Microsoft 365 audit scope
Every area we check, in plain English
A Microsoft 365 audit from SecureMyEmail assesses 112+ individual settings and controls across 11 categories — from who holds Global Admin to whether your audit log is even switched on. Each finding is risk-rated and mapped to the ACSC Essential Eight, the CIS Microsoft 365 Benchmark and your Privacy Act obligations.
On Google Workspace instead? See that scope →17 checks
Entra ID (Identity)
Accounts, admins, MFA coverage and stale identities.
See the checks →13 checks
Conditional Access
The policy engine that decides who gets in, from where.
See the checks →10 checks
Microsoft Defender
Anti-phishing, Safe Links, Safe Attachments and endpoint signal.
See the checks →10 checks
Exchange Online & Email Security
Mail flow, forwarding rules, SPF, DKIM and DMARC.
See the checks →10 checks
SharePoint & OneDrive
External sharing, guest resharing and data retention.
See the checks →8 checks
Microsoft Teams
External access, guest defaults and meeting controls.
See the checks →10 checks
Intune & Device Management
Compliance policies, encryption, patching and BYOD.
See the checks →9 checks
Shadow IT & OAuth App Governance
Connected apps, consent grants and unsanctioned SaaS.
See the checks →9 checks
Auditing, Logging & Alerting
Can you prove what happened after an incident?
See the checks →7 checks
Licensing & Cost Optimisation
Are you paying for security features you never switched on?
See the checks →9 checks
Secure Score & Compliance Baselines
How every finding maps to a recognised standard.
See the checks →Not sure which of these apply to you?
You don't need to. The audit runs the full set, and the report tells you what matters for a business your size — in order.
Get my Microsoft 365 audit