For the engagement owner. Separate policy intent, live configuration and operating records when preparing tenant evidence.
Define the tenant boundary
A Microsoft 365 assessment begins with scope, not a generic checklist. Identify the tenant count, relevant business services, guest populations and responsibility split between internal teams and providers. Record licence constraints and any planned consolidation. Distinguish Entra identity controls, collaboration settings, endpoints and Azure infrastructure rather than assuming they are one administrative boundary. A clear inventory helps determine which evidence sources can answer the audit questions and which areas need separate owners or further scoping.
Read diagram text
- Intent
- Approved policy and exception rules.
- Configuration
- Dated settings and role assignments.
- Operation
- Reviews and lifecycle records.
Count identities and assignments separately
One privileged identity can hold several role assignments, so reports should not use these counts interchangeably. Prepare dated exports showing the relevant roles, whether access is active or eligible, approval records and expiry where applicable. Include emergency-access and service identities in a defined category rather than hiding them in an exception. The assessor should compare observed settings with the agreed policy and review evidence. A permanent assignment is not automatically a policy breach if the approved control design permits and governs it.

Show what conditional access actually does
A policy name is not sufficient evidence. Explain whether the policy is enabled, report-only or excluded for selected populations, and provide the rationale for exceptions. The review should distinguish policy design from actual configuration and from evidence of ongoing oversight. A configuration finding about an exclusion does not prove an authentication bypass was attempted. If technical validation is needed, agree its method and permissions separately. Do not paste tenant identifiers, tokens or detailed security settings into the initial enquiry form.
Read diagram text
- Identity
- A unique privileged principal.
- Assignment
- A role granted to that principal.
- Approval
- The documented authority and duration.
Reconcile lifecycle records using consistent time
For leaver testing, agree the source of truth, disablement target and time zone before comparing records. Use a complete population for the review period, then select samples with a documented method. Explain contractor, service-account and emergency exceptions. Preserve the relevant timestamps rather than relying only on present account state. An account disabled today may still have missed the required deadline last month. Conversely, an apparent delay can be a time-zone or record-mapping error that needs factual resolution.
Read diagram text
- Event
- Approved departure record.
- Action
- Directory disablement timestamp.
- Criterion
- Target, time zone and exception rule.
Make the remedial action operational
A tenant review should produce more than a score. Specify the failed or unsupported requirement, evidence reference, scope and recommended action. Changes need an owner, approval, staged validation and rollback considerations. Follow-up should inspect the actual implementation and a new operating sample where the finding concerns a process. Existing provider responsibilities should be clear before assigning tasks. Related guidance from the same Atlant Security portfolio: identity and network trust boundaries and workplace and cloud service boundaries. Use these when an audit recommendation needs a separately scoped technical test or a clearly owned operational improvement.
Prepare a useful first conversation
Use the audit scoping brief builder to record your objectives, control areas, platforms and evidence period. Review its draft before sending it to Atlant Security through the contact form. You can attach an NDA or RFP for human review. Begin with non-sensitive context and approximate counts; confidential control evidence belongs in an agreed secure channel. The brief does not authorise system access, accept an NDA or establish an assurance opinion.
Read diagram text
- Approve
- Owner and deployment conditions.
- Validate
- Confirm the resulting settings.
- Resample
- Check sustained process operation.
Primary sources
- Atlant Security IT security audit
- NIST Cybersecurity Framework
- NIST SP 800-53A assessment methodology
General information, not a compliance opinion. Confirm legal applicability and security service requirements for your entity and jurisdiction.
This guide and the related sector publications linked above are published by Atlant Security. Technical examples are planning examples, not claims about completed client tests.
Published by Atlant Security. Sources, editorial policy and corrections.

