The evidence sits in your Microsoft 365 tenant. The question is how far back it goes.
Hardly any American company has ever checked how far back its audit log genuinely reaches, and the answer is very often a hundred and eighty days. That gets discovered mid-incident, or the afternoon an insurer or a SOC 2 auditor asks what happened eight months ago. We audit the tenant and tell you what you could actually prove.

- 180 daysThe default many tenants actually have
- One yearOnly for E5 users, only some workloads
- Tenant-wideIdentity, mail, data, devices
- Evidence firstWhat you could prove, not just settings
Eight areas of the tenant, ordered the way an attacker would care about them.
Identity, because that is where the compromise starts
Who holds an account, which of those accounts are dormant, which have never had multifactor enforced against them, how the administrators sign in, and whether any authentication route survives that cannot demand a second factor at all. Almost every compromise of a tenant starts with a credential rather than an exploit, which is why this section comes first.
Conditional Access, and the gaps between the policies
A policy list reads reassuringly while every bit of the risk lives in what it does not reach. Accounts excluded on a temporary basis three years ago, service accounts outside every policy you own, emergency accounts nobody watches and nobody has tested, and the particular combination of conditions leaving one route open. We read them as a set rather than one by one, because a set is how an attacker meets them.
Privileged roles and standing access
How many people hold a privileged role, whether that access is permanent or activated at the moment it is needed, whether anybody ever reviews it, and who granted it originally. The number of Global Administrators in the tenants we assess is consistently higher than anybody in the room expects, almost always because a consultant, a departed employee or a vendor was handed the role during a project and nobody took it back afterward.
Audit log retention, which is the one nobody has checked
Mail, SharePoint, OneDrive and directory audit records are retained for a year under the premium audit default, and only for people licensed at E5. Everything else, along with every non-E5 account and every guest, defaults to a hundred and eighty days. Most companies have no idea which applies to them until an investigation needs to see further back than the log reaches. This is, reliably, the single most valuable finding we produce.
Mail flow, forwarding rules, and what leaves the tenant
Transport rules, connectors, forwarding to outside addresses, and the mailbox rules quietly filing messages into a folder nobody has ever opened. Business email compromise is overwhelmingly about payment fraud, and the mechanism is nearly always a forwarding or filing rule created within hours of somebody reaching the mailbox. We look for the ones sitting there today and, separately, for whether anybody would notice a new one appearing tomorrow.
Data, sharing, and what is exposed by accident
The sharing settings across SharePoint and OneDrive, links that will never expire, anonymous access, guests reaching sites, and wherever sensitive material has ended up outside the company without a single person intending it. What we find here is almost never a deliberate act. It is several years of individually reasonable decisions that nobody has ever stood back and looked at together.
Devices, and whether compliance actually gates access
Which devices are actually enrolled, whether their compliance state is wired into access decisions or merely displayed on a dashboard, and how many machines reach company data under no management whatsoever. Marking a device non-compliant while continuing to let it open the mailbox is an extremely common arrangement, and it means the control is informational rather than protective.
Guests, external identities, and third parties
Guest accounts pile up in every tenant that has been running a while. A contractor from a project that ended in 2022, a client contact who changed employer, a vendor somebody invited once for a single meeting. Every one is a credential you do not control with a route into your data. We inventory them, work out which are still live, and put a review rhythm in place, because nobody has ever removed a guest account without being prompted to.
You may hold a hundred and eighty days of evidence while believing you hold a year.
This is precise, it is checkable in the documentation, and it catches companies out at the worst conceivable moment. Every number below is a published default rather than our estimate of one.
- The premium default keeps mail, SharePoint, OneDrive and directory records for a year. Everything else falls back to a hundred and eighty days. So even at the higher licensing level, a full year of history is not what you hold across the board. It is what you hold for four workloads and nothing else.
- That year applies only to activity by somebody holding an E5 license, or the Purview Suite, or the discovery and audit add-on. Anybody without one, and every guest account, has their records kept for a hundred and eighty days. Mixed licensing is entirely normal in American companies, which means your retention is mixed too, and it varies person by person.
- The standard default is a hundred and eighty days. It used to be ninety, and anything generated before 17 October 2023 is still held on that older basis. If your last audit was written against the old number, it is now wrong.
- Here is the trap almost everybody misses. A custom retention policy takes precedence over the default, and that includes a custom policy shorter than the default. A company can have quietly cut its own retention below what it was entitled to, with nobody ever connecting that setting to the investigation it will eventually make impossible. We check which policies actually exist rather than what the licensing entitles you to.
