microsoft 365 security audit · new zealand

A Microsoft 365 security audit for NZ firms who assume they're fine.

"We've got Microsoft, so we're covered." Are you, though? Most New Zealand small businesses have no real picture of how their Microsoft 365 tenant is set up, until an insurer, a customer questionnaire or an incident forces the question. We go through the tenant properly and tell you straight: where you're exposed, what to fix first, and what can wait.

in plain terms

A Microsoft 365 security audit is a structured check of how your Microsoft 365 and Entra tenant is actually configured, measured against Microsoft Secure Score, the CIS Microsoft 365 Benchmark and New Zealand guidance such as the NCSC advice. It covers who can sign in and how (MFA, Conditional Access, legacy sign-in), who holds admin rights, what your mailboxes are quietly doing (forwarding rules, delegated access), what's shared outside the business from SharePoint, OneDrive and Teams, whether Defender is switched on and tuned, whether your email can be spoofed, and whether your data is actually backed up. The output is a plain-English findings report ranked by risk, with a fix list that starts with the cheap, high-impact changes. Not a 90-page PDF.

the usual gaps

What we tend to find.

  • MFA that isn't everywhereTurned on for most people, skipped for the director, the shared mailbox or the old admin account nobody uses. Those are the ones that get hit.
  • Admin rights that sprawledGlobal Admin handed out to whoever set things up years ago, still there, still unprotected.
  • Mailbox rules nobody setA forwarding rule quietly copying invoices to an outside address, left behind by a phishing click months ago.
  • Sharing left wide open"Anyone with the link" on folders of client files, guests who left a project two years ago still in Teams.

what we check

The whole tenant, not just the login page.

Every area is checked against the benchmark, scored, and written up in plain English with what to change.

01

Identity & sign-in

Entra ID user by user: MFA coverage, Conditional Access policies, legacy authentication still open, stale and shared accounts, password policy, and whether security defaults are doing the job or just getting in the way.

02

Admin roles

Who holds Global Admin and the other privileged roles, whether they use separate admin accounts, whether there's a protected break-glass account, and how much of that access is still needed.

03

Mailbox rules & forwarding

Inbox rules, auto-forwarding to external addresses, delegated and shared mailbox access, and tenant-wide forwarding controls. This is where compromised accounts hide.

04

External sharing

SharePoint, OneDrive and Teams sharing settings, anonymous links, guest accounts and what they can still reach. We show you what's exposed and who put it there.

05

Defender & Secure Score

Which Defender features your licences include and whether they're on: Safe Links, Safe Attachments, anti-phishing, endpoint protection. Your Secure Score, and the recommendations worth acting on versus the noise.

06

Licensing posture

What you're paying for against what you're using. Security features you already own and haven't switched on, and the few cases where a licence step-up actually earns its keep.

07

Email authentication

SPF, DKIM and DMARC for every domain you send from, so criminals can't send invoices as you. The detail is on our DMARC and email authentication page.

08

Backup gaps

Microsoft keeps your service running. It does not keep a copy of your data you can restore after ransomware or a deleted mailbox. We check what's actually backed up, where, and whether anyone has tested a restore.

what you get

A report you can act on, and hand to an insurer.

01

Findings report, ranked by risk

Every finding written in plain English: what it is, why it matters to your business, how exposed it leaves you. Ordered by risk, not by the order we found it. Written so you can answer a cyber-insurance form or a customer security questionnaire from it.

02

A fix list

The cheap, high-impact fixes first: close the MFA gaps, kill legacy sign-in, rein in admin roles, remove the forwarding rule, tighten sharing. Each item says what to change and what it affects, so you or your current IT provider can work through it.

03

Optional remediation

If you'd rather we did the fixing, we work through the list with you, one change at a time, and re-check the tenant afterwards so the report shows closed, not just found. From there the same checks can run monthly under managed IT.

who it's for

NZ firms on Microsoft 365 with nobody watching the tenant.

Built for New Zealand businesses of roughly 5 to 50 staff on Microsoft 365 Business Basic, Standard or Premium: accounting practices, law firms, consultancies, trades offices, anyone whose client data lives in Outlook, SharePoint and Teams. Typically there's an IT provider who keeps things running but nobody who has ever sat down and checked the security configuration end to end. It takes a few days from access to report, not weeks, and we only need read-only access to run it.

  • → Read-only tenant access, revoked when done
  • → Business Basic, Standard and Premium
  • → A few days from access to report
  • → Wellington-based, NZ-wide

common questions

Microsoft 365 security audits, answered straight.

What does a Microsoft 365 security audit cover?
Identity and sign-in (MFA, Conditional Access, legacy authentication), admin roles, mailbox rules and forwarding, external sharing across SharePoint, OneDrive and Teams, Defender settings and Secure Score, licensing, email authentication (SPF, DKIM, DMARC) and backup. Measured against Microsoft Secure Score and the CIS Microsoft 365 Benchmark, not guessed.
How long does it take?
A few days from the moment we have access to the finished report. Most of that is reading the tenant carefully and writing findings you can act on. Remediation, if you want it, is scoped separately once you've seen the list.
What access do you need?
A read-only role in your Entra tenant, granted for the audit and removed afterwards. We don't change anything during the audit, so nothing breaks while we look.
We're on Business Basic or Standard, not Premium. Is it still worth it?
Yes. Most of the serious gaps (MFA, admin roles, forwarding rules, open sharing, missing DMARC) are configuration, not licensing, and can be fixed on any plan. Where a Premium feature would genuinely close a gap, the report says so and why, and where it wouldn't, it says that too.
Will this help with cyber insurance?
Yes. The report is written so you can answer an insurer's or a customer's security questionnaire and show what you've remediated. The questions they ask are the ones we measure.
Do you fix the issues or just report them?
Either. The audit stands alone and your current IT provider can work the fix list. Or we remediate the gaps with you and fold the ongoing checks into managed IT so the tenant stays correct month to month.
What does it cost?
A fixed price agreed before we start, sized to the number of users and domains in your tenant. Ask us and you'll have a number the same day.

start a conversation

Find out where you actually stand.

A fixed-price Microsoft 365 security audit is the front door. You'll know exactly where you're exposed and what's worth fixing first. No scare tactics, no upsell to things you don't need.