Most Microsoft 365 estates look tidy on the surface until someone asks a simple question like who has access to sensitive files, which accounts have MFA disabled, or why you are paying for licences nobody uses. That is usually the point when organisations start looking at how to audit Microsoft 365 properly, not as a box-ticking exercise, but as a way to reduce risk, improve control and get better value from a platform they already rely on every day.
For most SMEs, schools, charities and operational teams, the challenge is not whether Microsoft 365 is capable. It is whether the environment has grown in a controlled way. Over time, users join and leave, permissions get layered on, Teams sprawl, old SharePoint sites stay live, and settings drift away from what the business actually needs. A good audit gives you a clear picture of what is in place, what is exposed, and what should change first.
What a Microsoft 365 audit should cover
If you are working out how to audit Microsoft 365, start by being clear about scope. An audit is not just a security review and it is not just a licence check. It should look at identity, access, collaboration, data handling, device use, compliance settings and the practical day-to-day management of the tenant.
That matters because many of the biggest issues sit between those areas. A departed user account may still exist, still hold a licence, still appear in a Team, and still have access to files through a forgotten SharePoint group. On paper, each issue looks minor. Operationally, it adds up to unnecessary spend and avoidable risk.
A sensible audit usually covers users and groups, admin roles, multi-factor authentication, conditional access, mailbox and file-sharing settings, Teams governance, SharePoint permissions, OneDrive retention, endpoint management, audit logging, licensing and backup arrangements. In some organisations, it should also include Power Platform usage and any bespoke integrations that rely on Microsoft 365 data.
Start with the business context, not the portal
The technical review matters, but it should follow the realities of the organisation. A manufacturer with shift-based staff, a school with safeguarding requirements and a professional services business handling sensitive client data will not all need the same controls or reporting.
Before you look at settings, define what the environment is meant to support. Who needs remote access? Which teams share data externally? What information is commercially sensitive? Which users need elevated rights? How quickly should leavers lose access? If you skip this step, the audit can become a long list of technical findings with no sense of priority.
This is also the stage to identify what good looks like for your organisation. For some businesses, that means tighter security and formal governance. For others, it means simplifying a tenant that has become overcomplicated and expensive to run.
How to audit Microsoft 365 in a practical order
The best way to approach the work is to review the environment in layers. Start with identity, because that controls everything else.
Review users, sign-in methods and admin access
Begin with user accounts. Check that every active account belongs to a current user or a valid shared function. Look for former staff, duplicate accounts, test accounts that were never removed and generic logins with weak ownership.
Then review authentication. Multi-factor authentication should be enforced consistently, especially for administrators and anyone accessing business data remotely. If there are exclusions, they should be documented and justified. It is also worth checking whether legacy authentication is still enabled, as that can create an unnecessary route around modern security controls.
Administrative roles deserve particular scrutiny. In many tenants, too many users hold global admin or broad privileged roles simply because it was quicker at the time. That creates risk and makes change control harder. Most organisations benefit from reducing admin rights to the minimum required and separating day-to-day user accounts from privileged admin accounts.
Check permissions across SharePoint, Teams and OneDrive
Permissions are where many audits uncover the biggest surprises. Microsoft 365 makes collaboration easy, but easy sharing can turn into uncontrolled access if nobody reviews it.
Look at SharePoint site permissions, Team membership and OneDrive sharing settings. Pay close attention to externally shared files and folders, broken inheritance on key document libraries, and large groups that grant access far more widely than intended. If a user can access information, there should be a clear reason why.
This is also where operational trade-offs matter. Tightening every permission may look good in a report, but if it disrupts collaboration, users will find workarounds. The goal is sensible control, not friction for its own sake.
Review security policies and device controls
Next, assess the policies that protect access to data. Conditional access rules should reflect how your staff actually work. For example, remote users on unmanaged devices may need stricter rules than office-based users on company hardware.
Check whether Microsoft Defender, Intune and related security features are being used properly if they are included in your licensing. Many organisations are paying for features they have only partially configured. Others assume a setting is active because the licence exists, when in reality it has never been rolled out.
Device compliance policies, encryption, screen lock rules and app protection settings are all worth reviewing. If staff use personal devices, the audit should test whether the organisation has enough control over company data without making work impractical.
Examine data protection, retention and audit logs
A Microsoft 365 tenant should help you answer questions quickly when something goes wrong. That only works if logging and retention are set up properly.
Review whether unified audit logging is enabled, how long logs are retained, and whether the organisation can realistically investigate suspicious behaviour or accidental data loss. Then check retention labels, retention policies and mailbox settings. Some businesses keep data far longer than necessary, which increases exposure. Others delete too aggressively and create compliance or continuity problems.
Backup is another area where assumptions can be costly. Microsoft 365 provides resilience within the platform, but that does not always align with a business’s own recovery expectations. If a key mailbox, Team or document set became unavailable or was altered in error, you should know how quickly it could be restored and from where.
Assess licensing and service adoption
A proper audit should also ask whether the estate is cost-effective. Review what licences are assigned, who is actively using them and whether users have the right licence level for their role.
It is common to find users on higher-cost plans who only use email and Office apps, while other users lack features that would genuinely improve security or productivity. In the same review, check whether tools such as Teams, SharePoint or Power Automate are being used in a structured way or whether adoption has been inconsistent.
This part of the audit often highlights a useful tension. Underused features may point to waste, but they may also show missed value. Sometimes the right answer is to downgrade. Sometimes it is to configure and train properly so the business gets more from what it already pays for.
Common issues an audit tends to uncover
Most Microsoft 365 audits reveal a similar pattern. Permissions have expanded over time. Security policies exist but are inconsistent. Leaver processes are not fully joined up. Teams and SharePoint have grown without ownership. Licences no longer match real usage. Reporting is possible, but nobody has turned it into a regular management discipline.
None of that means the environment is failing. It usually means it has evolved faster than governance. That is very common in growing organisations, especially where internal IT is stretched or Microsoft 365 was rolled out quickly to support hybrid working.
The value of the audit is not in producing a long technical report. It is in turning those findings into a realistic plan. That might mean immediate action on admin rights and MFA, followed by a phased permissions review, licence rationalisation and clearer ownership for Teams and SharePoint.
Turning the audit into ongoing control
A one-off review is useful, but Microsoft 365 changes constantly. New users, new Teams, new devices and new business processes will keep altering the environment. If there is no repeatable review process, drift returns.
The most effective approach is to turn key parts of the audit into routine management. Review privileged accounts monthly. Check leavers and inactive users regularly. Reassess sharing and external access on a planned basis. Revisit licensing every quarter. Tie policy reviews to business change, not just to compliance deadlines.
For many organisations, that is where external support helps most. Not because the platform is impossible to manage internally, but because keeping it aligned with business risk, user behaviour and cost control takes time and experience. A pragmatic partner can help translate settings into operational decisions, which is often the difference between a tenant that merely functions and one that genuinely supports the business.
If you are wondering how to audit Microsoft 365, the right starting point is simple: look at what your people rely on, what your data needs protecting from, and where your current setup no longer reflects the way the organisation works. That is where practical improvements begin.