Four things separating a genuine audit from a screenshot of the Secure Score.
The tenant gets audited as it is configured rather than against a generic baseline
A generic baseline produces two hundred findings, most of them irrelevant to you, and the five that matter disappear among the rest. We establish how your company genuinely operates first, then report what creates real exposure in that specific context. A short report somebody acts on beats a comprehensive one that goes straight into a folder.
You get told what you could actually evidence, not merely what is switched on
The only question that matters after an incident is what you can reconstruct. That depends on the retention policies, on the licensing held by each individual person, and on whether anybody has ever successfully run a search. All three get checked, and we run a genuine historical query so you know the capability works long before the day you need it.
We do not recommend license upgrades reflexively
Answering every finding with a suggestion to move up to E5 is easy, and occasionally it is genuinely the right call, particularly where audit retention or investigation capability is the actual gap. Far more often it is not, and the same risk closes using configuration you already paid for. The two get separated clearly in the report, so you can see at a glance which findings cost money and which merely cost attention.
We hand you findings your team can work
Every finding says what it is, why it matters given how you operate, what to change, and roughly what that will take. Your own team can carry it out or we can, and either is genuinely fine by us. What we will not produce is a report that requires us to explain it to you, because that is a dependency dressed up as a deliverable.
Six situations that bring US businesses to a tenant audit.
A customer or cyber insurer has sent a security questionnaire
Far and away the most common reason people call. Somebody has to answer specific questions about multifactor, about access control, about logging and about how data is handled, and nobody inside the company knows the current state well enough to answer honestly. Insurance applications carry particular weight, because a claim can hinge on whether those answers were accurate. An audit produces them, and more usefully tells you which ones to go and fix before you answer at all.
After a suspicious email or a suspected compromise
A payment came close to going somewhere it should not have, a mailbox did something strange, or somebody received a message apparently from a colleague sitting ten feet away. The immediate question is what actually happened, and the answer depends entirely on what your audit log kept. This is where companies discover their retention position for the first time, and by then it is far too late to change it.
A financial firm with regulatory obligations
GLBA and the FTC Safeguards Rule both expect access control, logging and a genuine ability to investigate, and under NYDFS Part 500 those expectations are spelled out explicitly. For a typical firm, Microsoft 365 is where nearly all of that evidence lives. The retention question matters unusually here, because the period an examiner may ask you about is very often longer than the period your tenant retains anything by default.
A business that has changed IT provider
Somebody new inherits a tenant configured by whoever came before, complete with administrator accounts, applications granted consent years ago, and access policy exclusions whose reasons nobody can now recall. An independent audit at the point of handover establishes a baseline, and very often removes access that should have disappeared the day the previous relationship ended.
An organization with HIPAA or state privacy obligations
Healthcare organizations and their business associates, alongside anybody in scope of CCPA, CPRA or one of the other state privacy laws. Here the audit concentrates on where personal data physically sits, who can reach it, what has already been shared outside the company, and whether you could evidence who accessed what if a patient, a consumer or a regulator asked you to.
A company that has simply never looked
The healthiest reason of all, and easily the rarest. The tenant has run for years, people have joined and left, projects have come and gone, and somebody sensibly wants to know what condition it is in. These audits almost always turn up several things worth fixing and almost never turn up a crisis, which is precisely the outcome looking early is supposed to produce.
What typically turns up when we audit one of these tenants.
| Feature | Audited and maintained | Set up once, then drifted | Defaults, largely untouched |
|---|---|---|---|
Global Administrator count controlled | Few, reviewed | Grown quietly | Whoever asked |
MFA enforced on all privileged accounts | Mostly | Partially | |
Conditional Access exclusions justified | Forgotten | None exist | |
Audit retention known and deliberate | |||
External forwarding controlled | Sometimes | ||
Guest accounts reviewed | |||
Device compliance gates access | Reported only | ||
Third-party app consent governed | |||
Could reconstruct an incident from last year | Probably | Only within 180 days | Unlikely |
How common among US small and mid-size tenants | Uncommon | The default | Smaller firms |
What audit evidence a tenant holds by default, and for how long.
