Independent Microsoft 365 security assessment.Atlant Security
365/AuditBY ATLANT SECURITY
Build your scope Audit brief builder

LICENSING & SCOPE

Business Premium, E3 or E5: make the audit licence-aware

Avoid recommendations that assume unavailable features; map entitlements to the controls and evidence you need.

Discuss your requirements
Layered glass partitions in an illustrative corporate atrium

For the engagement owner. The useful question is what the relevant users and workloads are entitled to use, and what is operating today.

Do not scope from a shorthand plan name

“We have E3” can refer to different products and combinations. Mixed licences, add-ons and user assignments further change the environment. Record the actual subscriptions and the populations to which they apply. Treat an uncertain answer as a discovery task, not a weakness. The homepage planner deliberately includes “Not sure” so that teams can prepare a useful enquiry without first becoming licensing specialists.

Establish the facts. Subscription: Exact products and add-ons.; Assignment: Relevant user and workload populations.; Operation: Configured controls and accountable owners.
Working model 01Establish the factsIllustrative planning diagram. Adapt the decisions to your authorised scope.
Read diagram text
Subscription
Exact products and add-ons.
Assignment
Relevant user and workload populations.
Operation
Configured controls and accountable owners.

Separate entitlement from implementation

A feature may be available but unconfigured, configured but poorly assigned, or implemented effectively through a different product. Each situation requires a different recommendation. Ask what control objective the organisation needs to meet, which capability supports it and how the team operates that capability. This avoids a report that merely recommends buying more products or enabling every setting without considering business dependencies.

Architectural boundaries illustrated by smoked glass and stone
Operational perspectiveMake access boundaries explicit.Generated illustrative setting; not a client location.

Check identity and device dependencies

Conditional Access and risk-based controls have different licensing dependencies. Device compliance additionally depends on the organisation’s management approach, enrolment coverage and the way access decisions use the resulting signals. A tenant-wide statement should not be inferred from a small enrolled subset. Review populations separately: corporate devices, personally owned devices, unmanaged access and exceptions. Any rollout recommendation needs a practical support and recovery plan.

Choose the recommendation. Existing feature: Correct implementation where feasible.; Process: Explain limitations of an alternative.; Enhancement: Separate optional purchase decisions.
Working model 02Choose the recommendationIllustrative planning diagram. Adapt the decisions to your authorised scope.
Read diagram text
Existing feature
Correct implementation where feasible.
Process
Explain limitations of an alternative.
Enhancement
Separate optional purchase decisions.

Verify the evidence window

Audit availability and retention depend on the relevant service, record, user licensing and policy configuration. Confirm which historical questions the available evidence can answer. If the customer asks for a six-month operating review but only a shorter relevant history is available, the report must state the limitation. A new retention setting does not recreate records that were never retained. Avoid promising a forensic history solely from a subscription label.

Check historical evidence. Record: Identify the required activity type.; Retention: Verify applicable policy and entitlement.; Gap: State what cannot be reconstructed.
Working model 03Check historical evidenceIllustrative planning diagram. Adapt the decisions to your authorised scope.
Read diagram text
Record
Identify the required activity type.
Retention
Verify applicable policy and entitlement.
Gap
State what cannot be reconstructed.

Offer practical alternatives

For each finding, distinguish a feasible correction with existing entitlements, an operational workaround with explicit limitations and an optional product enhancement. Record dependencies and ongoing ownership for all three. This lets management evaluate cost and risk without confusing a commercial upgrade with completed remediation. If a control cannot meet the agreed objective without a new capability, make that constraint explicit and explain the remaining exposure.

Plan the operational handover

If a new product is needed, agree acceptance criteria before purchase or rollout. Specify the intended population, the evidence of successful implementation and the team that will maintain the control after the project closes.

Related Atlant Security guidance: verifying remediation with evidence and agreeing operational acceptance. Use these to connect the review with the evidence and responsibilities needed after it.

Bring the right facts to scoping

Our Business Premium review, Intune audit and audit logging review explain the relevant evidence boundaries. Use approximate licence families and workloads in the first enquiry. Licence inventories and administrator exports belong in the agreed secure channel. Product documentation and contractual terms should be rechecked for the actual engagement; this guide is not a licensing quote.

Build a workable plan. Scope: Agree the control objective.; Sequence: Confirm dependencies before changes.; Validate: Examine the resulting evidence.
Working model 04Build a workable planIllustrative planning diagram. Adapt the decisions to your authorised scope.
Read diagram text
Scope
Agree the control objective.
Sequence
Confirm dependencies before changes.
Validate
Examine the resulting evidence.

Sources & further reading

Reviewed 6 October 2026. Product names, licence entitlements and guidance can change. Confirm applicability to your tenant and agreed assessment date.

This guide and the related sector publications linked above are published by Atlant Security. Technical examples are planning examples, not claims about completed client assessments.

Published by Atlant Security. Sources, editorial policy and corrections.

PUT THE GUIDANCE TO WORK

Choose your next step.

LET’S START A CONVERSATION

Define the scope.
Take the next step.

Your audit objectives, control boundaries and evidence period. A useful starting point for your assessment.

Discuss your requirements