Microsoft 365 Audits

A tenant audit that found eleven years of accumulated access

A Microsoft 365 tenant set up in a hurry, grown through two acquisitions, and never reviewed against a benchmark.

Client
Professional services firm
Sector
Legal & accounting
Year
2025
34
Findings, risk-rated
9
Stale admin accounts closed
41%
Secure Score improvement

Engagement

Stack involved

  • Entra ID
  • Conditional Access
  • Purview
  • Defender
  • CIS Benchmarks

The situation

Client-confidential documents sat in a tenant where external sharing had never been restricted, legacy authentication was still enabled, and two acquisitions had left admin accounts belonging to people who had not worked there for years. An insurer had begun asking questions the firm could not answer.

What we did

  1. 01

    Scored audit against CIS Microsoft 365 benchmarks covering identity, mail flow, sharing, device compliance and admin roles.

  2. 02

    Every finding rated by risk and remediation effort, so leadership could sequence the work against budget.

  3. 03

    Conditional access and MFA piloted with a twelve-person group before staged rollout in rings.

  4. 04

    Legacy authentication disabled after a four-week report-only period identified the three applications still using it.

  5. 05

    Retention and external sharing policies rebuilt around the firm’s actual client-confidentiality obligations.

The outcome

Thirty-four findings documented and risk-rated; nine dormant privileged accounts removed. Legacy authentication was disabled without a single user-facing outage, and the firm answered its insurer’s questionnaire from the report rather than assembling evidence from scratch.

Service used Microsoft 365 Deployment & Audits

Tell us what is breaking.

A short call, an honest read on whether we are the right fit, and a fixed-price proposal after discovery. No obligation and no sales sequence afterwards.

Book a consultation hello@queuebytes.com

Mon–Fri, 09:00–18:00 · Emergency cover 24/7