First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/Microsoft 365 Security Audit - Baseline
Security and Protection

Microsoft 365 Security Audit — Baseline: Identify Security Risks & Remediation Priorities

The Microsoft 365 tenant basic security audit is a 3-day service that helps organizations review their Microsoft 365 tenant security settings, configurations, policies, users, and applications to identify potential vulnerabilities and ensure the tenant is properly secured against external threats.

Timeline 3 daysService owner Dan ApplebyOffice 365microsoft 365

What this engagement is

This service helps organizations assess the security posture of their Microsoft 365 tenant. IT Partner collects data from tenant configurations, policies, users, and applications in use; conducts a comprehensive security assessment; provides a detailed report of findings; and delivers a prioritized remediation plan, reviewing it with the client and advising on how to address the identified vulnerabilities. Hands-on remediation can be scoped separately.

Success criteria

01The Microsoft 365 tenant security assessment has been completed and the findings report delivered.
02Identified vulnerabilities have been prioritized.
03A remediation plan has been delivered and reviewed with the client.

What you receive

Detailed report outlining the findings of the security assessment.
Remediation plan.

How the work unfolds

Kickoff meeting.

Start the engagement with the client.

Conduct Microsoft 365 tenant security assessment.

Assess the Microsoft 365 tenant security configuration.

Analyze assessment data and prioritize vulnerabilities.

Review assessment data and prioritize identified vulnerabilities.

Develop a remediation plan.

Create a remediation plan based on the assessment.

Prerequisites

Access to the Microsoft 365 tenant environment, including all relevant applications and services.
A dedicated point of contact responsible for working with IT Partner and coordinating any outside vendor resources and schedules.

Who does what

IT Partner

  • Collect data from Microsoft 365 tenant configurations, policies, users, and applications in use.
  • Conduct a comprehensive security assessment of the Microsoft 365 tenant.
  • Provide a detailed report outlining the findings of the security assessment.
  • Review the findings and remediation plan with the client and advise on addressing the identified vulnerabilities (hands-on remediation is scoped separately).

Your team

  • Provide access to the Microsoft 365 tenant environment, including all relevant applications and services.
  • Provide a dedicated point of contact responsible for working with our team and coordinating any outside vendor resources and schedules.

What's not included

Hands-on implementation of all remediation items, broad configuration changes, or policy deployments beyond the assessment and remediation planning scope, unless separately agreed.
24/7 support, continuous monitoring, ongoing maintenance, managed security monitoring, security operations center services, alert triage, or incident response retainers are not included by default; these are available as optional extra-cost add-ons delivered through IT Partner's NOC, third-party support partnerships, and a Microsoft Premier Support agreement.
Penetration testing, phishing simulations, red-team exercises, or exploit-based vulnerability validation.
Full endpoint, server, network, firewall, or on-premises Active Directory security audits outside the Microsoft 365 tenant review scope.
Compliance certification, legal attestation, formal risk acceptance documentation, or audit representation for regulatory bodies.
Microsoft licensing costs, third-party security tools, add-on subscriptions, or remediation work requiring products not already available in the client tenant.
Custom application code review, third-party SaaS security assessment, or remediation of external applications integrated with Microsoft 365.

Frequently asked questions

What is the Microsoft 365 tenant basic security audit?

The Microsoft 365 tenant basic security audit is a 3-day service that reviews an organization’s Microsoft 365 tenant security settings, configurations, policies, users, and applications. The goal is to identify potential vulnerabilities and help ensure the tenant is configured securely against external threats.

What is included in the Microsoft 365 tenant basic security audit?

The service includes data collection from Microsoft 365 tenant configurations, policies, users, and applications in use, followed by a security assessment of the tenant. IT Partner then analyzes the findings, prioritizes identified vulnerabilities, and prepares a detailed security audit report and remediation plan.

What deliverables will we receive from the audit?

The deliverables are a detailed report outlining the findings of the Microsoft 365 tenant security assessment and a remediation plan. These documents summarize identified vulnerabilities and provide a prioritized path for addressing them.

How long does the Microsoft 365 tenant basic security audit take?

The Microsoft 365 tenant basic security audit is delivered over 3 days. The engagement includes kickoff, assessment, analysis and prioritization of vulnerabilities, and development of the remediation plan.

How much does the Microsoft 365 tenant basic security audit cost?

The Microsoft 365 tenant basic security audit is priced at $525 per project. Project work is quoted fixed-price in writing before work begins, and you pay after you approve delivery. If your environment has unusual requirements or you need services beyond the stated audit scope, confirm any additional cost considerations with IT Partner before starting.

What Microsoft products does this audit cover?

