01

Identity is the control plane

An audit should establish how users prove who they are, how risky sign-ins are handled and what happens when people join, change roles or leave. Multifactor authentication coverage matters, but so do authentication strength, legacy methods and recovery processes.

  • MFA registration and enforcement
  • Conditional access design and exclusions
  • Legacy authentication
  • Guest and dormant accounts
  • Account lifecycle controls

02

Privileged access needs separate attention

Administrative accounts can change the entire tenant, so they should not be assessed as ordinary users. The review should identify standing privilege, role concentration, emergency access and whether administrators use separate accounts for daily work.

03

Email and collaboration create practical exposure

The audit should examine anti-phishing and impersonation controls, mailbox forwarding, external sharing and the configuration choices that influence how information leaves the organisation.

Controls should be considered against real workflows. A technically strict setting that teams immediately bypass is not an effective control.

  • Anti-phishing and impersonation
  • Mail flow and forwarding rules
  • SharePoint and OneDrive sharing
  • Teams guest access
  • Data protection and retention

04

What the final report should do

Leadership needs a short explanation of the material scenarios and their business consequence. Technical owners need evidence, affected settings and a sequence that accounts for dependencies and user impact.

A strong report separates urgent exposure, quick improvements and longer governance work. It also states what was not tested, so the assurance is not overstated.