How to Audit Your Microsoft 365 Environment in Under an Hour
Microsoft 365 has become the backbone of most small businesses.
Email, calendar, Teams, SharePoint, OneDrive, and Office applications all run through the same platform. When it works well, your team stays connected and productive. When it is not configured properly, it creates security gaps, wasted spending, and unnecessary risk.
A Microsoft 365 audit does not have to be a months-long project. You can cover the most important areas in under an hour if you know what to look for.
Start with User Accounts
The first thing to review is who actually has access to your Microsoft 365 environment.
Over time, businesses accumulate accounts that no longer need access — former contractors, old employee accounts, test users, and shared accounts that should have been converted to shared mailboxes. Each unnecessary account is both a security risk and a wasted license.
Run through this checklist:
- How many active users do you have versus how many are licensed?
- Are there accounts for people who no longer work at the business?
- Are there admin accounts that no longer need admin-level access?
- Are any shared accounts still assigned to individual users instead of being converted to shared mailboxes?
- Which users have MFA enabled
- Which users are still relying on passwords alone
- Which admin accounts lack MFA (this is the most critical group)
- Are there any policies in place at all?
- Do they cover the right applications and users?
- Are there gaps that allow unrestricted access from any location?
- Are there any rules forwarding email to external addresses?
- Are there any inbox rules that delete or move messages automatically?
- Do any users have rules they do not recognize?
- How many licenses are assigned versus how many are actually being used
- Whether any users have higher-tier licenses than they need
- Whether there are unused licenses that could be reassigned or removed
- Can users share files with anyone outside the organization?
- Are there links that allow anonymous access without expiration?
- Are there sites with open sharing that should be restricted?
Clean up unnecessary accounts first. Every extra user is one more path an attacker could exploit.
Review Admin Roles
Microsoft 365 has multiple admin roles, and many businesses grant Global Admin to users who only need a fraction of that power. Global Admin gives access to everything — every setting, every user, every security configuration.
Review who has Global Admin access. Most users do not need it. If someone needs to reset passwords, a Helpdesk Admin or User Admin role is sufficient. If someone manages billing, a Billing Admin role covers that without full environment access.
The principle is simple: give people the minimum access they need to do their jobs, and nothing more.
Check MFA Enrollment
Multi-factor authentication should be enabled for every user in your Microsoft 365 environment, especially for admin accounts.
Check your MFA enrollment report to see:
If any admin account does not have MFA enabled, that should be addressed immediately. A compromised admin account without MFA gives an attacker the keys to the entire environment.
Review Conditional Access Policies
Conditional Access policies control when and how users can sign in. For example, you can require MFA only when signing in from outside the office, or block sign-ins from certain countries entirely.
Review your current policies to see:
Even a basic policy that requires MFA for all admin sign-ins is better than none. More sophisticated policies can be added over time as your needs evolve.
Audit Email Forwarding Rules
One of the most common ways attackers maintain persistent access after compromising an email account is by setting up an email forwarding rule that sends copies of incoming messages to an external address.
These rules are often invisible to the user and can go undetected for months. Review forwarding rules across your organization:
Clean up suspicious rules and monitor for new ones going forward.
Check Unused Licenses
Microsoft 365 licensing is easy to over-provision. Users get licenses when they are set up, but those licenses are not always reclaimed when they leave or change roles.
Review your license allocation to see:
This is often where businesses find immediate cost savings. Even a handful of unused licenses at $30-plus per month adds up over a year.
Review External Sharing Settings
SharePoint and OneDrive make it easy to share files externally, which is great for collaboration but can create exposure if not managed.
Check your sharing settings to see:
Tightening external sharing does not stop collaboration — it just makes sure shared access is intentional rather than accidental.
What to Do with What You Find
After completing this audit, you will likely have a short list of items to address. Some can be fixed immediately, like removing old accounts or enabling MFA. Others may require a bit more planning, like restructuring admin roles or implementing Conditional Access policies.
The value of the audit is not in finding every possible issue. It is in catching the most common and most dangerous gaps before they become problems.
Final Thoughts
A Microsoft 365 audit is one of the most practical things a small business can do to improve security and reduce waste. It does not require a massive project or a deep technical team. It requires knowing what to look for and taking action on what you find.
If your business wants help running through a structured Microsoft 365 review, AVS Technologies can help. We work with Atlanta small businesses to clean up their environments, reduce unnecessary access, and make sure their Microsoft 365 setup actually matches the way they work.