A read-only audit of your Microsoft 365 tenant: what is exposed, what you can prove, and exactly what to fix first.
We examine identity and MFA posture, Entra ID configuration, conditional access, Exchange Online protection, external sharing, DLP, audit logging, and Secure Score across roughly 140 checks. You receive a scored findings report, a prioritized remediation roadmap, and a Secure Score uplift plan. The assessment is remote-first, read-only, and users notice nothing.
- 140+Tenant checks
- 5-10 daysScoping to walkthrough
- Read-onlyAssessment access
- Remote-firstAcross India
Nine areas of the tenant, in the order attackers care about them.
Identity and MFA posture
Every account, every authentication method. Which accounts have MFA enforced rather than merely enabled, which use phishing-resistant methods, which legacy authentication protocols are still open, and which stale accounts have not signed in for 90 days but still hold a live credential. Most tenant compromises in India start with a password, not an exploit, so this section runs first.
Entra ID tenant configuration
Security defaults, password protection and banned-password lists, self-service password reset, user consent settings for third-party applications, and the app registrations and enterprise apps that hold standing permissions in your tenant. Consented apps are an access path that survives password resets, and most organizations have never reviewed the list.
Conditional access, read as a set
Policies look reassuring in a list. The risk lives in what they do not cover: excluded accounts that were meant to be temporary, service accounts outside every policy, untested break-glass accounts, and condition combinations that leave one path open. We read the policy set the way an attacker encounters it, as a whole, and report the gaps between the policies.
Privileged roles and admin access
How many Global Administrators exist, whether privileged access is permanent or activated on demand, whether it is reviewed, and who granted it. Admin counts are consistently higher than anyone expects, usually because a consultant or vendor was given the role during a project and nobody removed it afterwards. We inventory every privileged role, not just the global one.
Exchange Online protection
Anti-phishing, anti-spoofing, and anti-malware policies, SPF, DKIM, and DMARC posture on every sending domain, transport rules, connectors, and the external forwarding and mailbox rules that quietly move messages out of sight. Invoice fraud in India runs almost entirely on forwarding rules created after a mailbox was accessed. We look for the ones that exist now.
Sharing and guest access
SharePoint and OneDrive sharing settings, anonymous links that never expire, sites shared externally years ago, Teams external access, and the guest accounts that accumulate in every long-lived tenant. Each guest is a credential outside your control with a path into your data. We inventory them, establish which are live, and recommend a review cadence.
DLP and sensitivity labels
Whether data loss prevention policies exist, whether they are in test mode or actually enforcing, whether sensitivity labels are published and used, and whether the data your DPDP obligations care about, personal data of Indian data principals, is identifiable and protected or scattered and unlabelled. Most tenants we audit have licensing for controls that were never switched on.
Audit logging and retention
How far back your audit log actually reaches, which is the one setting almost nobody has checked. The Microsoft default is 180 days on Audit Standard, and one year only for E5-licensed users on four workloads. CERT-In directions separately expect 180 days of system logs. We check what your policies actually retain and run a real historical search to prove the capability works.
Secure Score and licence-to-feature gaps
Your current Secure Score, which recommendations genuinely apply to your organization, and the controls you are already paying for but not using. The licence-to-feature gap is the most common finding overall: Business Premium and E3 tenants routinely run with Defender, Intune, and Purview capabilities included in the subscription and sitting idle.
You may have 180 days of evidence and believe you have a year.
The single most valuable finding a tenant audit produces is the honest answer to one question: how far back can you actually see? The figures below are Microsoft published defaults, not our estimates, and they catch organizations at the worst possible moment, mid-incident.
- Audit (Standard) retains records for 180 days by default. Audit (Premium) retains Exchange Online, SharePoint, OneDrive, and Microsoft Entra records for one year, but only for users assigned an E5 licence or an equivalent add-on. All other activities default to 180 days.
- Mixed licensing means mixed retention, per user. If some staff are on Business Premium or E3 and some on E5, your evidence trail is uneven in ways nobody has mapped.
- Custom audit retention policies override the default in both directions. A custom policy shorter than the default silently reduces what you retain. We check what policies exist, not what the licence brochure promises.
- CERT-In directions require covered entities to maintain ICT system logs for a rolling 180 days and to report qualifying incidents on a very short clock. If your tenant retention, your log export, and your incident process have never been checked against that expectation, the audit checks all three.
Four things that separate an audit from a settings export.
