Microsoft 365 security audit
The auditor asks 12 questions. Your tenant already knows the answers.
Who can access what, how much is shared outside the company, which sensitive files carry no label, which admins have not signed in for months. In most tenants that takes a quarter of scripts and screenshots. 1Security keeps every one of those answers live for your Microsoft 365 security audit - as a filtered list with an export button, ready the day the request lands.
The problem
The evidence exists. Collecting it is the project.
ISO 27001, SOC 2, NIS2, a customer due-diligence questionnaire - the questions have the same shape every year. Who has access to sensitive data? How much of it is reachable from outside? Are dormant and privileged accounts under control? Is the labelling policy actually applied? Can you prove the last audit findings were fixed?
The answers live in different places - site permissions here, group memberships there, guest lists in a third, activity in a fourth - and none of them tells you on its own what a group actually opens or which guests hold access through SharePoint alone. So the audit becomes a collection project: it is common to see 100+ hours of admin time per audit, and the report describes a tenant that has already changed by the time it is submitted.
The numbers that come out are usually a surprise as well: hundreds of thousands of files reachable by an ordinary account, thousands of "anyone" links that never expire, sensitive files with no label in the majority of sites, and a handful of admin accounts that have not signed in this year. An audit is the worst moment to learn that.
In practice
The audit binder, assembled in an afternoon.
Each item on the evidence list is a filtered live view in 1Security with an export button.
- 01
Show who can actually access what
Open Users, sort by files reachable, and the accounts worth reviewing first are on top - the assistant who can open 400,000 files through three nested groups. Open a finance site and see every user, group, app and sharing link that opens it, with the path behind each one. Effective access, not the org chart.
- 02
Count what is shared outside
Open Files and filter to "shared with anyone" - the anonymous links, typically thousands in a mid-size tenant. Add "with sensitive info" and you have the list the auditor will ask for. Do the same for external users on Sites and for guests who have not signed in for a year but still hold access.
- 03
Prove accounts are under control
Users filtered to no sign-in for 90 days with a license: the dormant list, usually 10-30% of paid seats. Cross admin roles with missing MFA registration: the privileged-gap list. Both export as they stand, with last sign-in dates.
- 04
Measure the controls, then show the fixes
Files filtered to "with sensitive info" and "without label" is your label coverage gap as a number, quarter over quarter. Actions holds every remediation - links revoked, permissions removed, guests deleted - with who approved it and when, so last year's findings come with closing dates.
What makes it work
Live state beats collected evidence.
The audit workflow runs on three parts of the platform you can read about in depth.
The permission graph
Effective permissions resolved across nested groups, site inheritance, sharing links and app grants - the one source every audit question reduces to.
Explore access management →Answers, exportable
Saved views, full exports and sensitive-data counts with confidence levels - quote high-confidence matches only when the number goes to a regulator.
Explore reporting →Site-level governance
Every SharePoint site ranked by external exposure, sensitive content and abandonment, so the riskiest sites lead the audit instead of hiding from it.
Explore SharePoint governance →
FAQ
Common questions.
How long before we can run an audit this way?
Connection is a read-only consent and the first numbers appear the same day. Full depth depends on tenant size: a tenant under 100,000 files resolves in hours; the largest tenants with tens of millions of files take weeks to map completely. Connect before audit season, not during it.
Which frameworks does the evidence map to?
ISO 27001 and SOC 2 access-control and monitoring requirements, GDPR accountability, and NIS2 Article 21 measures - including the "effectiveness assessment" that asks for exactly the coverage-as-a-number view 1Security produces. The sensitive-info screen also filters by framework: GDPR, HIPAA, PCI-DSS, SOX, CCPA, FERPA.
Point-in-time or continuous evidence?
Both. Every view is live and exports as the point-in-time artifact, and the trend boards plus up to three years of retained activity history show the control operating over time - the part annual screenshots can never prove. You go from 180 days of audit history to three years, on the licenses you already have.
Do we need a premium license, or an agent on every machine?
Neither. 1Security runs on standard Microsoft 365 licenses with a read-only app registration. Sensitive-data detection uses our own scanning engine, so label coverage and personal-data counts work on standard licenses, and Purview labels are imported and shown next to our own detections.
Walk into the audit with numbers.
Connect read-only and see your own audit answers - effective access, external exposure, label coverage, dormant admins - before anyone asks for them.
Or start the screenshot quarter again next year.