Independent Microsoft 365 security assessment.Atlant Security
365/AuditBY ATLANT SECURITY
Build your scope Audit brief builder

AUDIT PREPARATION

A Microsoft 365 security audit checklist that asks for evidence

Prepare a tenant review around populations, exceptions, evidence and owners, rather than a list of enabled features.

Discuss your requirements
Layered glass partitions in an illustrative corporate atrium

For the engagement owner. For each control, ask what population it covers and how you can demonstrate that coverage.

Start with the tenant you actually operate

A useful checklist begins with the environment, not a score. Record tenant count, employee range, identity source, licence families and the workloads people use. Include external collaborators, shared mailboxes, administrative identities and applications. A company with 300 employees can have substantially more access-bearing objects. The number on the payroll is a scoping input, not the denominator for every control.

Identify the decision behind the review: an inherited tenant, a customer request, a new collaboration model or a planned Copilot deployment. That decision determines which evidence needs particular attention. An incident concern should be triaged separately so that a routine audit does not delay containment.

Define the population. People: Employees, guests and administrators.; Applications: Service principals and granted access.; Workloads: Mail, files, devices and audit records.
Working model 01Define the populationIllustrative planning diagram. Adapt the decisions to your authorised scope.
Read diagram text
People
Employees, guests and administrators.
Applications
Service principals and granted access.
Workloads
Mail, files, devices and audit records.

Replace checkboxes with questions

“MFA enabled” says little about excluded groups, administrator protection or the ability to register an alternative method. Ask which policies apply to which users, whether policies are enforced and how exceptions are approved. For sharing, distinguish the tenant default from site-specific settings, existing links and current guest access. A restrictive default does not establish that older access was removed.

Write a small evidence request beside every question. Include the export date, filter and relevant fields. This helps your IT team prepare a focused, sanitised response without exporting entire mailboxes or business documents.

Architectural boundaries illustrated by smoked glass and stone
Operational perspectiveMake access boundaries explicit.Generated illustrative setting; not a client location.

Sample operating evidence deliberately

Configuration describes a point in time. Review records show whether a control operated over a period. To assess joiner and leaver access, reconcile selected HR events with identity and group changes. To assess exceptions, inspect approvals, expiry and review records. Explain the population, selection rationale and missing evidence. A judgemental sample can demonstrate a particular exception; it should not be turned into a statistical claim about the entire tenant.

Ask for the evidence. Policy: What is configured and enforced?; Assignments: Who is included or excluded?; Operation: What selected records demonstrate use?
Working model 02Ask for the evidenceIllustrative planning diagram. Adapt the decisions to your authorised scope.
Read diagram text
Policy
What is configured and enforced?
Assignments
Who is included or excluded?
Operation
What selected records demonstrate use?

Agree the evidence boundary before collection

A supervised session may be sufficient for some questions; other questions need approved read-only exports. Agree the access method, collection purpose, retention and secure transfer channel in advance. Avoid assuming that a tool described as read-only has no sensitive output. Directory relationships, policy exclusions and application identifiers still reveal how an organisation operates. The access and data-handling page describes the decisions to make before any collection.

Record the limitations. Date: When was the export collected?; Sample: What population was examined?; Unknown: What could not be established?
Working model 03Record the limitationsIllustrative planning diagram. Adapt the decisions to your authorised scope.
Read diagram text
Date
When was the export collected?
Sample
What population was examined?
Unknown
What could not be established?

Make the checklist lead to action

For each observed gap, record its criterion, exact condition, affected population, business consequence, owner and closure evidence. “Improve email security” is not an implementable action. “Review the approved external-forwarding exception and verify the resulting effective policy for the selected mailbox” gives an owner a specific next step. Keep recommendations licence-aware and stage potentially disruptive changes with a pilot and rollback arrangement.

Plan the operational handover

A named custodian for each evidence request reduces back-and-forth and helps prevent overcollection. Agree who can explain each export, who approves disclosure and who will act on the resulting finding.

Related Atlant Security guidance: preparing a focused evidence request and assigning control ownership. Use these to connect the review with the evidence and responsibilities needed after it.

Use the preparation list

Start with our audit preparation checklist or the homepage planner. You can describe approximate counts and unknowns without sharing credentials or documents. If your review needs evidence across cloud infrastructure, software delivery and suppliers, consider the separate broader cybersecurity audit scope. Both sites are operated by Atlant Security.

Turn review into action. Observe: Describe the evidenced condition.; Assign: Name the responsible owner.; Verify: Agree the closure evidence.
Working model 04Turn review into actionIllustrative planning diagram. Adapt the decisions to your authorised scope.
Read diagram text
Observe
Describe the evidenced condition.
Assign
Name the responsible owner.
Verify
Agree the closure evidence.

Sources & further reading

Reviewed 6 October 2026. Product names, licence entitlements and guidance can change. Confirm applicability to your tenant and agreed assessment date.

This guide and the related sector publications linked above are published by Atlant Security. Technical examples are planning examples, not claims about completed client assessments.

Published by Atlant Security. Sources, editorial policy and corrections.

PUT THE GUIDANCE TO WORK

Choose your next step.

LET’S START A CONVERSATION

Define the scope.
Take the next step.

Your audit objectives, control boundaries and evidence period. A useful starting point for your assessment.

Discuss your requirements