Identity and privilege
Microsoft Entra ID roles, authentication methods, lifecycle, guests, applications, consent, identity risk, and governance features where licensed.
Built for a defined customer, insurer, board, or internal-audit question. The review connects current Microsoft 365 evidence to supported conclusions, open questions, and prioritized action without presenting itself as an attestation or certification.
TenantShield starts with the assurance or oversight request, reviews the Microsoft 365 evidence needed to answer it, validates material observations with stakeholders, and records supported conclusions and gaps. The word audit does not imply a statutory audit, formal attestation, or compliance certification.
The applicable control set depends on licensing, enabled services, architecture, user populations, regulatory or contractual context, accepted exceptions, and evidence available at the time of review.
Microsoft Entra ID roles, authentication methods, lifecycle, guests, applications, consent, identity risk, and governance features where licensed.
Policy state, assignments, exclusions, conditions, grant and session controls, authentication strengths, device dependencies, and rollout practices.
Exchange Online mail flow, connectors, forwarding, delegates, applications, built-in protections, public email authentication, auditing, and operations.
SharePoint Online, OneDrive, and Microsoft Teams sharing, external collaboration, guest access, link defaults, application dependencies, and lifecycle controls.
Microsoft Intune administration, enrollment, policy, compliance, endpoint security, device operations, enterprise applications, service principals, and credentials where applicable.
Microsoft Defender XDR and workload-specific protection, alerts, incidents, investigation, response, integrations, and security-operations ownership where licensed.
Relevant Microsoft Purview retention, sensitivity, data loss prevention, audit availability, evidence retention, and investigation dependencies where licensed and scoped.
Ownership, exception handling, joiner-mover-leaver processes, privileged change control, monitoring, recovery, periodic review, and evidence of operation.
Prioritize identity, access, messaging, collaboration, endpoint, application, data, and operational observations by impact, exposure, confidence, and dependency.
Separate configured controls from operating evidence, licensed capability from unavailable features, and verified facts from assumptions requiring owner confirmation.
Build a sequenced action register that accounts for business impact, implementation effort, user experience, change risk, compensating controls, and validation.
Confirm tenant relationships, services, licensing, populations, business drivers, stakeholders, evidence sources, exclusions, and intended use of the report.
Review agreed Microsoft 365 configuration and operational evidence with read-only methods where supported and record evidence limits.
Discuss high-impact observations with accountable owners, identify compensating controls, document accepted exceptions, and distinguish facts from open questions.
Deliver executive and technical views, a sequenced action register, named dependencies, validation steps, and a stakeholder readout.
No. TenantShield uses audit in the practical sense of an independent configuration and control review. The engagement is not an attestation, legal opinion, statutory audit, penetration test, or compliance certification.
The scope is agreed from the services, licenses, tenant architecture, business questions, and evidence available. Microsoft Entra ID, Conditional Access, Exchange Online, SharePoint Online, OneDrive, Microsoft Teams, Microsoft Intune, Microsoft Defender, Microsoft Purview, and operational controls are included only where applicable and licensed.
No. The audit establishes evidence, observations, risk, and recommended action. Implementation is a separate engagement with explicit authorization, change safeguards, rollback planning, and validation.
It can provide a structured, evidence-based view of Microsoft 365 configuration and control priorities for those conversations. It does not replace the specific assurance, legal, or attestation work another party may require.
Microsoft Secure Score is one useful posture signal. The audit also considers applicability, evidence quality, business dependencies, privilege, policy interaction, exceptions, operational ownership, change risk, and controls that are not represented by a single score.
Choose a deeper product-specific review when the risk or decision is already concentrated in one Microsoft 365 service.
See how applicability, evidence, validation, prioritization, and reporting are handled.
Run a directional browser-based review before deciding whether a professional audit is the right next step.
Share the business trigger, relevant Microsoft 365 licensing, approximate environment size, and decision deadline. No credentials or tenant exports are needed for the first conversation.