This audit is focused on Microsoft 365 and Office 365 tenant security. It reviews relevant tenant configurations, policies, users, applications, and services that are available within the client’s Microsoft 365 environment.

What happens during the kickoff meeting?

The kickoff meeting starts the engagement with the client and aligns the work between IT Partner and the client’s point of contact. It is used to coordinate access, schedules, and the audit process before the Microsoft 365 tenant security assessment begins.

What are the main steps in the audit process?

The audit process begins with a kickoff meeting, followed by a Microsoft 365 tenant security assessment. IT Partner then analyzes the assessment data, prioritizes vulnerabilities, and develops a remediation plan based on the findings.

What prerequisites are required before the audit can begin?

The client must provide access to the Microsoft 365 tenant environment, including all relevant applications and services. The client must also assign a dedicated point of contact to work with IT Partner and coordinate any outside vendor resources or schedules.

What access does IT Partner need for the Microsoft 365 security audit?

IT Partner needs access to the Microsoft 365 tenant environment, including relevant applications and services, because the audit depends on reviewing tenant configurations, policies, users, and applications in use. The exact access method and permissions should be coordinated with IT Partner during kickoff. IT Partner requests granular, time-bound admin access (GDAP) that you approve — never standing global admin.

Who is responsible for what during the audit?

IT Partner is responsible for collecting tenant data, conducting the security assessment, preparing the findings report, and working with the client on identified vulnerabilities. The client is responsible for providing tenant access and a dedicated point of contact to coordinate schedules and any outside vendor resources.

Will the audit cause downtime or interrupt Microsoft 365 users?

The stated scope is an assessment of Microsoft 365 tenant configurations, policies, users, and applications, so the service is primarily review and analysis work. The service description does not specify expected downtime or user interruption; confirm any environment-specific business impact with IT Partner before the engagement.

Does the service include fixing the vulnerabilities found in the audit?

No. The audit delivers a findings report and a prioritized remediation plan, and IT Partner reviews both with you and advises on how to address the identified vulnerabilities. Hands-on remediation is not included in the 3-day audit and can be scoped separately with IT Partner.

What happens after the security audit is completed?

After the audit, the client receives a detailed findings report and a remediation plan. The success criterion for the engagement is that the security audit report has been prepared, and the remediation plan can then guide follow-up security improvements.

Does the audit provide a prioritized list of security issues?

Yes, the engagement includes analyzing assessment data and prioritizing identified vulnerabilities. This prioritization is used to develop the remediation plan based on the Microsoft 365 tenant security assessment.

Is this service suitable for organizations that already use Microsoft 365 but are unsure whether it is secure?

Yes, this service is designed to assess the security posture of an existing Microsoft 365 tenant. It is especially relevant when an organization wants an expert review of tenant settings, policies, users, and applications to identify potential vulnerabilities.

What is not included in the Microsoft 365 tenant basic security audit?

24/7 support, continuous monitoring, ongoing maintenance, managed security monitoring, security operations center services, alert triage, and incident response retainers are not included by default. They are available as optional extra-cost add-ons delivered through IT Partner's NOC, third-party support partnerships, and a Microsoft Premier Support agreement. Buyers should also confirm with IT Partner whether activities such as extensive remediation implementation, third-party security tooling, or compliance certification are included if those items are required.

Does the audit guarantee that our Microsoft 365 tenant will be fully secure?

No guarantee is stated in the service scope. The audit helps identify potential vulnerabilities, provides a findings report and remediation plan, and supports secure configuration, but security outcomes also depend on the client’s environment and follow-through on remediation.

Can the audit include applications and services connected to our Microsoft 365 tenant?

Yes, the stated prerequisites and responsibilities include access to all relevant applications and services in the Microsoft 365 tenant environment. IT Partner collects data from tenant configurations, policies, users, and applications in use as part of the assessment.

Who manages the Microsoft 365 tenant basic security audit engagement?

The service information lists Dan Appleby as the manager for the Microsoft 365 tenant basic security audit. During the engagement, the client should still provide a dedicated point of contact to coordinate with IT Partner and any outside vendor resources.

How is this baseline audit different from the Microsoft 365 Advanced Security Audit (SCuBA)?

The baseline audit is a 3-day expert review of tenant security settings, policies, users, and applications that produces a findings report and remediation plan. The Advanced Security Audit tests the tenant against the secure configuration baselines published by CISA's Secure Cloud Business Applications (SCuBA) project over 10 days. Choose the baseline audit for a fast, broad review; choose the SCuBA audit for a deeper, baseline-by-baseline compliance assessment.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$525 per project
3 days
Book a meeting