blog

How to Audit Your M365 Tenant for Better Security and Cost Savings

Written by Mira Valjakka | Apr 23, 2024 12:22:22 PM


With forever evolving platforms like Microsoft 365, it is crucial to run regular health checks that pinpoint potential security risks and inefficiencies in usage and licensing. New features and updates are rolled out frequently and leaving them unchecked can expose your organisation to vulnerabilities. At the same time, when the number of users and applications grows, M365 adoption – as well as licensing and features - becomes increasingly complex to manage.

Optimise Your Microsoft 365 Tenant for Better Security and Cost Savings
Regular Microsoft 365 audits create a firm foundation for optimal security, productivity, collaboration, privacy, and compliance that organisations and users can rely on. At Forge Technologies we have audited countless of Microsoft 365 tenants across organisations big and small, and uncovered that:

All companies have licenses that are sitting completely unused because they’re unassigned or inactive

  • Many don’t take advantage of all the features and services they’re paying for
  • Many have significant weaknesses in their security posture
  • Many don’t utilise built-in Microsoft Security features

In this article we explain what is included in the Microsoft 365 audit and give you three no-brainer reasons why your tenant needs a health check:



What is a Microsoft 365 Audit?


Microsoft 365 audit will scan your Microsoft tenant to pull information around security posture, password weaknesses, and license usage. Based on our experience, security and adoption present most risks and inefficiencies for audited organisations. That is why we built a M365 audit process that is hyper focused on these two areas.



Security risks and vulnerabilities

A security assessment will highlight potential threats and misconfigurations that can compromise your data, end users and systems. We will review areas such aspassword security, failed login attempts, and identity protection that all play part in enhancing your Microsoft 365 security strategy and end user policies. You will also get valuable information forensuring compliance in accordance with industry regulations.

Microsoft 365 adoption and licensing

Beyond security posture, there are additional elements to reviewto ensure that your Microsoft 365 tenant is correctly configured, cost effective, and aligned with your business objectives. A thorough evaluation of the current adoption and licensing gives insight into your Microsoft 365 environment that help build a roadmap for optimisation and cost savings.

Typically, performing a Microsoft 365 audit takes around two weeks. During that time, our Microsoft-licensed specialists use enterprise-grade tools to gather data on your existing environment, day-to-day workloads, and employee responsibilities. You can rest assured that your data is safe with us; using the auditing tools we cannot edit settings, see inside the documents, or access other sensitive business information.

Once we have all the necessary data, we meet with your team to talk about the findings, potential areas of concerns, and recommended improvements that help optimise and secure your M365 environment. We always make sure to reserve plenty of time for questions, so that you can leave the meeting with a clear understanding of next steps. You will also get a detailed report with findings, using RAG reporting, along with a list of recommendations – a hefty document that is easy to use as a guidebook for optimisation.


Three Reasons Your Organisations Needs a Microsoft 365 Audit


Think of Microsoft 365 audit as an annual dental check. You can skip it for a year or two, but during that time what could have been fixed with a small filling now requiresa root canal that is not only more painful, but also more expensive. When done regularly, it is much easier to keep things healthy – even across your Microsoft 365 tenant!

Simplify Microsoft 365 Tenant Management

IT management is more complicated than ever. 72% of organisations reported increased complexity within their IT environment over the past two years. Without a doubt the biggest perk of Microsoft 365 is the ability to consolidate vendors into one licensing. Correct configuration of your Microsoft 365 tenants provides user productivity and performance as well as advanced endpoint management solutions in one cost-effective, bundled plan.

But as the number and complexity of Microsoft products increase, managing Microsoft 365 tenant can be a challenging task. A Microsoft 365 audit will give you a clear overview of licensing, features, security, and user adoption to help you make informed decisions on what you need and what you do not need. Following the clear RAG reportingof our audit report, it is easy to create a list of planned actions in order of priority.


Improve Security posture


Evolving needs of hybrid work and rise in connected devices have made endpoints increasingly exposed to cyber-attacks like phishing, ransomware, and data theft. 68% of organisations have experienced one or more endpoint attacks that compromised data and their IT infrastructure. A compromised endpoint gives an attacker easy access to wider IT environment, putting the entire organisation at risk.

The good news is that Microsoft 365 licensing comes with a plethora of built-in security features that help ensure device health and compliance. When auditing organisations, we often find that Microsoft Intune, Microsoft’s suite of end point management services, is not correctly, or at all, configured. Most important takeaway for you today: make sure to enable Microsoft Intune.

Do you feel confident about your current Microsoft 365 security settings and endpoint management setup? If you hesitated even for a second, there’s room for improvement. Microsoft 365 audit gives you concrete recommendations on how to improve your security posture and reduce the risk of information loss using Microsoft Security services. 

Achieve Cost Savings Through Optimisations


Are your Microsoft 365 licensing costs on upwards trend? Optimising licensing subscriptions is the quickest way to bring home cost savings. Microsoft 365 audit will review where your organisation is today: what licenses you currently have and how much you are paying for them. Havingclear visibility on the inventory helps highlight licences that are unused or inactive. From there, you can eliminate unnecessary costs depending on renewal dates and licensing types.

To make the most of the Microsoft 365 investment, what you purchase should also match the needs of your workforce. This may sound obvious, but end user needs evolve over time, and it can be tricky for the IT teams to stay on top of the changes. The audit will also look at your end users needs and behaviour to determine exactly what is needed in terms of features and applications. Efficient, ongoing license management helps ensure end users adopt and utilise what is purchased.

Do you need a Microsoft 365 Audit?


To understand if your organisation can benefit from a Microsoft 365 Audit, ask yourself, and your team, these questions:

  • Are we utilising Microsoft Intake and Endpoint Management for maximum security?
  • Are we using our licensing and features to full potential?
  • Have we double-checked that all users are using strong passwords?
  • Is multi-factor authentication (MFA) enabled for all users?
  • Do we know how many users have administrative roles?
  • Are we monitoring failed sign-ins?
  • Do we have anti-phishing policies in place?
  • Do you have a way to monitor user needs on an ongoing basis?

If you answered no to any of the above questions, it is time to audit your Microsoft 365 tenant. For a total peace of mind, we recommend a comprehensive Microsoft 365 health check, performed by Microsoft-licensed experts. With the right auditing tools, it is easy to pinpoint the steps you need to take to optimise your Microsoft 365 licensing to improve security and save costs.

Talk to our team of Microsoft-licensed specialists to get started with your Microsoft 365 audit. It is OK too if you prefer to run a quick M365 health check in-house. Here are a few simple steps that will help you get on the right path:

  • Clean up inactive and unused licenses
  • Remove duplicate users
  • Investigate your app usage and adjust where possible