Is your Microsoft 365 tenant actually secure?
Find out before an attacker does.
A structured, fixed-price security audit of your Entra ID, devices, backups and access controls — delivered as a plain-English report with a prioritised hardening plan. Most audits we run find at least three critical gaps.
Default Microsoft 365 is not secure Microsoft 365
A Microsoft 365 subscription is secure the day you buy it — configured to let everyone work, from anywhere, on anything. Everything convenient about that is an attack path.
Your tenant is the front door to your business
Email. Files. Client data. Invoices. For most businesses, compromising one Microsoft 365 account means compromising the business. And account takeover attacks against M365 tenants have become industrialised — credential stuffing, phishing kits and MFA-fatigue attacks run continuously against every domain on the internet.
The defences that stop these attacks — phishing-resistant MFA, Conditional Access, device compliance — all exist inside the licences you already own. But they have to be deliberately configured, tested and maintained. Almost no tenant we encounter has them fully in place.
That's what this audit exists to answer: measured against real attack techniques, where does your tenant stand today, and what closes the biggest gaps first.
Assume compromise
The auditor's mindset: if an attacker had one stolen password right now, how far would they get? Everything we test flows from that question.
Beyond the checkbox
"We have MFA" often means an SMS code that phishing kits relay in real time. We test whether your controls resist actual attack techniques, not whether boxes are ticked.
Plain English
The report is written for directors, not sysadmins. Clear findings, clear risk, clear priorities — and what each fix involves.
Eight security domains, one thorough audit
Every area of the tenant assessed against the attack techniques actually used against small businesses — not a generic checklist.
Identity & sign-in (Entra ID)
Who can sign in, from where, with what protection. We review MFA coverage and strength, admin accounts, guest access, dormant users, and whether legacy authentication protocols — the route behind most M365 breaches — are blocked.
Conditional Access policies
The rules engine that decides who reaches your data. We map existing policies, expose unintended gaps where none apply, and identify the protections worth enforcing — trusted locations, compliant devices, sign-in risk thresholds.
Device compliance & management (Intune)
Whether machines accessing your data are known, healthy and patched — including encryption status, OS support lifecycles, and whether an unmanaged laptop can walk away with your client files.
Email security & impersonation defence
SPF, DKIM and DMARC configured to stop your domain being spoofed in phishing campaigns, mailbox forwarding and hidden inbox rules checked for signs of silent compromise, and anti-phishing protections tuned.
Admin privileges & privilege sprawl
How many global admins you really need (usually one), standing permissions that should be just-in-time, and unmanaged consent grants letting third-party apps read your mail.
Data exposure & sharing
SharePoint and OneDrive links exposed publicly without anyone noticing, files shared with departed staff or personal accounts, and external sharing settings that treat every anonymous link as fine.
Backup & recovery
What happens when ransomware encrypts a SharePoint library or a departing employee empties their mailbox. Microsoft's shared-responsibility model puts recovery squarely on you — most tenants have no independent backup to fall back on.
Audit logging & alerting
Whether sign-in anomalies, mass deletions and privilege changes would even be noticed — and how quickly. An intrusion nobody detects is a breach nobody contains.
From booking to hardened tenant
Scope & access
A 30-minute call to understand your business, the data you hold, and your obligations — clients, GDPR, insurance, certifications. Read-only audit access is granted securely, with nothing installed on your machines.
The audit
Working through the eight domains over several days, using Microsoft's own diagnostic tooling plus manual review — cross-checking configurations against real-world attack techniques.
Findings briefing
A one-hour call walking through the report: every finding rated by risk, what an attacker could do with it, and the prioritised fix list. No jargon walls, no scare tactics — just where you stand.
Remediation — your choice
Take the report and fix things in-house, have your existing IT provider implement it, or have us close the critical gaps under a fixed-price package or monthly retainer. The report is yours either way.
Directors who can't afford a breach — or the question
"Are we actually secure?" deserves a better answer than "we have antivirus."
Professional services
Solicitors, accountants, architects and engineering firms holding client-confidential data, where a breach means regulatory exposure and reputational damage — and where professional indemnity insurers increasingly ask the question first.
Regulated & tender-active
Businesses chasing public-sector or major-project work — Sizewell C supply chain included — where Cyber Essentials and client security questionnaires gate the bid. The audit maps directly onto what assessors ask.
Growing SMEs
Five to fifty staff, IT grown organically with no-one owning security. If you don't know your MFA coverage or who holds global admin, that's not negligence — it's exactly what this audit resolves.
Microsoft 365 security audit — FAQs
What is a Microsoft 365 security audit?
A systematic review of your Microsoft 365 tenant's security configuration — identity and sign-in protection, Conditional Access, device management, email authentication, data sharing, backups and logging — benchmarked against real-world attack techniques, and delivered as a prioritised action plan.
We already have MFA. Isn't that enough?
MFA is necessary but not sufficient. Phishing kits relay push approvals and SMS codes in real time, and legacy protocols often bypass MFA entirely. The audit tests whether your MFA is phishing-resistant, whether protocols that sidestep it are blocked, and what else is exposed around it.
How long does the audit take?
Typically five to ten working days from access to findings briefing, depending on tenant size. Your team spends about an hour total — one scoping call and one findings call.
Does the audit change anything on our systems?
No. Audit access is read-only. Remediation only happens afterwards, on your instruction, with changes agreed in advance. Nothing is altered during the audit itself.
Will the audit break anything or disrupt staff?
No — because nothing is changed. Users carry on working throughout; most never know it's running.
Do you work with our existing IT provider or internal IT?
Gladly. The report is designed to be handed to a competent IT team for implementation, or we can remediate ourselves. Many organisations use the audit as an independent second opinion on their current setup.
Do you only cover Suffolk?
The audit itself is fully remote, so we work with businesses across the UK. On-site work — remediation, device work — concentrates around Halesworth, Leiston, Framlingham, Woodbridge, Ipswich and wider East Anglia.
Book your Microsoft 365 security audit
Tell us about your organisation and we'll come back within one working day with a fixed price and a start date.