A Microsoft 365 health check for boards and leaders
Six questions any well-run Australian business should be able to answer in writing about its Microsoft 365 tenant.
This is not a sales document. It is the same framework we use when leadership teams ask us to review a tenant they already manage themselves, or one managed by another provider. The aim is clarity, not change.
Identity posture
Admins, MFA, Conditional Access
Recoverability
Tenant backup independent of Microsoft
Written findings
Retained by the business, vendor-neutral
Identity
Identity is now the perimeter.
Who can sign in, from where, and as whom.
Most Microsoft 365 incidents in 2025 and 2026 began at the identity layer rather than the endpoint. A health check confirms the business knows, in writing, who holds Global Administrator, how MFA is enforced, and whether legacy authentication is still permitted.
Who holds Global Administrator access?
Names, accounts and any third-party vendors with persistent admin rights.
Evidence · Privileged role report
Is MFA enforced for every active user, including admins?
No exclusions, no exceptions, no legacy auth bypass.
Evidence · Authentication methods report
Are break-glass accounts documented and tested?
Stored independently of the standard password manager, with documented annual test.
Evidence · Break-glass procedure document
Is legacy authentication blocked at the tenant level?
Basic auth, IMAP and POP turned off unless explicitly required.
Evidence · Authentication methods policy
Conditional Access
Policies should be written down, named, and reviewed.
Conditional Access is the actual security boundary.
Conditional Access has quietly become the most consequential part of any Microsoft 365 tenant. It is also the most common area where well-meaning configuration drifts over time without leadership ever being aware.
Is there a documented Conditional Access policy library?
Each policy named, scoped, and assigned a clear business purpose.
Evidence · Policy export, reviewed quarterly
Are sign-ins from outside Australia blocked or challenged?
Either explicit geo-block, or named locations with risk-based step-up.
Evidence · Sign-in logs by country
Are unmanaged devices restricted from accessing tenant data?
Compliant or hybrid-joined devices only for sensitive resources.
Evidence · Device compliance policies
Is privileged access protected by stricter Conditional Access?
Admin roles require phishing-resistant MFA and trusted devices.
Evidence · Privileged role policy
Backup
Microsoft does not back up your tenant.
Recoverability is the leadership question, not retention.
Microsoft operates the platform. The data inside it is the customer's responsibility. A tenant health check confirms there is an independent, tested, retainable copy of mailboxes, OneDrive, SharePoint and Teams content.
Is Microsoft 365 data backed up by an independent third party?
Mailboxes, OneDrive, SharePoint and Teams content, retained outside the tenant.
Evidence · Backup vendor and retention policy
When was the last successful test restore?
Dated, signed-off restore of a real mailbox or document set.
Evidence · Most recent restore log
How long is data retained after a user leaves?
Aligned to record-keeping obligations, not the default 30-day tenant window.
Evidence · Retention schedule
Where is the backup data physically stored?
Australian sovereign hosting where data residency matters to the business.
Evidence · Backup vendor data residency statement
Licence rationalisation
Most tenants carry licences they no longer need.
Cost is the visible problem. Sprawl is the real one.
Microsoft licensing has become one of the single largest line items in many SMB technology budgets. A health check confirms the business is paying for what it uses, has the right SKU for its security posture, and is not duplicating capability with third-party tools.
What is the current licence mix and assigned headcount?
Business Basic, Standard, Premium, E3, E5 and any add-ons.
Evidence · Licence assignment report
Are there licences assigned to users who have left?
Removed promptly as part of the offboarding runbook.
Evidence · Offboarding procedure
Is the security posture matched to the licence tier?
Defender, Intune and Conditional Access features actually enabled rather than just available.
Evidence · Secure Score, licence utilisation
Are third-party tools duplicating Microsoft 365 capability?
Common in MFA, MDM, backup and threat protection.
Evidence · Tool inventory vs licence entitlements
Data sovereignty
Where the data physically lives is a leadership question.
Privacy Act 1988 obligations attach to the data, not the platform.
Most Microsoft 365 tenants used by Australian businesses are provisioned in the Australia East and Australia Southeast regions, but the question is no longer simply where the tenant is hosted. It is which sub-services, including Teams transcription, Copilot, and recent AI features, process data outside Australia.
Which Microsoft data residency region holds the tenant?
Australia East and Southeast for most Australian businesses.
Evidence · Tenant data location report
Are AI and Copilot features processing data outside Australia?
Some features route through US or EU regions even when the tenant is Australian.
Evidence · Microsoft service health and data residency statement
Have Privacy Act obligations been mapped against the tenant?
Specifically Australian Privacy Principles 8 (cross-border disclosure) and 11 (security).
Evidence · Privacy impact assessment
Is data classification applied to sensitive content?
Microsoft Information Protection labels or equivalent, applied to financial, HR and clinical records.
Evidence · Sensitivity label policy and adoption rate
Governance cadence
A health check is a moment. Governance is a rhythm.
Documented review cycles outlive any individual provider.
The single strongest predictor of a healthy Microsoft 365 tenant is not which provider manages it. It is whether the business runs a documented governance cadence. The questions below ask whether that cadence exists, not who attends.
Is there a quarterly Microsoft 365 governance review?
Attendees, agenda and outputs documented.
Evidence · Last four governance review minutes
Is Secure Score tracked over time?
Reviewed at each governance cycle with explicit accept-or-improve decisions.
Evidence · Secure Score trend graph
Are admin actions logged and reviewable?
Unified audit log enabled, retention aligned to record-keeping obligations.
Evidence · Audit log retention policy
Is there a documented incident response plan specific to the tenant?
First hour, communication tree, evidence preservation, OAIC notification path.
Evidence · M365 incident response runbook
The deliverable
What a tenant health check report actually contains.
The output of the engagement is a written report a director can read in fifteen minutes and an engineer can deliver from. Six sections, quantified findings, a costed remediation roadmap. Below is the section structure and a sanitised excerpt from a recent engagement.
Typical engagement
Duration
2 weeks
Length
20 to 30 pages
Audience
Board and IT
Includes
Read-out call
Tenant snapshot
Plan tier, identity posture, conditional access state, Defender deployment, sensitivity label coverage, Purview retention. The one-page brief a director can read first.
Identity and Conditional Access audit
Global Admins named, MFA coverage quantified, break-glass tested, legacy auth state. Each finding mapped to the Essential Eight identity controls.
Backup and recoverability evidence
Independent backup vendor, retention policy, date of last successful test restore, sovereignty position. The leadership-facing answer to 'are we recoverable'.
Licence rationalisation and Secure Score trend
Licence mix vs assigned headcount, leavers still licensed, Secure Score over the last four quarters, duplicate capability across third-party tools.
Data sovereignty and AI surface
Where the tenant data physically lives, which AI and Copilot features route outside Australia, sensitivity label adoption rate, Privacy Act mapping.
Prioritised remediation roadmap
Findings sorted Now, Next, Later. Each item costed in engineer hours and licence dollars. Directors-readable at the front, delivery plan at the back.
Excerpt: Section 06 prioritised findings
SanitisedTwo-week engagement. Read-out call included. Indicative pricing on the first call.
If you would like a documented review
A tenant health check is a fixed-scope advisory engagement.
We document findings against the six chapters above, score each one against a written rubric, and hand the report to the business. There is no requirement to change provider, change licensing, or buy anything. Many businesses use the report to strengthen the relationship they already have.
A health check is an advisory exercise. The findings belong to the business.

Remote Support