OnlineV Insight

The Small Business Microsoft 365 Audit Checklist

Audit Microsoft 365 by reviewing accounts, admin roles, MFA, mailbox rules, sharing, Teams, SharePoint, licences, devices, offboarding gaps, and action priorities in a clear business-readable sequence.

A small business Microsoft 365 audit should review users, admin roles, MFA, mailbox rules, external sharing, Teams, SharePoint, OneDrive, licences, devices, and offboarding records. The audit should produce decisions the business can act on, not just a long export of settings.

Microsoft 365 often becomes the centre of email, files, meetings, identity, devices, and applications. That means small configuration drift can affect security, cost, and daily productivity. A regular audit keeps the environment understandable.

Start With Accounts And Administrators

Review active users, blocked users, former employees, shared accounts, break-glass or emergency accounts, and guest users. Confirm that administrator roles are limited to people and providers who need them. Global admin access should be especially deliberate because it can change almost anything in the tenant.

Look for old vendor accounts, staff who changed roles, and administrators without MFA. These are not abstract findings; they are common ways small businesses lose track of who can change critical systems.

Review Sign-In Protection And Mail Flow

Check MFA registration, authentication methods, conditional access or security defaults where applicable, mailbox forwarding, suspicious inbox rules, delegated mailbox access, shared mailbox permissions, and distribution groups. Email is where many business risks become visible first.

A real scenario: a former manager is blocked from sign-in, but their mailbox still has forwarding to a personal address created during a transition. The account appears closed, yet mail may still leave the business. An audit that includes forwarding and rules catches what a basic user list misses.

Review Files, Teams, And External Sharing

Audit SharePoint sites, Teams, OneDrive sharing, guest users, anonymous or anyone links if enabled, sensitive libraries, and ownerless workspaces. Files should have a clear business home. If important records live in personal OneDrive folders, staff changes will be harder than necessary.

External sharing should match how the business collaborates. Some outside access is legitimate. The question is whether the business knows who has access, why they have it, and when it should end.

Review Licences And Devices

Compare licence assignments to role needs. Identify unassigned licences, former employees with paid licences, duplicate accounts, add-ons that are no longer used, and roles that may be over-licensed or under-protected. Then review devices that access Microsoft 365, including unmanaged laptops and mobile phones.

Licence changes should wait until data and feature dependencies are checked. Device review should focus on where business data is stored, whether lost devices can be addressed, and whether staff understand expectations for personal devices.

Audit Checklist

  • List active users, blocked users, guests, shared accounts, and administrators.
  • Confirm MFA coverage and remove weak or stale exceptions where appropriate.
  • Review mailbox forwarding, inbox rules, delegation, and shared mailbox access.
  • Review SharePoint sites, Teams, OneDrive sharing, guest users, and ownerless workspaces.
  • Compare licences and add-ons to actual role requirements.
  • Check offboarding records for recent departures and department changes.
  • Rank findings by business impact, ease of correction, and disruption risk.

Turn Findings Into Decisions

The audit is only useful if findings become decisions. Assign each finding to keep, fix now, schedule, investigate, or accept temporarily. Avoid producing a spreadsheet that nobody owns. Small businesses need a short list of changes that reduce real friction or risk.

Be careful with broad security claims. Turning on a setting does not automatically satisfy every requirement. The better habit is to state what the setting does, what could be affected, and how the business verified it.

Scope the audit so it can finish. A small business does not need to inspect every setting with the same intensity on the same day. Start with high-value areas: administrators, former users, MFA, forwarding, external sharing, and licences. Then schedule deeper reviews for SharePoint structure, device management, and application permissions. A completed narrow audit is better than a broad one that never reaches decisions.

Use evidence that managers can understand. Instead of saying “permission inheritance is broken,” state that a finance folder has direct access for two former contractors. Instead of saying “licence posture is inefficient,” state which roles appear over-licensed and what must be checked before downgrading. Clear findings are easier to approve and less likely to stall.

Audit results should also identify what should not change yet. Some findings need business approval, vendor coordination, or user communication before action. Marking those items as scheduled or pending approval is better than leaving them buried in the report. It shows the business understands the issue and has chosen the next step deliberately.

Keep the next audit date visible so the tenant does not drift for another year before anyone checks the same controls again.

Next Step

Run the checklist against one tenant area first, such as admin roles and external sharing, then expand. OnlineV can help perform a business-focused Microsoft 365 review through Cloud Management. Related pages include Cybersecurity, Managed IT Services, and Cloud and Microsoft 365 insights.

Sources and further reading

Need Help With Microsoft 365?

Clean up users, files, licenses, and access safely

OnlineV can review Microsoft 365, Teams, SharePoint, OneDrive, licensing, guest users, and permissions without turning cleanup into a disruptive project.

Microsoft 365 Support Microsoft 365 Consulting
Book a Free IT & AI Review View Microsoft 365 Support

Continue Reading

Three useful guides on this topic

Teams vs SharePoint vs OneDrive: Where Should Business Files Go? Choose the right Microsoft 365 file location by separating personal drafts, team collaboration, official records, external sharing, and... How To Organize SharePoint Files So Staff Can Actually Find Things Organize SharePoint so staff can find files by designing around departments, business processes, permissions, naming, ownership, and archive... How To Reduce Microsoft 365 License Waste Without Breaking Access Reduce Microsoft 365 licence waste safely by matching plans to roles, checking add-ons and inactive accounts, and preserving...