01
Identity is the control plane
An audit should establish how users prove who they are, how risky sign-ins are handled and what happens when people join, change roles or leave. Multifactor authentication coverage matters, but so do authentication strength, legacy methods and recovery processes.
- MFA registration and enforcement
- Conditional access design and exclusions
- Legacy authentication
- Guest and dormant accounts
- Account lifecycle controls
02
Privileged access needs separate attention
Administrative accounts can change the entire tenant, so they should not be assessed as ordinary users. The review should identify standing privilege, role concentration, emergency access and whether administrators use separate accounts for daily work.
03
Email and collaboration create practical exposure
The audit should examine anti-phishing and impersonation controls, mailbox forwarding, external sharing and the configuration choices that influence how information leaves the organisation.
Controls should be considered against real workflows. A technically strict setting that teams immediately bypass is not an effective control.
- Anti-phishing and impersonation
- Mail flow and forwarding rules
- SharePoint and OneDrive sharing
- Teams guest access
- Data protection and retention
04
What the final report should do
Leadership needs a short explanation of the material scenarios and their business consequence. Technical owners need evidence, affected settings and a sequence that accounts for dependencies and user impact.
A strong report separates urgent exposure, quick improvements and longer governance work. It also states what was not tested, so the assurance is not overstated.
