How to Run a Security Audit on Your Office 365 Tenant
Most Australian organisations running Exchange Online, SharePoint, Teams and OneDrive sit on a Microsoft 365 environment that quietly grows each quarter. New users join, third-party apps get consent for mailboxes, SharePoint sites expand, and Defender policies drift from their original setting. A security audit brings that growth back under control, giving Sydney-based enterprise tenants, Brisbane government departments and Melbourne healthcare groups a clear picture of who can see what, where sensitive data lives, and whether last year's controls still match today's threats.
The process is not about ticking boxes for the sake of an auditor. It is about understanding the configuration of your identity, data and threat-protection layers, then tightening anything that has loosened since the last review. Treating it as an annual discipline, much like the Essential Eight assessments many local businesses already adopt, helps teams catch risky OAuth grants, dormant admin accounts and mailbox forwarding rules before they become part of an incident reportable to the Office of the Australian Information Commissioner.
Preparing the audit scope and roles
Before opening any blade in the Defender portal, decide what the audit will cover. A tenant that hosts patient records across NSW Health partners needs different boundaries than a financial services firm in Parramatta or a mid-market retailer in Adelaide. Document a written scope listing the workloads in play — Exchange Online, SharePoint, OneDrive, Teams, Azure AD and any connected apps — with the compliance frameworks that apply, such as the Privacy Act 1988 and the local Notifiable Data Breaches scheme.
Assign ownership next. The audit needs three pairs of hands: a security engineer who can read configuration data, a compliance lead who translates findings into policy language, and a business sponsor, often a CFO or COO, who can sign off on remediation budgets. Rotate who holds the Global Administrator role during the review so that no single account becomes a permanent back door. Where tenants are managed by a partner such as Infoziant Security, confirm those analyst accounts are scoped with the least privilege their work actually requires.
Reviewing identity, conditional access and privileged roles
Identity is the front line of any Office 365 tenant. Pull the full list of directory roles and sort them by last sign-in. In many Australian environments the audit surfaces Global Admins who logged in years ago and never returned — perfect targets for credential-stuffing using one of the leaked password lists still in circulation. Disable what is not needed, convert permanent assignments to eligible PIM requests, and require phishing-resistant MFA for anything holding directory write access.
Conditional Access policies should be reviewed line by line. Look for rules that exclude specific users, because an attacker who compromises an excluded account bypasses every other control. Confirm named-location definitions match the actual IP ranges of your Sydney and Melbourne offices, and that break-glass accounts are excluded without being forgotten. Check Azure AD MFA registration and number matching — legacy settings allowing SMS or basic authentication remain common in regional tenants and should be retired in favour of the Authenticator app or hardware keys.
Inspecting data governance and information protection
Once identity is in order, turn to the data itself. Run a search across SharePoint and OneDrive for content labelled as sensitive and compare it against your labels in Purview. Many Australian organisations discover that the labels created during an earlier project were never applied, leaving patient consent forms, credit-card data or contract negotiations readable by far more people than intended.
Audit external sharing on every SharePoint site, OneDrive account and Teams shared channel. Default-to-private should be the rule, with explicit allowlists for the small number of sites that genuinely collaborate with external partners or legal advisers. Review retention policies to confirm they match the records practices the National Archives of Australia expects, and that auto-labelling is enforcing protection rather than waiting for users to classify documents themselves. Sample a few files per label to verify the protection actually triggers on download or print.
Checking Exchange Online, Defender and mail-flow hygiene
Email remains the single biggest entry point for Australian businesses, so mail-flow configuration deserves a dedicated pass. Open the Exchange admin centre and review transport rules, accepted domains and inbound connectors, particularly the legacy ones left over from mergers. Confirm that outbound spam policies block bulk sending from user mailboxes — a common sign of a compromised account being used for invoice fraud against local suppliers.
Defender for Office 365 should still be protecting against modern threats. Confirm Safe Links and Safe Attachments are enforced in block mode, that anti-phishing policies impersonate your real domain and your most spoofed suppliers, and that the tenant has not fallen back to defaults after a licence change. Recent reporting on cash-out fraud makes clear that attackers pivot to mailbox-driven schemes the moment they hold a foothold, which makes these policies worth the licence cost. Pull the unified audit log and look for unusual sign-ins from overseas data centres during your local arvo.
Recommendations worth locking in
- Document the audit scope, owners and exit criteria before the first script runs, and reuse the same template each cycle.
- Treat every directory role review as a chance to convert standing admin rights into just-in-time, requestable assignments.
- Sample at least five SharePoint sites and three mailboxes per business unit before signing the audit off as complete.
- Keep one break-glass account permanently excluded from Conditional Access, store its credentials in a sealed envelope inside a NSW or Victorian vault, and rehearse its use annually.
- Map every key control to the Essential Eight maturity level and the Notifiable Data Breaches obligations so the board sees a single view.
Book a 30-minute call with the Infoziant Security team to walk through your tenant findings, or request a complimentary VAPT snapshot alongside your next Office 365 audit so the identity, data and mail-flow layers are reviewed together by people who spend every day inside Australian tenants.