We value your privacy

We use cookies to analyze site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Audit and compliance
  2. Microsoft 365 security audit
Microsoft 365 security audit for US businesses

The evidence sits in your Microsoft 365 tenant. The question is how far back it goes.

Hardly any American company has ever checked how far back its audit log genuinely reaches, and the answer is very often a hundred and eighty days. That gets discovered mid-incident, or the afternoon an insurer or a SOC 2 auditor asks what happened eight months ago. We audit the tenant and tell you what you could actually prove.

Book a Microsoft 365 security auditSee what we examine
Microsoft 365 tenant security audit for US organizations
  • 180 daysThe default many tenants actually have
  • One yearOnly for E5 users, only some workloads
  • Tenant-wideIdentity, mail, data, devices
  • Evidence firstWhat you could prove, not just settings
What we examine

Eight areas of the tenant, ordered the way an attacker would care about them.

This is not a screenshot of the Secure Score. That score is a useful index to start from and it is evidence of nothing whatsoever. What matters is whether the controls are configured correctly for the way your company actually operates, and whether you could reconstruct events if somebody demanded it.

Identity, because that is where the compromise starts

Who holds an account, which of those accounts are dormant, which have never had multifactor enforced against them, how the administrators sign in, and whether any authentication route survives that cannot demand a second factor at all. Almost every compromise of a tenant starts with a credential rather than an exploit, which is why this section comes first.

Conditional Access, and the gaps between the policies

A policy list reads reassuringly while every bit of the risk lives in what it does not reach. Accounts excluded on a temporary basis three years ago, service accounts outside every policy you own, emergency accounts nobody watches and nobody has tested, and the particular combination of conditions leaving one route open. We read them as a set rather than one by one, because a set is how an attacker meets them.

Privileged roles and standing access

How many people hold a privileged role, whether that access is permanent or activated at the moment it is needed, whether anybody ever reviews it, and who granted it originally. The number of Global Administrators in the tenants we assess is consistently higher than anybody in the room expects, almost always because a consultant, a departed employee or a vendor was handed the role during a project and nobody took it back afterward.

Audit log retention, which is the one nobody has checked

Mail, SharePoint, OneDrive and directory audit records are retained for a year under the premium audit default, and only for people licensed at E5. Everything else, along with every non-E5 account and every guest, defaults to a hundred and eighty days. Most companies have no idea which applies to them until an investigation needs to see further back than the log reaches. This is, reliably, the single most valuable finding we produce.

Mail flow, forwarding rules, and what leaves the tenant

Transport rules, connectors, forwarding to outside addresses, and the mailbox rules quietly filing messages into a folder nobody has ever opened. Business email compromise is overwhelmingly about payment fraud, and the mechanism is nearly always a forwarding or filing rule created within hours of somebody reaching the mailbox. We look for the ones sitting there today and, separately, for whether anybody would notice a new one appearing tomorrow.

Data, sharing, and what is exposed by accident

The sharing settings across SharePoint and OneDrive, links that will never expire, anonymous access, guests reaching sites, and wherever sensitive material has ended up outside the company without a single person intending it. What we find here is almost never a deliberate act. It is several years of individually reasonable decisions that nobody has ever stood back and looked at together.

Devices, and whether compliance actually gates access

Which devices are actually enrolled, whether their compliance state is wired into access decisions or merely displayed on a dashboard, and how many machines reach company data under no management whatsoever. Marking a device non-compliant while continuing to let it open the mailbox is an extremely common arrangement, and it means the control is informational rather than protective.

Guests, external identities, and third parties

Guest accounts pile up in every tenant that has been running a while. A contractor from a project that ended in 2022, a client contact who changed employer, a vendor somebody invited once for a single meeting. Every one is a credential you do not control with a route into your data. We inventory them, work out which are still live, and put a review rhythm in place, because nobody has ever removed a guest account without being prompted to.

Check this before you need it

You may hold a hundred and eighty days of evidence while believing you hold a year.

This is precise, it is checkable in the documentation, and it catches companies out at the worst conceivable moment. Every number below is a published default rather than our estimate of one.

