Find the evidence
Policy, logs, owners, exceptions and recent tests.
Identity · administration · recovery
Turn a Microsoft 365 security review into a clear list of confirmed controls, unanswered questions and priority follow-ups—without reducing a complex tenant to a misleading score.
Start the tenant reviewA review worksheet, not a scanner
Use current policy screens, sign-in evidence, audit records, change tickets and recovery tests. “Configured once” is not the same as confirmed today.
How to use the result
A clean review separates known gaps from evidence gaps. Start with emergency access and privileged identity, then work through legacy protocols, audit visibility, sharing and recoverability.
Policy, logs, owners, exceptions and recent tests.
Licensing, identity model and business-critical apps.
Approval, staged rollout, emergency access and rollback.
Important boundaries
Microsoft 365 names, defaults and licensing evolve. The checklist points to review areas; your current tenant, contracts, risk and regulatory obligations determine the right control design.
Access changes can lock out administrators or break mail, devices and applications. Use report-only modes, pilots and rollback where appropriate.
Define what must be restored, from when and how quickly. Then validate the available retention or backup route with representative data.
Framework and legal requirements need evidence, scope and accountable interpretation beyond a general-purpose worksheet.
First-party guidance
These references underpin the most consequential questions. Check the pages again when planning a live change because service behaviour and licensing can change.
Common questions
No. It is a structured self-review and does not ask you to sign in or grant access. The result is only as reliable as the evidence used to answer each question.
No. It means you recorded the item as confirmed. Control design, configuration, exceptions, licensing, testing and current threat context still need competent review.
Microsoft's current guidance recommends two or more cloud-only emergency accounts so administrators have an independent recovery route if normal identity controls fail or cause lockout.
No. Security Defaults, Conditional Access, hybrid identity, mail protection, audit retention and backup options differ by tenant, licence and operating need. Validate the supported design before changing policy.
Need a second pair of eyes?
ACA Tech Solutions can help UK teams examine Microsoft 365 identity, administration, sharing, audit and recovery with evidence, sequencing and practical change controls.