What does a Microsoft 365 security review cover?
A Microsoft 365 security review is a read of the tenant's configuration by someone who knows which settings attackers use. It covers six areas: identity and sign-in in Entra ID, administrative roles, Exchange Online, SharePoint and OneDrive sharing, Defender for Office 365 and endpoint protection, and the audit trail. Each area is checked against what the organisation's licence already provides, because the controls that close most findings are paid for and switched off.
Secure Score is a starting input. It counts settings and awards points, and it cannot tell whether an exclusion in a conditional access policy is deliberate, whether an inbox rule is forwarding a director's mail, or whether the person holding Global Administrator left the business in March. The review answers those questions with the configuration open and the people who run it in the room.
Access is read-only. Global Reader in Entra ID covers most of the tenant, with Security Reader for Defender and View-Only Audit Logs for the audit search, agreed at scoping and removed when the review ends.
Identity: how do users sign in?
Most Microsoft 365 compromises start with a sign-in, so identity is read first. The review lists every conditional access policy, its assignments and exclusions, and maps which sign-ins reach the tenant without multi-factor authentication. Exclusions are the usual gap: a service account, a shared mailbox someone signs in to directly, or a group created for a migration that still exempts forty users.
Tenants without Entra ID P1 run on security defaults, which enforce multi-factor authentication for everyone but offer no exclusions and no device conditions. Tenants with P1, which comes with Microsoft 365 Business Premium and E3, should be running conditional access with security defaults turned off, and the review checks that the policies cover everything security defaults would have.
Legacy authentication protocols cannot carry a second factor. Microsoft has been retiring basic authentication in Exchange Online since 2022, and the devices and applications that relied on it rarely disappear quietly: a multifunction scanner, a line-of-business application or a website contact form that sends mail through the tenant. The review checks that conditional access blocks legacy authentication, finds every system that sends mail through the tenant, and records how each one authenticates and who owns it.
- Conditional access policies listed with every exclusion explained, and the sign-ins that reach the tenant with a password alone.
- Phishing-resistant methods for administrators: passkeys, FIDO2 security keys or Windows Hello for Business.
- Legacy authentication blocked in conditional access, and every scanner, application and form that sends mail through the tenant traced to its owner.
- Self-service password reset methods, since a reset path weaker than sign-in becomes the way in.
- User consent to third-party applications, and the applications that already hold delegated mail and file access.
Which administrative roles get checked?
Every privileged role assignment is listed with the person behind it and the date it was last used. Microsoft recommends fewer than five Global Administrators, and small tenants commonly carry more, with an MSP account, a former IT manager and the original reseller among them. Exchange Administrator, SharePoint Administrator, Privileged Role Administrator and Application Administrator get the same treatment, since each can reach a large share of the tenant's data.
The review checks that administrative work runs from dedicated accounts without mailboxes, that two emergency access accounts exist and are monitored, and, where Entra ID P2 is licensed, that Privileged Identity Management makes the high-impact roles eligible and time-bound. Partner relationships are read too: a delegated admin relationship granted to a reseller years ago can still hold Global Administrator over the tenant.
What does the review check in Exchange Online?
Mail is where business email compromise turns into money. The review reads the outbound spam policy for automatic external forwarding, which Microsoft sets to off by default and which is often switched on to suit one user. It searches mailbox rules across the tenant for rules that forward, redirect or delete messages, the persistence step in most BEC cases. It reads transport rules for anything that bypasses filtering, and lists mailboxes with full access or send-as permissions granted to accounts that no longer need them.
Domain authentication is checked from outside: SPF, DKIM signing for every sending domain, and a DMARC record at p=quarantine or p=reject with reports going somewhere a person reads. A DMARC record at p=none leaves anyone free to send mail as the organisation's domain to its own customers and suppliers.
How are SharePoint and OneDrive sharing settings judged?
Sharing settings decide how far a document travels once someone clicks share. The review reads the tenant-wide external sharing level, the default link type, link expiry for anyone links, and per-site overrides that loosen the tenant setting. An organisation-wide default of anyone links means a forwarded email carries the document to whoever receives it.
Guest accounts are counted, aged and traced to the sites and teams they can reach. Permissions matter twice where Microsoft 365 Copilot is in use or planned, because Copilot answers from whatever the signed-in user can already open. Oversharing that was invisible because nobody browsed for it becomes visible the first time someone asks Copilot about salaries.
What about Defender and device settings?
Business Premium includes Defender for Office 365 Plan 1 and Defender for Business. The review checks that Safe Links and Safe Attachments policies cover every user, that the preset security policies are applied, and that impersonation protection names the executives and finance staff whose names attackers use. On the endpoint side it checks onboarding coverage, tamper protection, attack surface reduction rules in block mode, and whether alerts reach a person who acts on them.
Intune compliance policies are read alongside conditional access. A device compliance requirement only protects the tenant if devices that fail it are blocked, and if unmanaged devices cannot download files to local storage.
Is the audit trail long enough to investigate an incident?
Microsoft Purview Audit (Standard) keeps audit records for 180 days, and Audit (Premium), included with E5, keeps them for one year by default. Entra ID sign-in and audit logs are held for 30 days on P1 or P2 licences and seven days without.
Incidents are often found weeks after they start, so the review checks that the unified audit log is on, that mailbox auditing is enabled, and that sign-in logs are exported to a Log Analytics workspace or a SIEM with retention set to the organisation's investigation and legal needs.
The test is practical: pick a date ninety days ago and confirm the sign-in records for an administrator on that date can be retrieved. Where they cannot, the review sets the export and retention changes needed.
How long does a Microsoft 365 security review take?
The effort follows the size and history of the tenant more than the headcount. A tenant with one domain, a few hundred users and conditional access built recently reads quickly. A tenant that has been through two mergers, three IT providers and a hybrid identity migration carries more exclusions, more stale accounts and more applications with consent nobody remembers granting, and each one has to be traced.
The review needs a few hours of time from the people who administer the tenant: one session at the start to explain what the business runs and why settings are the way they are, and one at the end to walk through the findings. Most of the work in between is reading configuration and logs, and it does not touch users.
What does the review deliver?
Two documents. A findings report with each issue verified and the evidence to reproduce it, and a remediation plan ordered by the exposure each change removes, written so the organisation's IT provider or internal team can carry it out. Most plans open with conditional access exclusions, legacy authentication, external forwarding, standing Global Administrator assignments and log retention, because those close the paths most Microsoft 365 compromises take.
Black Shard runs Microsoft 365 and Azure tenants in production for its own systems and for client organisations. The Microsoft 365 and Azure security review starts at $3,500 ex GST for a fixed scope with written findings and a remediation plan, and the Entra ID security review goes deeper on identity where the tenant needs it. Where the tenant also hosts Azure workloads, the Azure security review covers both. Scope is agreed on a free 30-minute scoping call.