01. Agree the objective and criteria
Confirm the audience, business questions, tenant boundary, current licences and evidence period. Identify which Microsoft recommendations, baseline version, internal policy or contractual criterion will be used. Record exceptions that management has already approved.
02. Collect proportionate evidence
Arrange supervised sessions or approved read-only exports. Record source, collector, timestamp and population for each item. Minimise personal information and exclude secrets. Sampling is selected for the stated objective; a judgemental sample is not a statistical assurance claim.
03. Corroborate the effective control
Examine assignments and exclusions alongside policy state. Where agreed, use representative records and supported policy evaluation to understand effective coverage. An automated baseline output is an input requiring review, not the final audit conclusion.
04. Resolve factual questions
Discuss the observed condition with the responsible owner. Record contrary evidence and alternative mitigations. Distinguish confirmed gaps, accepted exceptions, evidence limitations and areas needing separately authorised validation.
05. Report and plan closure
Deliver an executive summary and technical findings with evidence references. Sequence changes around dependencies, change-control windows and business impact. Revalidation checks the agreed closure condition; completing a ticket alone does not establish closure.
Prepare your audit request
Use the Microsoft 365 Audit Planner for a licence-aware starting scope, or the detailed scoping assistant. Review the brief and send it with your enquiry. You can attach your NDA or RFP in the contact form.
Sources & further reading
Reviewed 6 October 2026. Product names, licence entitlements and guidance can change. Confirm applicability to your tenant and agreed assessment date.

