For the engagement owner. The useful question is what the relevant users and workloads are entitled to use, and what is operating today.
Do not scope from a shorthand plan name
“We have E3” can refer to different products and combinations. Mixed licences, add-ons and user assignments further change the environment. Record the actual subscriptions and the populations to which they apply. Treat an uncertain answer as a discovery task, not a weakness. The homepage planner deliberately includes “Not sure” so that teams can prepare a useful enquiry without first becoming licensing specialists.
Read diagram text
- Subscription
- Exact products and add-ons.
- Assignment
- Relevant user and workload populations.
- Operation
- Configured controls and accountable owners.
Separate entitlement from implementation
A feature may be available but unconfigured, configured but poorly assigned, or implemented effectively through a different product. Each situation requires a different recommendation. Ask what control objective the organisation needs to meet, which capability supports it and how the team operates that capability. This avoids a report that merely recommends buying more products or enabling every setting without considering business dependencies.

Check identity and device dependencies
Conditional Access and risk-based controls have different licensing dependencies. Device compliance additionally depends on the organisation’s management approach, enrolment coverage and the way access decisions use the resulting signals. A tenant-wide statement should not be inferred from a small enrolled subset. Review populations separately: corporate devices, personally owned devices, unmanaged access and exceptions. Any rollout recommendation needs a practical support and recovery plan.
Read diagram text
- Existing feature
- Correct implementation where feasible.
- Process
- Explain limitations of an alternative.
- Enhancement
- Separate optional purchase decisions.
Verify the evidence window
Audit availability and retention depend on the relevant service, record, user licensing and policy configuration. Confirm which historical questions the available evidence can answer. If the customer asks for a six-month operating review but only a shorter relevant history is available, the report must state the limitation. A new retention setting does not recreate records that were never retained. Avoid promising a forensic history solely from a subscription label.
Read diagram text
- Record
- Identify the required activity type.
- Retention
- Verify applicable policy and entitlement.
- Gap
- State what cannot be reconstructed.
Offer practical alternatives
For each finding, distinguish a feasible correction with existing entitlements, an operational workaround with explicit limitations and an optional product enhancement. Record dependencies and ongoing ownership for all three. This lets management evaluate cost and risk without confusing a commercial upgrade with completed remediation. If a control cannot meet the agreed objective without a new capability, make that constraint explicit and explain the remaining exposure.
Plan the operational handover
If a new product is needed, agree acceptance criteria before purchase or rollout. Specify the intended population, the evidence of successful implementation and the team that will maintain the control after the project closes.
Related Atlant Security guidance: verifying remediation with evidence and agreeing operational acceptance. Use these to connect the review with the evidence and responsibilities needed after it.
Bring the right facts to scoping
Our Business Premium review, Intune audit and audit logging review explain the relevant evidence boundaries. Use approximate licence families and workloads in the first enquiry. Licence inventories and administrator exports belong in the agreed secure channel. Product documentation and contractual terms should be rechecked for the actual engagement; this guide is not a licensing quote.
Read diagram text
- Scope
- Agree the control objective.
- Sequence
- Confirm dependencies before changes.
- Validate
- Examine the resulting evidence.
Sources & further reading
Reviewed 6 October 2026. Product names, licence entitlements and guidance can change. Confirm applicability to your tenant and agreed assessment date.
This guide and the related sector publications linked above are published by Atlant Security. Technical examples are planning examples, not claims about completed client assessments.
Published by Atlant Security. Sources, editorial policy and corrections.