Your context, not a generic baseline
A generic benchmark produces a wall of findings, most of which do not apply to you, and the important five get lost. We spend the first call understanding how your organization works, then score findings against that reality. A shorter report that gets acted on beats a comprehensive one that gets filed.
Read-only, zero disruption
The assessment runs on read-only reporting roles you grant and can revoke at any time. No configuration changes during the audit, no agent installs, no user interruptions. If we find an indicator of active compromise, we tell you within hours rather than saving it for the report.
No reflexive licence upselling
It is easy to answer every finding with an E5 recommendation. Often the same risk closes with configuration you already own, and the licence-to-feature gap list usually shows you are underusing what you already pay for. We separate findings that cost money from findings that cost attention, clearly.
We can also do the fixing
The roadmap is written so your own team can execute it, and many clients do exactly that. If you would rather hand it over, we run the remediation as a scoped follow-on engagement and re-measure the tenant afterwards so the improvement is documented rather than assumed. Either path is fine with us.
Three deliverables, written so your team can act on them.
Scored findings report
Every finding from the 140+ checks, scored by severity and grouped by the nine assessment areas. Two tiers in one document: a short executive summary for leadership and the full technical detail for whoever does the work.
- Severity rating per finding, critical to informational
- Evidence for each finding, setting and value as observed
- Why it matters in your context, not a generic baseline lecture
- Executive summary readable by a non-technical founder or CFO
- Mapping to DPDP, CERT-In, ISO 27001, and SOC 2 where relevant
Prioritized remediation roadmap
The findings ordered into a sequence your team can actually run: quick wins first, then structural changes, with configuration-only fixes separated from anything that would need a licence change.
- First-week actions: the fixes that close the most risk fastest
- 30, 60, and 90 day phases with effort estimates per item
- Configuration fixes separated from licence-dependent fixes
- User-impact notes so you can plan communication and timing
- Owner suggestions per item, your team, us, or either
Secure Score uplift plan
Your current score, the realistic target for your licensing tier, and the specific recommendations worth taking. Secure Score is not the goal, but it is a useful shared metric for tracking whether the tenant is actually improving.
- Current score with per-category breakdown
- Recommendations filtered to the ones that apply to you
- Expected score movement per remediation phase
- Licence-to-feature gap list: paid-for controls sitting idle
- A re-measurement point after remediation to document the uplift
Six situations that bring Indian organizations to a tenant audit.
Startups before funding or enterprise deals
Due diligence questionnaires and enterprise procurement now ask direct questions about MFA, access control, logging, and data handling. An audit produces honest answers, and more usefully, tells you which answers to fix before you send them. SOC 2 readiness work usually starts exactly here, because the tenant is where most controls live.
BFSI and regulated financial firms
RBI and SEBI supervisory expectations cover access control, logging, and the ability to investigate, and for most firms Microsoft 365 is where that evidence lives. The audit retention question matters most here, because the period a regulator or auditor asks about can be longer than what your tenant retains by default.
Healthcare and clinics
Patient records, referral mail, and diagnostic reports flow through Exchange and SharePoint in most Indian healthcare organizations. The audit focuses on where that data actually sits, who can reach it, what has been shared externally, and whether access could be evidenced if a patient or regulator asked.
After an incident or a near miss
A payment nearly went to the wrong account, a mailbox behaved oddly, or a message arrived that looked like it came from a colleague. The immediate question is what actually happened, and the answer depends entirely on what your audit log retained. This is where organizations discover their retention position, and it is too late to change it then.
DPDP Act readiness
The DPDP Act 2023 expects reasonable security safeguards and breach notification, and for most organizations the majority of personal data lives in Microsoft 365. The audit maps where personal data sits in the tenant, who can access it, what protection is enforced, and what you could demonstrate if the Data Protection Board asked.
Businesses that changed IT provider
A new provider inherits a tenant configured by somebody else: admin accounts, consented applications, and conditional access exclusions whose reasons nobody remembers. An independent audit at handover establishes a baseline and frequently removes access that should have ended when the previous relationship did.
