You retain control of the tenant
A supervised review is a practical starting point: your authorised administrator navigates the agreed settings and prepares approved evidence. If direct access or automated collection is appropriate, agree the individual permissions, workload coverage, duration and revocation process in advance. Do not assume that a single reader role exposes all required data.
Minimise the information collected
- Use configuration metadata and sampled records wherever possible
- Redact account and user identifiers where identity is not material to the finding
- Do not place passwords, tokens, private keys, mailbox contents or confidential exports in the website form
- Agree a secure evidence exchange channel, access controls and retention before collection
NDA and RFP handling
Upload a PDF or DOCX up to 2 MiB through the protected contact form or planner. Send larger documents to sales@ms365securityaudit.com and arrange the appropriate channel. A person reviews documents and signatures. Attachments are not sent to the optional AI scoping model.
Close access as deliberately as you open it
Record accounts or app permissions granted for the engagement, owner approval and expiry. Agree revocation, evidence return or deletion, and any records that must be retained. The website privacy notice covers enquiries; engagement-specific evidence handling belongs in the agreed contract.
Prepare your audit request
Use the Microsoft 365 Audit Planner for a licence-aware starting scope, or the detailed scoping assistant. Review the brief and send it with your enquiry. You can attach your NDA or RFP in the contact form.