  • The premium default keeps mail, SharePoint, OneDrive and directory records for a year. Everything else falls back to a hundred and eighty days. So even at the higher licensing level, a full year of history is not what you hold across the board. It is what you hold for four workloads and nothing else.
  • That year applies only to activity by somebody holding an E5 license, or the Purview Suite, or the discovery and audit add-on. Anybody without one, and every guest account, has their records kept for a hundred and eighty days. Mixed licensing is entirely normal in American companies, which means your retention is mixed too, and it varies person by person.
  • The standard default is a hundred and eighty days. It used to be ninety, and anything generated before 17 October 2023 is still held on that older basis. If your last audit was written against the old number, it is now wrong.
  • Here is the trap almost everybody misses. A custom retention policy takes precedence over the default, and that includes a custom policy shorter than the default. A company can have quietly cut its own retention below what it was entitled to, with nobody ever connecting that setting to the investigation it will eventually make impossible. We check which policies actually exist rather than what the licensing entitles you to.
Ask us how far back your tenant genuinely reaches
How we audit

Four things separating a genuine audit from a screenshot of the Secure Score.

Anybody can export a configuration report in about four minutes. The value lies in knowing which settings genuinely matter for your company, which findings are noise, and what you could actually prove afterward.

The tenant gets audited as it is configured rather than against a generic baseline

A generic baseline produces two hundred findings, most of them irrelevant to you, and the five that matter disappear among the rest. We establish how your company genuinely operates first, then report what creates real exposure in that specific context. A short report somebody acts on beats a comprehensive one that goes straight into a folder.

You get told what you could actually evidence, not merely what is switched on

The only question that matters after an incident is what you can reconstruct. That depends on the retention policies, on the licensing held by each individual person, and on whether anybody has ever successfully run a search. All three get checked, and we run a genuine historical query so you know the capability works long before the day you need it.

We do not recommend license upgrades reflexively

Answering every finding with a suggestion to move up to E5 is easy, and occasionally it is genuinely the right call, particularly where audit retention or investigation capability is the actual gap. Far more often it is not, and the same risk closes using configuration you already paid for. The two get separated clearly in the report, so you can see at a glance which findings cost money and which merely cost attention.

We hand you findings your team can work

Every finding says what it is, why it matters given how you operate, what to change, and roughly what that will take. Your own team can carry it out or we can, and either is genuinely fine by us. What we will not produce is a report that requires us to explain it to you, because that is a dependency dressed up as a deliverable.

When organizations ask for this

Six situations that bring US businesses to a tenant audit.

Whatever prompted the audit shapes what it covers. One driven by a customer questionnaire looks nothing like one driven by a suspected compromise, and the scope follows the reason rather than us running an identical engagement every time.

A customer or cyber insurer has sent a security questionnaire

Far and away the most common reason people call. Somebody has to answer specific questions about multifactor, about access control, about logging and about how data is handled, and nobody inside the company knows the current state well enough to answer honestly. Insurance applications carry particular weight, because a claim can hinge on whether those answers were accurate. An audit produces them, and more usefully tells you which ones to go and fix before you answer at all.

After a suspicious email or a suspected compromise

A payment came close to going somewhere it should not have, a mailbox did something strange, or somebody received a message apparently from a colleague sitting ten feet away. The immediate question is what actually happened, and the answer depends entirely on what your audit log kept. This is where companies discover their retention position for the first time, and by then it is far too late to change it.

A financial firm with regulatory obligations

GLBA and the FTC Safeguards Rule both expect access control, logging and a genuine ability to investigate, and under NYDFS Part 500 those expectations are spelled out explicitly. For a typical firm, Microsoft 365 is where nearly all of that evidence lives. The retention question matters unusually here, because the period an examiner may ask you about is very often longer than the period your tenant retains anything by default.

A business that has changed IT provider

Somebody new inherits a tenant configured by whoever came before, complete with administrator accounts, applications granted consent years ago, and access policy exclusions whose reasons nobody can now recall. An independent audit at the point of handover establishes a baseline, and very often removes access that should have disappeared the day the previous relationship ended.

An organization with HIPAA or state privacy obligations

Healthcare organizations and their business associates, alongside anybody in scope of CCPA, CPRA or one of the other state privacy laws. Here the audit concentrates on where personal data physically sits, who can reach it, what has already been shared outside the company, and whether you could evidence who accessed what if a patient, a consumer or a regulator asked you to.

A company that has simply never looked

The healthiest reason of all, and easily the rarest. The tenant has run for years, people have joined and left, projects have come and gone, and somebody sensibly wants to know what condition it is in. These audits almost always turn up several things worth fixing and almost never turn up a crisis, which is precisely the outcome looking early is supposed to produce.

