Ask for a method, not a check count
- Which workloads and populations are actually examined?
- How are policy assignments and exceptions validated?
- What reader permissions or supervised sessions are needed?
- How are missing records, licensing gaps and accepted exceptions reported?
- Who reviews factual accuracy and owns the remediation plan?
- Does the price include follow-up validation or only the first report?
Examine a sample finding
Look for an evidence reference, assessment date, affected population, risk rationale and a testable closure condition. A long export of settings without interpretation creates work for your administrators rather than resolving decisions.
Confirm the commercial and confidentiality terms
Agree scope, deliverables, access, evidence handling, staffing, price and timing in writing. Submit your NDA through the contact form if needed before a confidential conversation. Procurement validation is the place to request current credentials and insurance evidence.
Prepare your audit request
Use the Microsoft 365 Audit Planner for a licence-aware starting scope, or the detailed scoping assistant. Review the brief and send it with your enquiry. You can attach your NDA or RFP in the contact form.
Prepare a brief before the scoping call
Identify the tenant and licence context, the workloads you use and the decision the audit should support. Keep uncertain coverage and unavailable records visible in the proposed scope.
Use the free microsoft 365 security audit brief builder to record objectives, assessment areas, constraints and NDA preferences. Review the proposed scope, then send it directly to Atlant Security through the contact form.

