Home  /  Guides  /  Microsoft 365 Security Health Check: What to Audit and Why
Cybersecurity

Microsoft 365 Security Health Check: What to Audit and Why

Almost every tenant I audit is secure in the places the last engineer looked and wide open in the places nobody thought to check. MFA is on for the office staff but not the service account. Defender is licensed but the anti-phishing policy is still at default. The backup exists but has never been restored.

A health check is not a scan. It is a structured pass over the whole tenant against a known baseline, producing a list of findings a business owner can act on and price. This is what I cover, in the order I cover it, and the free tooling that does most of the heavy lifting.

Why this is worth doing right now

Three things have changed in the last twelve months that make an old tenant configuration a genuine liability rather than just untidy.

First, the government's Cyber Security Breaches Survey 2025/2026, published on 30 April 2026 by DSIT and the Home Office, found 43 per cent of UK businesses identified a breach or attack in the previous twelve months, around 612,000 organisations. Phishing was reported by 38 per cent of businesses and named the most disruptive attack type by 69 per cent of those affected. Among businesses that were breached, 51 per cent experienced phishing and nothing else, up from 45 per cent the year before. The threat is concentrated in one place, and that place is email and identity.

Second, Cyber Essentials tightened. Version 3.3 of the Requirements for IT Infrastructure and the new Danzell question set went live in late April 2026. Two automatic failure conditions now exist: no MFA on a cloud service that offers it, and high-risk security updates not applied within 14 days. Cloud services also got a formal definition and can no longer be excluded from scope. If Microsoft 365 is in your business, it is in your assessment.

Third, Microsoft removed the option to defer. Mandatory MFA for the Microsoft 365 admin centre took full effect on 9 February 2026, with sign-in blocked without it. The Azure portal has required MFA since March 2025.

The point of a health check Not to produce a 60-page document nobody reads. To produce a ranked list of what is wrong, what it would take to fix, and what happens if it is not fixed. Everything below feeds that list.

The nine areas

1. Identity and authentication

This is where most real risk sits, so it goes first.

2. Administrative access

3. Conditional access

Only available with Entra ID P1, which comes with Business Premium. If the tenant has the licence and no policies, that is unused spend as well as unused protection.

4. Email protection

Given phishing is the dominant attack route, default settings here are not good enough.

5. Device management

6. Data protection and sharing

7. Logging and visibility

8. Backup and recovery

9. Licensing and spend

Not strictly security, but it belongs in the same report because it usually pays for the remediation.

Tools that do most of the work

ToolWhat it gives youCost
Microsoft Secure ScoreDirectional baseline and a prioritised improvement list inside the tenantFree
ScubaGear (CISA)Automated assessment against a published secure configuration baseline, with an HTML reportFree
MaesterPester-based test framework for Entra ID and M365 config, good for repeat checksFree
Microsoft Graph PowerShell SDKEverything the portals will not export cleanly, especially dormant accounts and role assignmentsFree
MXToolboxExternal view of MX, SPF, DKIM, DMARC and blacklist statusFree tier
Have I Been PwnedDomain search for staff addresses in known breachesFree for domain owners

Do not hand a client a raw ScubaGear output and call it a report. The tools find the facts. The value is in deciding which findings matter for that business and what the fix costs.

On Secure Score It is worth watching, but it is a Microsoft-weighted model, not a risk assessment for your business. It will happily reward you for enabling something with low practical value while ignoring that your only backup has never been restored. Use it as one input.

Reporting the findings

A traffic-light report per area works better than a score, because a business owner can look at a page of red, amber and green and immediately know where the conversation needs to go.

StatusMeaningExpected action
RedControl missing or ineffective, with a realistic route to compromiseFix within days
AmberControl present but partial, misconfigured or unmonitoredFix within the next month
GreenControl in place and verified workingReview at next audit

For each red and amber finding, state three things: what is wrong, what an attacker could do with it, and what fixing it requires in terms of licence, effort and disruption. That last part is what turns a report into a decision.

How often to run one

Annually as a floor. Also run one after any of these:

Related reading: how to audit your Microsoft 365 tenant security, Cyber Essentials vs Cyber Essentials Plus, and auditing sign-in logs in Entra ID.

Would rather have this done for you?

We run this audit as a fixed price piece of work and hand you a written plain English report.

See the Security Health Check

Tags: Microsoft 365 · Security Audit · Cyber Essentials · UK SME · Entra ID

More in this series: all Klariq guides.