The findings ordered into a sequence your team can actually run: quick wins first, then structural changes, with configuration-only fixes separated from anything that would need a licence change.

  • First-week actions: the fixes that close the most risk fastest
  • 30, 60, and 90 day phases with effort estimates per item
  • Configuration fixes separated from licence-dependent fixes
  • User-impact notes so you can plan communication and timing
  • Owner suggestions per item, your team, us, or either

Secure Score uplift plan

Your current score, the realistic target for your licensing tier, and the specific recommendations worth taking. Secure Score is not the goal, but it is a useful shared metric for tracking whether the tenant is actually improving.

  • Current score with per-category breakdown
  • Recommendations filtered to the ones that apply to you
  • Expected score movement per remediation phase
  • Licence-to-feature gap list: paid-for controls sitting idle
  • A re-measurement point after remediation to document the uplift
Who needs this

Six situations that bring Indian organizations to a tenant audit.

The trigger shapes the scope. An audit prompted by an investor questionnaire looks different from one prompted by a suspected mailbox compromise, and we scope accordingly rather than running the same engagement every time.

Startups before funding or enterprise deals

Due diligence questionnaires and enterprise procurement now ask direct questions about MFA, access control, logging, and data handling. An audit produces honest answers, and more usefully, tells you which answers to fix before you send them. SOC 2 readiness work usually starts exactly here, because the tenant is where most controls live.

BFSI and regulated financial firms

RBI and SEBI supervisory expectations cover access control, logging, and the ability to investigate, and for most firms Microsoft 365 is where that evidence lives. The audit retention question matters most here, because the period a regulator or auditor asks about can be longer than what your tenant retains by default.

Healthcare and clinics

Patient records, referral mail, and diagnostic reports flow through Exchange and SharePoint in most Indian healthcare organizations. The audit focuses on where that data actually sits, who can reach it, what has been shared externally, and whether access could be evidenced if a patient or regulator asked.

After an incident or a near miss

A payment nearly went to the wrong account, a mailbox behaved oddly, or a message arrived that looked like it came from a colleague. The immediate question is what actually happened, and the answer depends entirely on what your audit log retained. This is where organizations discover their retention position, and it is too late to change it then.

DPDP Act readiness

The DPDP Act 2023 expects reasonable security safeguards and breach notification, and for most organizations the majority of personal data lives in Microsoft 365. The audit maps where personal data sits in the tenant, who can access it, what protection is enforced, and what you could demonstrate if the Data Protection Board asked.

Businesses that changed IT provider

A new provider inherits a tenant configured by somebody else: admin accounts, consented applications, and conditional access exclusions whose reasons nobody remembers. An independent audit at handover establishes a baseline and frequently removes access that should have ended when the previous relationship did.

Three tenant positions

What we find when we audit a Microsoft 365 tenant in India.

The middle column is the most common by a wide margin. The tenant was set up competently at some point, then years of staff changes, projects, and consultants happened, and nobody looked at the whole thing again.
Feature
Audited and maintained
Reviewed on a cadence
Set up once, then drifted
The most common state
Defaults, largely untouched
Smaller tenants
Global administrator count controlled
Few, reviewedGrown quietlyWhoever asked
MFA enforced on all privileged accounts
MostlyPartially
Conditional access exclusions justified
ForgottenNone exist
Audit retention known and deliberate
External forwarding controlled
Sometimes
Guest accounts reviewed on a cadence
DLP enforcing rather than in test mode
Licensed security features actually in use
MostSomeFew
Could answer a DPDP or CERT-In evidence request
YesOnly within 180 daysUnlikely
Could reconstruct an incident from last year
ProbablyPartiallyNo
How the audit runs

Six steps, typically 5-10 days end to end.

Remote-first from our Hyderabad HQ, delivered across India. The work is read-only and does not disrupt users. What we need is properly scoped access and a short conversation about how your organization actually operates, because that determines which findings matter.
  1. 1

    Scoping call

    Day 1

    A 30-45 minute video call. What is in scope, which compliance drivers apply (DPDP, CERT-In, ISO 27001, SOC 2, RBI or SEBI expectations), how the business works, who travels, who uses personal devices, and which third parties have access. Findings are worthless without this context.

  2. 2

    Read-only access granted

    Day 1-2

    You grant scoped, read-only reporting roles, typically Global Reader and Security Reader, to a named account you create and control. No passwords are shared, access is logged in your own audit trail, and you revoke it the moment the assessment ends. We never ask for Global Administrator.

  3. 3

    Assessment

    Day 2-6

    The 140+ checks across all nine areas: identity, Entra ID configuration, conditional access, privileged roles, Exchange Online protection, sharing and guests, DLP and labels, audit logging, and Secure Score. Anything that looks like an active compromise is escalated to you the same day, not saved for the report.

  4. 4

    Report and roadmap written

    Day 6-8

    Findings scored, evidence attached, and the remediation roadmap sequenced into first-week, 30, 60, and 90 day phases. Configuration-only fixes are separated from licence-dependent ones, and each item carries an effort estimate and a user-impact note. Internal QA before anything reaches you.

  5. 5

    Findings walkthrough

    Day 8-10

    A live walkthrough of every significant finding. On-site workshop for Hyderabad organizations; a video call walkthrough for Mumbai, Bengaluru, Delhi NCR, Chennai, Pune, and everywhere else in India. You leave knowing exactly what to fix first and why, with the floor open for hard questions.

  6. 6

    Optional remediation

    Scoped separately

    Your team runs the roadmap, or we do, or we split it. If we remediate, changes are planned with you, communicated to users where they will notice (MFA rollout, legacy auth cutoff), and the tenant is re-measured afterwards so the Secure Score uplift and closed findings are documented in writing.

Straight answers

What organizations ask before booking a Microsoft 365 audit.

Tenant self-check

Twelve things to check in your own tenant this week.

You can work through most of these yourself, and we would rather you did than left them unexamined. The first group is identity, the second is what leaves the tenant, the third is whether you could evidence any of it afterwards.

Identity, where it starts

  • How many accounts hold Global Administrator?
    The number is nearly always higher than the answer people give.
  • Is MFA enforced on every one of them?
    Enforced, not enabled, not encouraged.
  • Are any accounts excluded from conditional access?
    Check why, and whether the reason still exists.
  • How many accounts have not signed in for 90 days?
    Each one is a live credential nobody is watching.

What leaves the tenant

  • Is external mail forwarding blocked or monitored?
    The classic mechanism behind invoice fraud.
  • Can users create anonymous sharing links that never expire?
    Check the setting, then check what already exists.
  • How many guest accounts exist, and who owns each?
    They accumulate, and nobody removes them unprompted.
  • Which third-party apps have consent in your tenant?
    Consented apps survive every password reset.

Could you evidence it

  • How far back does your audit log actually reach?
    Check the retention policies, not the licence brochure.
  • Could you produce 180 days of logs if CERT-In asked?
    The direction expects logs maintained and producible.
  • Has anybody ever run a real audit log search?
    The first time should not be during an incident.
  • Are DLP policies enforcing, or still in test mode?
    Test mode reports; it does not protect.
Next step

Find out what your tenant would tell an attacker, before one asks it.

A three-minute form, an initial reply within 4 business hours, and a 30-45 minute scoping call. Remote-first across India from our Hyderabad HQ, read-only access you control, and a findings walkthrough your leadership can actually use. No obligation and no retainer.