Identity

Microsoft 365 Auditor

Audits your Microsoft 365 tenant configuration to verify security baselines — MFA enforcement, conditional access, suspicious sign-ins, and per-user risk profiling.

Microsoft 365 Auditor

Complete security visibility for your M365 tenant

What it does

Key capabilities

Security Configuration Audit

Verifies your M365 tenant is configured to Microsoft Secure Score best practices and your internal baseline.

MFA & Password Policy

Validates MFA enforcement across all users and audits password policy compliance, surfacing gaps immediately.

User Risk Profiles

Generates an individual risk score for each user based on sign-in behaviour, policy compliance, and anomalies.

Sign-In Audit Logs

Reviews and surfaces suspicious sign-in activity — failed logins, impossible travel, and legacy authentication use.

Conditional Access Review

Audits your Conditional Access policies to ensure they cover the critical scenarios they are designed to protect.

Compliance Reporting

Produces M365 security posture reports for ISO 27001 and cyber insurance requirements.

Highlights

Why Microsoft 365 Auditor?

  • Verifies MFA across all users automatically
  • Individual user risk profiles for every account
  • Sign-in anomaly detection — impossible travel, legacy auth
  • Conditional Access policy gap analysis
  • Compliance-ready reports for ISO 27001 and insurance
Included in OneView

Microsoft 365 Auditor is part of the Hakware OneView platform. All findings, events, and data from this module flow into your central dashboard alongside every other security signal in your environment.

24/7 Support Available
Phone: +27 060 984 1210
FAQs

Frequently asked questions

The module reviews MFA registration status for every user in your tenant, identifies accounts where MFA is not enabled or enforcement is bypassed via legacy authentication protocols, and flags accounts where MFA is marked as in use but legacy authentication exclusions exist that could allow MFA bypass without triggering alerts.

Each user receives an individual risk score based on: MFA status, sign-in anomalies (impossible travel, unfamiliar location, legacy auth use), failed authentication attempts, risky sign-in detections from Microsoft Identity Protection, and policy compliance gaps. Risk profiles update as new sign-in data is ingested.

The audit reviews your Conditional Access policies against common security baseline scenarios — are all users covered, are admin accounts forced to use compliant devices, are legacy authentication protocols blocked, is MFA required for all cloud app access, and are high-risk sign-ins requiring password change. Gaps are listed with specific remediation steps.

Cyber insurance underwriters routinely require evidence of MFA enforcement across all users. ISO 27001 Annex A.5.16 and A.8.5 require identity management and secure authentication controls. Microsoft 365 Auditor produces compliance-ready reports showing MFA coverage, policy gaps, and risk posture that satisfy both underwriter questionnaires and ISO auditor evidence requests.

See Microsoft 365 Auditor in action

Request a personalised demo and we'll show you exactly how Microsoft 365 Auditor works within your environment.