Three tenant positions

What typically turns up when we audit one of these tenants.

The middle column is by a considerable margin the most common. Somebody set the tenant up competently at some point, then five years of staff turnover, projects and consultants happened on top of it, and nobody ever stood back and looked at the whole thing again.
Global Administrator count controlled
Audited and maintainedFew, reviewed
Set up once, then driftedGrown quietly
Defaults, largely untouchedWhoever asked
MFA enforced on all privileged accounts
Audited and maintained
Set up once, then driftedMostly
Defaults, largely untouchedPartially
Conditional Access exclusions justified
Audited and maintained
Set up once, then driftedForgotten
Defaults, largely untouchedNone exist
Audit retention known and deliberate
Audited and maintained
Set up once, then drifted
Defaults, largely untouched
External forwarding controlled
Audited and maintained
Set up once, then driftedSometimes
Defaults, largely untouched
Guest accounts reviewed
Audited and maintained
Set up once, then drifted
Defaults, largely untouched
Device compliance gates access
Audited and maintained
Set up once, then driftedReported only
Defaults, largely untouched
Third-party app consent governed
Audited and maintained
Set up once, then drifted
Defaults, largely untouched
Could reconstruct an incident from last year
Audited and maintainedProbably
Set up once, then driftedOnly within 180 days
Defaults, largely untouchedUnlikely
How common among US small and mid-size tenants
Audited and maintainedUncommon
Set up once, then driftedThe default
Defaults, largely untouchedSmaller firms
Feature
Audited and maintained
Set up once, then drifted
Defaults, largely untouched
Global Administrator count controlled
Few, reviewedGrown quietlyWhoever asked
MFA enforced on all privileged accounts
MostlyPartially
Conditional Access exclusions justified
ForgottenNone exist
Audit retention known and deliberate
External forwarding controlled
Sometimes
Guest accounts reviewed
Device compliance gates access
Reported only
Third-party app consent governed
Could reconstruct an incident from last year
ProbablyOnly within 180 daysUnlikely
How common among US small and mid-size tenants
UncommonThe defaultSmaller firms
What you can actually prove

What audit evidence a tenant holds by default, and for how long.

Every figure below is a published default for audit retention. Any custom policy somebody has created overrides these in either direction, which is exactly why an audit reads the policies rather than reading the license entitlement.

Situation

Audit Standard, logs on or after October 17, 2023

Default retention
180 days

Situation

Audit Standard, logs before October 17, 2023

Default retention
90 days

Situation

Audit Premium, Exchange Online records, E5 user

Default retention
One year

Situation

Audit Premium, SharePoint and OneDrive, E5 user

Default retention
One year

Situation

Audit Premium, Microsoft Entra records, E5 user

Default retention
One year

Situation

Audit Premium, all other activities

Default retention
180 days by default

Situation

Any activity by a non-E5 user

Default retention
180 days

Situation

Any activity by a guest user

Default retention
180 days

Situation

With the ten year retention add-on on top of E5

Default retention
Up to 10 years

Situation

A custom policy shorter than the default

Default retention
The shorter custom policy wins

Situation

Maximum retention policies per organization

Default retention
50
SituationDefault retention
Audit Standard, logs on or after October 17, 2023180 days
Audit Standard, logs before October 17, 202390 days
Audit Premium, Exchange Online records, E5 userOne year
Audit Premium, SharePoint and OneDrive, E5 userOne year
Audit Premium, Microsoft Entra records, E5 userOne year
Audit Premium, all other activities180 days by default
Any activity by a non-E5 user180 days
Any activity by a guest user180 days
With the ten year retention add-on on top of E5Up to 10 years
A custom policy shorter than the defaultThe shorter custom policy wins
Maximum retention policies per organization50
How the audit runs

Five stages, typically one to two weeks.

All of it runs remotely, almost entirely read-only, and nobody using the systems notices a thing. What we need is access scoped properly and a short conversation about how your company genuinely operates, because that conversation is what determines which findings matter and which are noise.
  1. 1

    Scope, access, and context

    Establishing what is in scope, what read access is needed and how it gets granted, and then a conversation about how the business really runs. Who travels, who works from their own phone, which outside parties hold access, and what is actually driving the compliance requirement. Findings are worthless without that context, because whether a given setting constitutes a risk depends entirely on what your people do all day.

