What the M365 Audit Checks
Run the export script with a Global Reader or Security Reader account — it reads tenant configuration, policy, and aggregate registration counts only. It never touches mailbox content, files, or Teams messages.
Identity & Access
Security Defaults status, Conditional Access policy count, MFA-enforcing policies, legacy authentication blocking, and admins without MFA registered.
Privileged Roles
Global Administrator count — flags standing over-privileged access that expands your tenant's attack surface.
Mail Authentication
SPF, DKIM and DMARC policy on your default domain, plus external mail-forwarding rules and custom anti-phishing policy coverage.
Guest & External Sharing
Unrestricted guest invite settings and SharePoint Online external sharing capability — common sources of data leakage.
Microsoft Secure Score
Live Secure Score percentage pulled directly from Microsoft Graph, plus SSPR registration coverage across your users.
Auditing & Compliance
Unified audit log ingestion status, mailbox auditing, and device compliance enforcement via Conditional Access.
Common M365 Findings We Catch
Fix:
none or quarantine means spoofed mail impersonating your domain can still reach inboxes or land in spam instead of being blocked outright — leaving phishing and BEC risk on the table.Fix:
p=reject once SPF/DKIM alignment is confirmed clean via aggregate reports.Fix:
Audit Your Microsoft 365 Tenant Now
Download the script, run it with a read-only reporting role, upload the results — get a scored report in 60 seconds.
🔒 Start Free Audit