Microsoft 365 Audit
Fixed project price from 7,000 €, no hourly billing
30 minutes, no preparation needed. You will receive a written offer within a few working days.
Martin Grottenthaler, Founder and Lead Penetration Tester. OSCP, CISSP, GCFA, GWAPT. Pentesting since 2017.

Diese Seite ist auch auf Deutsch verfügbar.
A Microsoft 365 Audit is a read-only, white-box review of your M365 tenant (Exchange Online, Teams, SharePoint, Defender, and admin roles) that finds misconfigurations enabling phishing, data theft, or account takeover.
Microsoft 365 is the productivity backbone of most modern organizations: Exchange Online handles email, Teams drives collaboration, SharePoint stores documents, and Entra ID manages identities. A misconfiguration in any of these components can expose sensitive data, enable phishing attacks, or allow unauthorized access to company resources.
This audit reviews the security configuration of your Microsoft 365 tenant using a read-only account. It is typically performed as a white-box engagement and scoped in a kick-off call. It is a natural complement to an Entra ID Audit, which focuses specifically on identity and access management.
Scope
The following areas are reviewed as part of a Microsoft 365 Audit:
- Exchange Online: anti-phishing policies, SPF/DKIM/DMARC configuration, mail transport rules, connector security, external email warnings
- Teams and SharePoint: external sharing settings, guest access policies, document permission review
- Microsoft Defender for Office 365: policy configuration, Safe Links, Safe Attachments, threat protection settings
- Admin roles and MFA: review of global admins and privileged roles, MFA enforcement for admin accounts
- Microsoft Secure Score: review of current score and highest-impact recommendations
- Conditional Access: review of policies protecting M365 applications
Why
- Microsoft 365 environments are a prime target for attackers: phishing, business email compromise (BEC), and data theft typically exploit misconfigurations rather than software vulnerabilities
- Default Microsoft 365 settings are not hardened; many organizations run significant gaps without knowing it
- A compromised M365 tenant can expose all company email, files, and credentials
Why VidraSec 🦦
My focus on Windows, Active Directory, and the Microsoft identity stack extends naturally into Microsoft 365. The Entra ID and M365 layers are tightly integrated; understanding one requires understanding the other. This audit is often combined with an Entra ID Audit for a complete picture of the Microsoft identity and productivity environment.
Typical Duration
3-5 days (reporting included; scope-dependent)
Typical Price
from 7,000 €
The final price depends on the scope and is calculated from the planned effort, which the offer itemizes transparently (person-days times daily rate). The offer total is the final price: if the actual effort ends up a little over or under the estimate, the price stays the same.
Deliverables
Every engagement includes:
- Written findings report with all identified misconfigurations, prioritized by risk
- Management summary tailored to your audience (technical or executive)
- Live debriefing to walk through findings and answer questions
- Retesting after remediation available on request
See example reports to get a sense of what a VidraSec report looks like.
Compliance
Relevant for organizations working towards NIS2, ISO 27001, or TISAX compliance. Microsoft 365 security configuration is increasingly audited as part of information security management reviews.
Frequently asked questions
What is the difference between a Microsoft 365 Audit and an Entra ID Audit?
A Microsoft 365 Audit reviews the productivity services such as Exchange Online, Teams, SharePoint, and Defender. An Entra ID Audit focuses specifically on identity and access management. The two layers are tightly integrated and are often audited together for a complete picture.Does the audit require access to our tenant?
Yes, a read-only account is sufficient. The audit is performed white-box, which lets VidraSec review configuration and security settings efficiently without making changes to your tenant.How long does a Microsoft 365 Audit take?
Typically 3 to 5 days including reporting, depending on tenant size and the services in use.How much does a Microsoft 365 Audit cost?
From 7,000 euros. The final price depends on scope and the maturity level of your environment and is calculated individually.More questions on pricing, lead times, NDAs, or compliance: see the general FAQ