  2. 2

    Identity and access review

    The accounts themselves, who holds a privileged role, which authentication methods are in play, the access policies read as a set rather than as a list, the dormant accounts, the guests, and every application anybody ever granted consent to. This stage produces the highest severity findings in most tenants, and it is where the most time goes.

  3. 3

    Data, mail, and device review

    How sharing is configured alongside what is actually shared outside the company right now, the mail flow rules and forwarding, the connectors, and whether device compliance has any bearing on access at all. We look at what exists today rather than only at what policy would permit, because the distance between those two things is nearly always where the finding lives.

  4. 4

    Evidence and retention check

    What your retention genuinely is, worked out per license and per custom policy, plus a real historical search run to confirm the capability functions at all. You get told how far back you can actually see, which very often differs from what everybody believed, and it is the finding clients most often say afterward that they were glad to have received.

  5. 5

    Report, prioritize, and fix

    The findings ordered by severity, each carrying the context that makes it severe, and split between what costs configuration effort and what would cost money. Then the remediation itself, carried out by your team or by ours, and we are genuinely content with either. Where you want it, we audit again afterward so the improvement is documented rather than assumed.

Straight answers

What organizations ask about a Microsoft 365 audit.

That depends on your licensing and on any custom policies somebody created, and the honest answer for most companies is considerably less far than they assume. Under the premium default, mail, SharePoint, OneDrive and directory records are kept for a year, though only for people holding an E5 license or an equivalent add-on. Everything else defaults to a hundred and eighty days, and anybody without E5, along with every guest, is held to a hundred and eighty days regardless. The standard default is also a hundred and eighty days. So a tenant with mixed licensing has mixed retention, varying person by person.

It is a genuinely useful index and it is not an audit. That score is calculated against a baseline knowing nothing about your business, so it hands out points for controls you may have no need of while remaining entirely blind to the one misconfiguration capable of hurting you. We have audited tenants carrying strong scores alongside a single access policy exclusion that rendered most of the policy set meaningless. Use it to track direction over time, never to answer whether you are secure.

No. The review is read-only and nobody using the systems notices anything at all. What can be disruptive is the remediation afterward, particularly anything touching authentication, which is exactly why the two are kept separate and changes get planned with you rather than applied mid-audit. If something genuinely urgent surfaces, an indicator of active compromise for instance, you hear about it that hour rather than in the report three weeks later.

No, and implying otherwise would be doing you a disservice. A well-configured tenant on modest licensing is meaningfully more secure than a badly configured one on E5, and most of the highest severity findings we produce concern configuration rather than capability. Where E5 genuinely earns its place is in investigation and evidence: longer retention across the workloads that matter, and the tooling to work an incident properly rather than approximately. If you are regulated or holding sensitive data, that is a real argument. If you are neither, configuration comes first.

Directly, because those three processes ask the same tenant-level questions: is MFA enforced everywhere, who has admin access and why, how are leavers offboarded, how long are audit logs retained, and who outside the company can reach your data. The audit answers each with evidence rather than optimism, and it tells you which answers to fix before you submit the questionnaire. We are an IT services firm, not an auditor or a law firm, so your compliance advisors own the interpretation; we own the controls and the evidence.

Few, and every one of them for a reason somebody can state. There is no universal number, but the pattern we find is consistent: the count grows because a consultant needed it during a project, a vendor asked for it, or someone was granted it to solve a problem quickly, and nothing removes it afterwards. Along with the count, the questions worth asking are whether that access is permanent or activated when needed, whether it is reviewed, and whether every one of those accounts has multi-factor authentication genuinely enforced.

Conditional Access with exclusions that nobody can justify. The policy set looks robust in a list, and then a service account, a break-glass account that was never tested, or an exception created for one person during a trip turns out to sit outside all of it. The second most common is external mail forwarding being possible and unmonitored, which is the mechanism behind most business email compromise losses. Neither costs money to fix.

Yes, within limits set by licensing. You can create custom audit log retention policies, up to fifty per organization, and there is a ten-year option where you hold the ten-year audit log retention add-on alongside E5. Creating or changing one requires the Organization Configuration role. The important caveat is that custom policies take priority over the default in both directions, so a custom policy shorter than the default silently reduces what you retain, which we check for specifically.

We tell you immediately rather than putting it in the report, and we stop and agree the next step with you before doing anything that could destroy evidence. Preserving what the tenant still holds becomes the priority, which is time-sensitive precisely because of the retention limits discussed on this page. Depending on what we find, that may mean an incident response engagement rather than continuing the audit, and we would say so plainly rather than continuing to bill an audit around a live problem.

