The guide to a good
Microsoft 365 security audit
A successful audit is more than running a scan. From preparation to tracking fixes, here is the method to get a reliable, defensible and truly actionable result.
The 8 steps of a successful audit
Know what you're auditing
An audit without a clear scope produces an uninterpretable score. First of all, list the services actually in use in your organisation: identity (Entra ID), local directory (Active Directory), Azure, and the enabled Microsoft 365 services (Exchange, SharePoint, OneDrive, Teams, Defender, Purview).
Auditing a service you don't use skews the result: dozens of controls will show as “non-compliant” even though they don't apply to you. Conversely, forgetting a service in production leaves a blind spot.
Start with identity (Entra ID / AD). It's the gateway to everything else: a compromised account nullifies most other protections.
A read-only audit, nothing more
A security audit must never modify your environment. The permissions granted to the audit tool must be strictly read-only : it reads configurations, it does not change them.
In practice, for Microsoft 365, this means an application registered in Entra ID holding Graph permissions of type *.Read.All. No write permission should be requested.
Be wary of any tool that demands write or global admin rights “to audit”. An audit doesn't need them. The principle of least privilege applies to the auditor too.
On what basis to judge compliance
A control only makes sense relative to a recognised framework. The most used for Microsoft 365 are the CIS Microsoft 365 Benchmark, the recommendations of ANSSI, le NIST and ISO 27001. They formalise what a “safe” configuration is.
But no generic framework fits your context perfectly. Some controls don't apply to you; others, secondary in the standard, are critical for you. Hence the value of a custom baseline : start from the standard, exclude the off-topic, and adjust the criticality of what really matters.
Not all controls are equal. We usually distinguish core controls (level 1), essential ones, from hardening controls (level 2), which strengthen the posture. A good score weights these levels rather than counting them equally.
A reliable, reproducible snapshot
Execution must be automated and reproducible. An audit done “by hand” via screenshots and manual checks is slow, incomplete and impossible to replay identically three months later.
Automation guarantees that every audit covers exactly the same points, under the same conditions — an essential requirement to compare two audits and measure progress.
- Each control is evaluated against the tenant's actual configuration.
- Results are categorised: compliant, warning (indeterminate), or non-compliant.
- The operation alters no configuration: it's a simple read.
Understand what the number says
A compliance score is only useful if you know what it measures. A simple ratio of “X boxes ticked out of Y” is misleading: it puts a critical control and a cosmetic setting on the same level.
A score weighted by criticality is far more meaningful: core controls weigh more than hardening ones. An indeterminate control (warning) counts for an intermediate value. The result reflects real risk, not a mechanical count.
Look at the overall score, but above all the score per framework. An overall 70% can hide a service at 40% that deserves all your attention.
Where to start
An audit that lists 120 non-compliances in no order is discouraging and unusable. The value of an audit lies in its ability to say where to start.
The rule: address first the non-compliances that are core (level 1), the ones that expose you the most. A concrete remediation must accompany each item — not a mere observation, but the action to take and, ideally, a link to the official documentation.
- First the critical non-compliant controls (maximum impact).
- Then the warnings, to be resolved to clarify the situation.
- Finally the hardening controls, to strengthen the posture.
Two readings for two audiences
The same audit addresses two audiences with opposite needs. Management and the CISO want a high-level view: a score, a trend, the priorities, the overall risk. The technical teams want the detail: each control, its result, its remediation.
A good report serves both: an executive summary up front (cover page, score, methodology, priorities) followed by the full technical detail. All in a presentable deliverable — not a raw spreadsheet.
A defensible score and an explicit methodology are invaluable before a cyber insurer, an ISO 27001 assessor or as part of NIS2 compliance.
An audit is not an event, it's a cycle
The security of a Microsoft 365 environment drifts constantly: new accounts, configuration changes, new Microsoft features. A one-off audit has only limited value over time.
The best practice is to re-audit regularly and track the score's evolution. “You were at 54%, you're now at 71%” is tangible proof of progress — far more convincing than a one-off snapshot.
How often should you audit?
- Quarterly for standard posture monitoring.
- Monthly in sensitive environments or during active remediation.
- After any major change : migration, new M365 component, access reorganisation.
Move from theory to practice
EntraGUARD applies this methodology end to end: 283 controls, weighted score, custom baselines, executive reports and tracking over time.
Download the free demo