Real cases
Compromised accounts nobody knew about
At a services company we found automatic forwarding rules to external addresses in three mailboxes: someone had been reading their email for months. We removed the rules, forced MFA and credential resets, enabled Defender alerts and closed the legacy authentication they had come in through.
Client data reachable with a link
A professional practice shared SharePoint folders with "anyone with the link", including folders with case files. We restricted external sharing to identified guests, applied sensitivity labels and a data loss prevention policy for national IDs and IBANs.
Unencrypted laptops at a company with a field sales team
With Intune we enrolled the devices, turned on BitLocker and set compliance requirements: a lost laptop is no longer a data breach.
A Copilot that could see too much
Before enabling Copilot at a 60-person company we measured what each user could reach: payslips and contracts in a library shared with everyone. We fixed permissions, applied sensitivity labels and a DLP policy, and only then enabled Copilot for the pilot group. The oversharing report went from hundreds of documents to zero.
Frequently asked questions
Does the audit disrupt work?
No. It is read-only: we review configuration and logs. Changes happen in the hardening phase, planned and announced.
What is Secure Score?
The score Microsoft gives to your tenant's security. It is a useful reference to measure improvement, not a goal in itself: some points are not worth chasing in an SMB.
Does it help with ISO 27001 or similar frameworks?
The audit covers the Microsoft 365 technical controls those frameworks require and the report can be used as evidence. It does not replace certification.
How often should it be repeated?
Once a year, or after major changes (growth, merger, new tools). If we manage your tenant, it is part of the ongoing review.
Do I need extra licences?
It depends on what you have. Business Premium covers most of it; we tell you exactly what would be needed and what would not before touching anything.
What does Zero Trust mean in practice?
Three principles: always verify identity and device (MFA, conditional access, compliant devices), grant the least privilege needed (permissions, admins, guests) and assume a breach will happen (detection, alerts, response). The audit checks, control by control, how far your tenant meets them.
Do you audit Copilot too?
Yes. Copilot does not bypass permissions, but permissions are usually wrong: the audit measures which data each user would reach through the AI and what must be fixed before switching it on. It also covers Copilot Studio agents and Power Platform connectors.