They can, and there is a reason to prefer an independent review: your provider configured the tenant, so an audit by them is an assessment of their own work. That is not an accusation of bad faith, it is a structural problem that applies to any provider including us where we run the estate. Where we manage a client tenant, we say plainly that our audit is not independent and we are comfortable with a third party reviewing it.

They accumulate in every tenant more than a year or two old, and almost nobody removes them without a prompt. A contractor from a project that finished, a client contact who has changed employer, a vendor invited once for a file transfer. Each is a credential outside your control with a path into your data, and their audit records are retained for 180 days regardless of your licensing. We inventory them, identify which are live and which are dormant, and put a review cadence in place.

A tenant drifts continuously, because people join and leave, projects grant access, and Microsoft changes defaults. Annually is a reasonable cadence for most organizations, with an additional review after a significant change such as a merger, a change of IT provider, or a large migration. What matters more than frequency is that the second audit is comparable to the first, so it measures whether anything actually improved rather than restating a fresh set of opinions. Commercially, the engagement is scoped per organization: user count, services in scope, and whether remediation is included.
Tenant health check

Fifteen things worth checking in your own tenant before Friday.

Most of these you can work through without us, and we would far rather you did than leave them unexamined. The first block covers identity, the second covers what leaves the tenant, and the third asks whether you could evidence any of it afterward.

Identity, where it starts

  • How many accounts hold Global Administrator?
    The real number is almost always higher than whatever anybody says off the top of their head.
  • Is multifactor genuinely enforced against every single one?
    Enforced, not enabled, not encouraged.
  • Are there accounts excluded from Conditional Access?
    Check why, and whether the reason still exists.
  • Do emergency accounts exist, and has anybody ever signed into one?
    Untested emergency access is not emergency access.
  • How many accounts have gone ninety days without a single sign-in?
    Each one is a live credential nobody is watching.

What leaves the tenant

  • Is external mail forwarding blocked or monitored?
    The classic business email compromise mechanism.
  • Are there mailbox rules quietly filing mail into folders nobody opens?
    Worth looking at directly, not just in policy.
  • Can users create anonymous sharing links that never expire?
    Check the setting and check what already exists.
  • How many guest accounts exist, and who owns each?
    They accumulate and nobody removes them unprompted.
  • Which third-party applications have consent in your tenant?
    Consented apps are a standing access path.

Could you evidence it

  • How far back does your audit log actually reach?
    Check the retention policies, not the license brochure.
  • Do custom retention policies exist, and is any one of them shorter than the default?
    Custom policies override the default in both directions.
  • Are all your users E5, or is licensing mixed?
    Retention is per user. Mixed licensing means mixed evidence.
  • Has anybody ever run a real audit log search?
    The first time should not be during an incident.
  • Is device compliance connected to access, or only reported?
    Reported non-compliance changes nothing on its own.
Related reading

The pages around this one.

Cybersecurity audit and compliance

The wider audit practice, and how to tell which kind of engagement your situation actually calls for.

Learn more

Microsoft Entra

The identity layer underneath everything on this page: Conditional Access, privileged access, and the controls that close the findings we most often report.

Learn more

Tenant security baseline

The written, enforced security configuration that keeps the tenant hardened after the audit closes its findings.

Learn more
Next step

Go and check how far back your audit log reaches.

It takes a few minutes, it is free, and for most organizations the answer is different from what they assumed. If you would like help checking it, or a full review of the tenant behind it, that is a short conversation and we will tell you what we would look at first.

Book a Microsoft 365 security auditSee the audit practice

Related Services

Explore more solutions that work great with this service

Google Workspace Security Audit

Google Workspace security audit for US organizations worked through

Learn more

Email Security Audit

Email security audits for US organizations: sending domain inventory

Learn more

Active Directory Security Audit

On-premises Active Directory security audit for US organizations:

Learn more

Microsoft Entra

Identity and access management solutions

Learn more

Tenant Security Baseline

Documented controls mapped to CIS

Learn more
GR IT SERVICES

IT services for US businesses,
delivering enterprise-grade solutions
remotely, coast to coast.

Microsoft CSP PartnerApple Jamf PartnerCISGuard

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support USA
  • IT AMC USA
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • hello@gritservices.io
  • gritservices.io

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie PolicyCCPA/CPRA