Begin with the tenant boundary
Record the number of tenants, the organisation or business units represented, the licence mix and the identity model. Distinguish Microsoft 365 from Azure infrastructure, on-premises Active Directory and third-party applications. Connected does not automatically mean included.
Describe the population
| Input | Why it affects the work |
|---|---|
| Users and roles | Account types, guests, administrators and service identities require different samples. |
| Workloads | Exchange, collaboration, Intune, Purview, Copilot and apps have different evidence sources. |
| Licences | User assignments and add-ons affect available controls and records. |
| Evidence period | Historic operating evidence may be unavailable even when current configuration is visible. |
| Business events | An acquisition, MSP handover or AI rollout changes the questions the audit should answer. |
Make exclusions explicit
Examples include mailbox contents, employee personal files, active exploitation, phishing simulations, third-party tenants and production changes. Document dependencies even when the dependent system is outside scope.
Prepare your audit request
Use the Microsoft 365 Audit Planner for a licence-aware starting scope, or the detailed scoping assistant. Review the brief and send it with your enquiry. You can attach your NDA or RFP in the contact form.
Prepare a brief before the scoping call
Identify the tenant and licence context, the workloads you use and the decision the audit should support. Keep uncertain coverage and unavailable records visible in the proposed scope.
Use the free microsoft 365 security audit brief builder to record objectives, assessment areas, constraints and NDA preferences. Review the proposed scope, then send it directly to Atlant Security through the contact form.