What we find when we audit a Microsoft 365 tenant in India.
| Feature | Audited and maintained Reviewed on a cadence | Set up once, then drifted The most common state | Defaults, largely untouched Smaller tenants |
|---|---|---|---|
Global administrator count controlled | Few, reviewed | Grown quietly | Whoever asked |
MFA enforced on all privileged accounts | Mostly | Partially | |
Conditional access exclusions justified | Forgotten | None exist | |
Audit retention known and deliberate | |||
External forwarding controlled | Sometimes | ||
Guest accounts reviewed on a cadence | |||
DLP enforcing rather than in test mode | |||
Licensed security features actually in use | Most | Some | Few |
Could answer a DPDP or CERT-In evidence request | Yes | Only within 180 days | Unlikely |
Could reconstruct an incident from last year | Probably | Partially | No |
Six steps, typically 5-10 days end to end.
- 1
Scoping call
Day 1
A 30-45 minute video call. What is in scope, which compliance drivers apply (DPDP, CERT-In, ISO 27001, SOC 2, RBI or SEBI expectations), how the business works, who travels, who uses personal devices, and which third parties have access. Findings are worthless without this context.
- 2
Read-only access granted
Day 1-2
You grant scoped, read-only reporting roles, typically Global Reader and Security Reader, to a named account you create and control. No passwords are shared, access is logged in your own audit trail, and you revoke it the moment the assessment ends. We never ask for Global Administrator.
- 3
Assessment
Day 2-6
The 140+ checks across all nine areas: identity, Entra ID configuration, conditional access, privileged roles, Exchange Online protection, sharing and guests, DLP and labels, audit logging, and Secure Score. Anything that looks like an active compromise is escalated to you the same day, not saved for the report.
- 4
Report and roadmap written
Day 6-8
Findings scored, evidence attached, and the remediation roadmap sequenced into first-week, 30, 60, and 90 day phases. Configuration-only fixes are separated from licence-dependent ones, and each item carries an effort estimate and a user-impact note. Internal QA before anything reaches you.
- 5
Findings walkthrough
Day 8-10
A live walkthrough of every significant finding. On-site workshop for Hyderabad organizations; a video call walkthrough for Mumbai, Bengaluru, Delhi NCR, Chennai, Pune, and everywhere else in India. You leave knowing exactly what to fix first and why, with the floor open for hard questions.
- 6
Optional remediation
Scoped separately
Your team runs the roadmap, or we do, or we split it. If we remediate, changes are planned with you, communicated to users where they will notice (MFA rollout, legacy auth cutoff), and the tenant is re-measured afterwards so the Secure Score uplift and closed findings are documented in writing.
What organizations ask before booking a Microsoft 365 audit.
Twelve things to check in your own tenant this week.
Identity, where it starts
- How many accounts hold Global Administrator?The number is nearly always higher than the answer people give.
- Is MFA enforced on every one of them?Enforced, not enabled, not encouraged.
- Are any accounts excluded from conditional access?Check why, and whether the reason still exists.
- How many accounts have not signed in for 90 days?Each one is a live credential nobody is watching.
What leaves the tenant
- Is external mail forwarding blocked or monitored?The classic mechanism behind invoice fraud.
- Can users create anonymous sharing links that never expire?Check the setting, then check what already exists.
- How many guest accounts exist, and who owns each?They accumulate, and nobody removes them unprompted.
- Which third-party apps have consent in your tenant?Consented apps survive every password reset.
Could you evidence it
- How far back does your audit log actually reach?Check the retention policies, not the licence brochure.
- Could you produce 180 days of logs if CERT-In asked?The direction expects logs maintained and producible.
- Has anybody ever run a real audit log search?The first time should not be during an incident.
- Are DLP policies enforcing, or still in test mode?Test mode reports; it does not protect.
The pages around this one.
Cybersecurity Audit & Compliance
The wider audit practice: penetration testing, ISO 27001 and SOC 2 readiness, CERT-In alignment, and policy development. A tenant audit often becomes the first module of a broader programme.
Learn moreMicrosoft 365 Reporting & Auditing
Ongoing reporting and audit tooling for the tenant after the point-in-time audit: usage, licensing, activity, and security reports on a continuous cadence.
Learn moreManaged IT Services India
Full operational ownership of your IT estate, including the continuous tenant hygiene that keeps the next audit boring: access reviews, patching, monitoring, and a 30-minute response SLA.
Learn moreFind out what your tenant would tell an attacker, before one asks it.
A three-minute form, an initial reply within 4 business hours, and a 30-45 minute scoping call. Remote-first across India from our Hyderabad HQ, read-only access you control, and a findings walkthrough your leadership can actually use. No obligation and no retainer.
Related Services
Explore more solutions that work great with this service