A Microsoft 365 audit is a structured way to see how the tenant is actually operated. The result should be a prioritized list of verified findings, owners, and next actions, not a claim of certification.
Why this deserves a focused review
An audit should produce a small number of useful findings rather than a generic score. Each finding needs evidence, an owner, a priority, and an indication of whether the business can address it through normal administration or a separate project.
Scenario
A growing company knows it has Microsoft 365 but cannot quickly identify global administrators, shared mailbox owners, inactive guests, or the status of key backups.
Review sequence
01. Confirm tenant ownership and administrator roles.
02. Review active users, shared mailboxes, and former staff accounts.
03. Check MFA, sign-in controls, and recovery paths.
04. Review sharing, guest access, and mailbox forwarding.
05. Document a prioritized remediation list with ownership.
Useful record
Keep operational choices separate from legal or regulatory conclusions. The tenant can be reviewed for access, records, and configuration, while the organization’s advisers decide what its obligations require.
- Confirm tenant ownership and administrator roles.
- Review active users, shared mailboxes, and former staff accounts.
- Check MFA, sign-in controls, and recovery paths.
- Review sharing, guest access, and mailbox forwarding.
- Document a prioritized remediation list with ownership.
Common mistake
Treating an audit as a one-time cleanup. Staffing, licensing, applications, and external relationships keep changing.
Practical next step
Repeat focused checks as the organization changes. A successful audit is one that makes the next review easier. OnlineV can help apply this through the relevant service. Continue with microsoft 365 security settings small businesses should review, common microsoft 365 cleanup issues small business, microsoft 365 offboarding checklist small business.
Detailed guidance
A small business Microsoft 365 audit should review users, admin roles, MFA, mailbox rules, external sharing, Teams, SharePoint, OneDrive, licences, devices, and offboarding records. The audit should produce decisions the business can act on, not just a long export of settings.
Microsoft 365 often becomes the centre of email, files, meetings, identity, devices, and applications. That means small configuration drift can affect security, cost, and daily productivity. A regular audit keeps the environment understandable.
Review active users, blocked users, former employees, shared accounts, break-glass or emergency accounts, and guest users. Confirm that administrator roles are limited to people and providers who need them. Global admin access should be especially deliberate because it can change almost anything in the tenant.
Look for old vendor accounts, staff who changed roles, and administrators without MFA. These are not abstract findings; they are common ways small businesses lose track of who can change critical systems.
Check MFA registration, authentication methods, conditional access or security defaults where applicable, mailbox forwarding, suspicious inbox rules, delegated mailbox access, shared mailbox permissions, and distribution groups. Email is where many business risks become visible first.
A real scenario: a former manager is blocked from sign-in, but their mailbox still has forwarding to a personal address created during a transition. The account appears closed, yet mail may still leave the business. An audit that includes forwarding and rules catches what a basic user list misses.
Audit SharePoint sites, Teams, OneDrive sharing, guest users, anonymous or anyone links if enabled, sensitive libraries, and ownerless workspaces. Files should have a clear business home. If important records live in personal OneDrive folders, staff changes will be harder than necessary.
External sharing should match how the business collaborates. Some outside access is legitimate. The question is whether the business knows who has access, why they have it, and when it should end.
Compare licence assignments to role needs. Identify unassigned licences, former employees with paid licences, duplicate accounts, add-ons that are no longer used, and roles that may be over-licensed or under-protected. Then review devices that access Microsoft 365, including unmanaged laptops and mobile phones.
Licence changes should wait until data and feature dependencies are checked. Device review should focus on where business data is stored, whether lost devices can be addressed, and whether staff understand expectations for personal devices.
The audit is only useful if findings become decisions. Assign each finding to keep, fix now, schedule, investigate, or accept temporarily. Avoid producing a spreadsheet that nobody owns. Small businesses need a short list of changes that reduce real friction or risk.
Be careful with broad security claims. Turning on a setting does not automatically satisfy every requirement. The better habit is to state what the setting does, what could be affected, and how the business verified it.
Scope the audit so it can finish. A small business does not need to inspect every setting with the same intensity on the same day. Start with high-value areas: administrators, former users, MFA, forwarding, external sharing, and licences. Then schedule deeper reviews for SharePoint structure, device management, and application permissions. A completed narrow audit is better than a broad one that never reaches decisions.
Use evidence that managers can understand. Instead of saying “permission inheritance is broken,” state that a finance folder has direct access for two former contractors. Instead of saying “licence posture is inefficient,” state which roles appear over-licensed and what must be checked before downgrading. Clear findings are easier to approve and less likely to stall.
Audit results should also identify what should not change yet. Some findings need business approval, vendor coordination, or user communication before action. Marking those items as scheduled or pending approval is better than leaving them buried in the report. It shows the business understands the issue and has chosen the next step deliberately.
Keep the next audit date visible so the tenant does not drift for another year before anyone checks the same controls again.
Sources and further reading
Need Help With Microsoft 365?
Clean up users, files, licenses, and access safely
OnlineV can review Microsoft 365, Teams, SharePoint, OneDrive, licensing, guest users, and permissions without turning cleanup into a disruptive project.
Continue Reading