Identity & sign-in
Entra ID user by user: MFA coverage, Conditional Access policies, legacy authentication still open, stale and shared accounts, password policy, and whether security defaults are doing the job or just getting in the way.
microsoft 365 security audit · new zealand
"We've got Microsoft, so we're covered." Are you, though? Most New Zealand small businesses have no real picture of how their Microsoft 365 tenant is set up, until an insurer, a customer questionnaire or an incident forces the question. We go through the tenant properly and tell you straight: where you're exposed, what to fix first, and what can wait.
A Microsoft 365 security audit is a structured check of how your Microsoft 365 and Entra tenant is actually configured, measured against Microsoft Secure Score, the CIS Microsoft 365 Benchmark and New Zealand guidance such as the NCSC advice. It covers who can sign in and how (MFA, Conditional Access, legacy sign-in), who holds admin rights, what your mailboxes are quietly doing (forwarding rules, delegated access), what's shared outside the business from SharePoint, OneDrive and Teams, whether Defender is switched on and tuned, whether your email can be spoofed, and whether your data is actually backed up. The output is a plain-English findings report ranked by risk, with a fix list that starts with the cheap, high-impact changes. Not a 90-page PDF.
the usual gaps
what we check
Every area is checked against the benchmark, scored, and written up in plain English with what to change.
Entra ID user by user: MFA coverage, Conditional Access policies, legacy authentication still open, stale and shared accounts, password policy, and whether security defaults are doing the job or just getting in the way.
Who holds Global Admin and the other privileged roles, whether they use separate admin accounts, whether there's a protected break-glass account, and how much of that access is still needed.
Inbox rules, auto-forwarding to external addresses, delegated and shared mailbox access, and tenant-wide forwarding controls. This is where compromised accounts hide.
SharePoint, OneDrive and Teams sharing settings, anonymous links, guest accounts and what they can still reach. We show you what's exposed and who put it there.
Which Defender features your licences include and whether they're on: Safe Links, Safe Attachments, anti-phishing, endpoint protection. Your Secure Score, and the recommendations worth acting on versus the noise.
What you're paying for against what you're using. Security features you already own and haven't switched on, and the few cases where a licence step-up actually earns its keep.
SPF, DKIM and DMARC for every domain you send from, so criminals can't send invoices as you. The detail is on our DMARC and email authentication page.
Microsoft keeps your service running. It does not keep a copy of your data you can restore after ransomware or a deleted mailbox. We check what's actually backed up, where, and whether anyone has tested a restore.
what you get
Every finding written in plain English: what it is, why it matters to your business, how exposed it leaves you. Ordered by risk, not by the order we found it. Written so you can answer a cyber-insurance form or a customer security questionnaire from it.
The cheap, high-impact fixes first: close the MFA gaps, kill legacy sign-in, rein in admin roles, remove the forwarding rule, tighten sharing. Each item says what to change and what it affects, so you or your current IT provider can work through it.
If you'd rather we did the fixing, we work through the list with you, one change at a time, and re-check the tenant afterwards so the report shows closed, not just found. From there the same checks can run monthly under managed IT.
common questions
start a conversation
A fixed-price Microsoft 365 security audit is the front door. You'll know exactly where you're exposed and what's worth fixing first. No scare tactics, no upsell to things you don't need.