Situation
Audit Standard, logs on or after October 17, 2023
- Default retention
- 180 days
Situation
Audit Standard, logs before October 17, 2023
- Default retention
- 90 days
Situation
Audit Premium, Exchange Online records, E5 user
- Default retention
- One year
Situation
Audit Premium, SharePoint and OneDrive, E5 user
- Default retention
- One year
Situation
Audit Premium, Microsoft Entra records, E5 user
- Default retention
- One year
Situation
Audit Premium, all other activities
- Default retention
- 180 days by default
Situation
Any activity by a non-E5 user
- Default retention
- 180 days
Situation
Any activity by a guest user
- Default retention
- 180 days
Situation
With the ten year retention add-on on top of E5
- Default retention
- Up to 10 years
Situation
A custom policy shorter than the default
- Default retention
- The shorter custom policy wins
Situation
Maximum retention policies per organization
- Default retention
- 50
Five stages, typically one to two weeks.
- 1
Scope, access, and context
Establishing what is in scope, what read access is needed and how it gets granted, and then a conversation about how the business really runs. Who travels, who works from their own phone, which outside parties hold access, and what is actually driving the compliance requirement. Findings are worthless without that context, because whether a given setting constitutes a risk depends entirely on what your people do all day.
- 2
Identity and access review
The accounts themselves, who holds a privileged role, which authentication methods are in play, the access policies read as a set rather than as a list, the dormant accounts, the guests, and every application anybody ever granted consent to. This stage produces the highest severity findings in most tenants, and it is where the most time goes.
- 3
Data, mail, and device review
How sharing is configured alongside what is actually shared outside the company right now, the mail flow rules and forwarding, the connectors, and whether device compliance has any bearing on access at all. We look at what exists today rather than only at what policy would permit, because the distance between those two things is nearly always where the finding lives.
- 4
Evidence and retention check
What your retention genuinely is, worked out per license and per custom policy, plus a real historical search run to confirm the capability functions at all. You get told how far back you can actually see, which very often differs from what everybody believed, and it is the finding clients most often say afterward that they were glad to have received.
- 5
Report, prioritize, and fix
The findings ordered by severity, each carrying the context that makes it severe, and split between what costs configuration effort and what would cost money. Then the remediation itself, carried out by your team or by ours, and we are genuinely content with either. Where you want it, we audit again afterward so the improvement is documented rather than assumed.
What organizations ask about a Microsoft 365 audit.
Fifteen things worth checking in your own tenant before Friday.
Identity, where it starts
- How many accounts hold Global Administrator?The real number is almost always higher than whatever anybody says off the top of their head.
- Is multifactor genuinely enforced against every single one?Enforced, not enabled, not encouraged.
- Are there accounts excluded from Conditional Access?Check why, and whether the reason still exists.
- Do emergency accounts exist, and has anybody ever signed into one?Untested emergency access is not emergency access.
- How many accounts have gone ninety days without a single sign-in?Each one is a live credential nobody is watching.
What leaves the tenant
- Is external mail forwarding blocked or monitored?The classic business email compromise mechanism.
- Are there mailbox rules quietly filing mail into folders nobody opens?Worth looking at directly, not just in policy.
- Can users create anonymous sharing links that never expire?Check the setting and check what already exists.
- How many guest accounts exist, and who owns each?They accumulate and nobody removes them unprompted.
- Which third-party applications have consent in your tenant?Consented apps are a standing access path.
Could you evidence it
- How far back does your audit log actually reach?Check the retention policies, not the license brochure.
- Do custom retention policies exist, and is any one of them shorter than the default?Custom policies override the default in both directions.
- Are all your users E5, or is licensing mixed?Retention is per user. Mixed licensing means mixed evidence.
- Has anybody ever run a real audit log search?The first time should not be during an incident.
- Is device compliance connected to access, or only reported?Reported non-compliance changes nothing on its own.
The pages around this one.
Cybersecurity audit and compliance
The wider audit practice, and how to tell which kind of engagement your situation actually calls for.
Microsoft Entra
The identity layer underneath everything on this page: Conditional Access, privileged access, and the controls that close the findings we most often report.
Tenant security baseline
The written, enforced security configuration that keeps the tenant hardened after the audit closes its findings.
Go and check how far back your audit log reaches.
It takes a few minutes, it is free, and for most organizations the answer is different from what they assumed. If you would like help checking it, or a full review of the tenant behind it, that is a short conversation and we will tell you what we would look at first.
Related Services
Explore more solutions that work great with this service
Google Workspace Security Audit
Google Workspace security audit for US organizations worked through
Learn moreEmail Security Audit
Email security audits for US organizations: sending domain inventory
Learn moreActive Directory Security Audit
On-premises Active Directory security audit for US organizations:
Learn moreMicrosoft Entra
Identity and access management solutions
Learn moreTenant Security Baseline
Documented controls mapped to CIS
Learn more