For the engagement owner. For each control, ask what population it covers and how you can demonstrate that coverage.
Start with the tenant you actually operate
A useful checklist begins with the environment, not a score. Record tenant count, employee range, identity source, licence families and the workloads people use. Include external collaborators, shared mailboxes, administrative identities and applications. A company with 300 employees can have substantially more access-bearing objects. The number on the payroll is a scoping input, not the denominator for every control.
Identify the decision behind the review: an inherited tenant, a customer request, a new collaboration model or a planned Copilot deployment. That decision determines which evidence needs particular attention. An incident concern should be triaged separately so that a routine audit does not delay containment.
Read diagram text
- People
- Employees, guests and administrators.
- Applications
- Service principals and granted access.
- Workloads
- Mail, files, devices and audit records.
Replace checkboxes with questions
“MFA enabled” says little about excluded groups, administrator protection or the ability to register an alternative method. Ask which policies apply to which users, whether policies are enforced and how exceptions are approved. For sharing, distinguish the tenant default from site-specific settings, existing links and current guest access. A restrictive default does not establish that older access was removed.
Write a small evidence request beside every question. Include the export date, filter and relevant fields. This helps your IT team prepare a focused, sanitised response without exporting entire mailboxes or business documents.

Sample operating evidence deliberately
Configuration describes a point in time. Review records show whether a control operated over a period. To assess joiner and leaver access, reconcile selected HR events with identity and group changes. To assess exceptions, inspect approvals, expiry and review records. Explain the population, selection rationale and missing evidence. A judgemental sample can demonstrate a particular exception; it should not be turned into a statistical claim about the entire tenant.
Read diagram text
- Policy
- What is configured and enforced?
- Assignments
- Who is included or excluded?
- Operation
- What selected records demonstrate use?
Agree the evidence boundary before collection
A supervised session may be sufficient for some questions; other questions need approved read-only exports. Agree the access method, collection purpose, retention and secure transfer channel in advance. Avoid assuming that a tool described as read-only has no sensitive output. Directory relationships, policy exclusions and application identifiers still reveal how an organisation operates. The access and data-handling page describes the decisions to make before any collection.
Read diagram text
- Date
- When was the export collected?
- Sample
- What population was examined?
- Unknown
- What could not be established?
Make the checklist lead to action
For each observed gap, record its criterion, exact condition, affected population, business consequence, owner and closure evidence. “Improve email security” is not an implementable action. “Review the approved external-forwarding exception and verify the resulting effective policy for the selected mailbox” gives an owner a specific next step. Keep recommendations licence-aware and stage potentially disruptive changes with a pilot and rollback arrangement.
Plan the operational handover
A named custodian for each evidence request reduces back-and-forth and helps prevent overcollection. Agree who can explain each export, who approves disclosure and who will act on the resulting finding.
Related Atlant Security guidance: preparing a focused evidence request and assigning control ownership. Use these to connect the review with the evidence and responsibilities needed after it.
Use the preparation list
Start with our audit preparation checklist or the homepage planner. You can describe approximate counts and unknowns without sharing credentials or documents. If your review needs evidence across cloud infrastructure, software delivery and suppliers, consider the separate broader cybersecurity audit scope. Both sites are operated by Atlant Security.
Read diagram text
- Observe
- Describe the evidenced condition.
- Assign
- Name the responsible owner.
- Verify
- Agree the closure evidence.
Sources & further reading
- Atlant Security Microsoft 365 audit service ↗
- CISA ScubaGear and baseline guidance ↗
- CIS Microsoft 365 Benchmark ↗
Reviewed 6 October 2026. Product names, licence entitlements and guidance can change. Confirm applicability to your tenant and agreed assessment date.
This guide and the related sector publications linked above are published by Atlant Security. Technical examples are planning examples, not claims about completed client assessments.
Published by Atlant Security. Sources, editorial policy and corrections.
