Independent Microsoft 365 security assessment.Atlant Security
365/AuditBY ATLANT SECURITY
Build your RFP Audit brief builder

MICROSOFT 365 / INDEPENDENT SECURITY ASSESSMENT

Microsoft 365
security audit.
Clarity. Then action.

Find the gaps between the controls you intended and the access your tenant actually allows. Get a clear, prioritised plan for identity, email, data and devices.

Licence-aware scopeEvidence-linked findingsPractical remediation
BY ATLANT SECURITYIndependent of Microsoft

YOUR ENVIRONMENT. YOUR REQUIREMENTS.

Plan your Microsoft 365 audit.

Your licences. Your workloads. A useful scope.
See the review priorities before sharing your email.

START WITH WHAT IS PUBLIC / FREE

What does your email domain reveal?

Check public mail routing, SPF, DMARC and common Microsoft DKIM selectors. No login, email address or tenant access required.

Use the part after @ in your work email. Only DNS is queried through Cloudflare. You can skip this check and use the planner below.

How the check works and its limits

We query six public DNS names through Cloudflare’s resolver: MX, SPF, DMARC, two common Microsoft DKIM aliases and Autodiscover. We do not connect to your website or tenant, send test mail, or change settings. Results stay in this page until you choose to submit an enquiry; then we recheck the domain and include the observations for our team.

This is a starting point for discussion. It cannot establish MFA, administrator privileges, mail forwarding, data sharing or device security. It does not fully validate SPF, discover every DKIM selector, or resolve DMARC inheritance for subdomains. A lookup failure is reported as unknown.

Reference: Microsoft guidance on SPF, DKIM and DMARC. See our public-domain check privacy notice.

The guided builder needs JavaScript for its security check. Send your employee range, scope and requested outcomes to sales@ms365securityaudit.com, with your NDA/RFP if available.

Your tenant is connected.
Your audit
should be too.

A Microsoft 365 security audit examines configuration, effective access and supporting records across your agreed workloads.

We look at the people and applications behind the settings: who is included, who is excluded, who owns the exception and what evidence supports the conclusion.

Use one focused workstream or agree a broader tenant review. Your licence assignments and available records shape the scope.

Inside the service
01 / WORKLOAD REVIEW

Entra ID security audit

Understand identity lifecycle, privileged roles and the paths that connect your people, applications and tenant.

02 / WORKLOAD REVIEW

Conditional Access review

Examine which people, applications and sign-in situations your policies actually cover.

03 / WORKLOAD REVIEW

Exchange Online security audit

Review mail flow, forwarding, authentication and effective protection for the recipients that matter.

05 / WORKLOAD REVIEW

Intune security audit

Connect device inventory, policy assignment and compliance signals to real access decisions.

08 / WORKLOAD REVIEW

Purview audit & logging review

Establish which questions your current audit evidence can answer, for which users and over what period.

02 / A FINDING SHOULD EXPLAIN ITSELF

From a setting
to a decision.

“MFA is enabled” leaves important questions unanswered.

The report should identify the population, actual coverage, exception and business implication. Each recommendation needs an owner, a dependency check and a way to validate closure.

Explore the deliverables

ILLUSTRATIVE FINDING / IDENTITY

The policy exists.
The excluded users remain.

Observed condition
A broad exception group bypasses the intended policy in the example tenant.
Evidence to examine
Policy state, group membership, owner approval and representative sign-ins.
Action to agree
Validate business dependencies, reduce the exception in a controlled rollout and review the resulting sign-ins.

Reporting example only. No claim about your tenant or a real client.

03 / CONTROLLED ACCESS. CLEAR OUTPUTS.

You keep control of your tenant.

Access & data handling
  1. 01

    Agree the boundary

    Confirm tenants, licences, workloads, evidence dates, report audience and NDA requirements.

  2. 02

    Review the evidence

    Work through supervised sessions or approved read-only exports. Record what was examined and what was unavailable.

  3. 03

    Validate the finding

    Discuss business context and factual accuracy. Distinguish a missing record from an absent control.

  4. 04

    Prioritise the change

    Set owners, dependencies, rollout safeguards and closure evidence. Agree implementation or revalidation separately.

No credentials in the website form. No automatic tenant connection. No production changes implied by an enquiry.

BEYOND A SINGLE NUMBER

Secure Score is a signal.
The audit adds context.

Microsoft Secure Score tracks recommended actions. An independent review connects those actions with exclusions, business dependencies, effective access and evidence limitations.

Compare the two
A useful inputThe next question
Recommended actionWhich population and exceptions does it cover?
Configured policyWas it enforced in the relevant scenario?
Available capabilityIs the right licence assigned to the relevant user?
A closed taskWhat evidence demonstrates the change works?

Secure Score does not express breach probability. Microsoft’s explanation.

KNOW WHAT YOU ALREADY OWN

Recommendations that respect your licences.

Business Premium review

Configure what is available

Identify gaps in controls your tenant already includes. Confirm assignments, coverage and operational ownership before proposing new products.

Separate the dependencies

Conditional Access, risk-based identity protection and advanced audit features have different entitlements. Mark those dependencies clearly.

Keep unknowns visible

Mixed plans and add-ons are common. An unknown licence or missing record becomes a scoping question, not an invented finding.

SEE THE STANDARD OF EVIDENCE

A Microsoft 365 audit.
Open for inspection.

A fictional assessment of Meridian Advisory Group AG: tenant architecture, licence assumptions, evidence excerpts, eight findings and a remediation register.

Preview the sample report

Eight pages visible before the form. Original illustrative report; not a claim of client work.

Cover of the fictional Meridian Advisory Group AG Microsoft 365 audit

04 / BEFORE YOU COMMISSION AN AUDIT

The practical questions.

All questions
Do you need our Global Administrator credentials?

No credentials belong in this form. We can start with supervised sessions led by your team. Any additional read-only access or export permissions are separately agreed for the selected workloads.

How much does an audit cost?

Tenant count, workloads, hybrid identity, evidence availability and reporting requirements drive effort. We agree a written scope and price before access. Our pricing guide links Atlant’s current published starting prices.

Will the audit change our settings?

The default engagement is an assessment. Remediation implementation, active validation, phishing simulations and production changes need their own agreed scope and approvals.

Can we send an NDA or RFP first?

Yes. Attach a PDF or DOCX up to 2 MiB through the planner or contact form, or email sales@ms365securityaudit.com. A person reviews documents and signatures.

PRACTICAL GUIDANCE / PRIMARY SOURCES

Ask better questions of your tenant.

Explore all six guides

PREPARE WITH ATLANT SECURITY

Evidence before the first meeting.

Use the preparation checklist and find Atlant’s published Microsoft 365 auditing tools.

Explore the resources

LET’S START A CONVERSATION

Define the scope.
Take the next step.

Your audit objectives, control boundaries and evidence period. A useful starting point for your assessment.

Discuss your requirements