Leadership advisorySix chapters · vendor-neutral

A Microsoft 365 health check for boards and leaders

Six questions any well-run Australian business should be able to answer in writing about its Microsoft 365 tenant.

This is not a sales document. It is the same framework we use when leadership teams ask us to review a tenant they already manage themselves, or one managed by another provider. The aim is clarity, not change.

Identity posture

Admins, MFA, Conditional Access

Recoverability

Tenant backup independent of Microsoft

Written findings

Retained by the business, vendor-neutral

01

Identity

Identity is now the perimeter.

Who can sign in, from where, and as whom.

Most Microsoft 365 incidents in 2025 and 2026 began at the identity layer rather than the endpoint. A health check confirms the business knows, in writing, who holds Global Administrator, how MFA is enforced, and whether legacy authentication is still permitted.

Q01

Who holds Global Administrator access?

Names, accounts and any third-party vendors with persistent admin rights.

Evidence · Privileged role report

Q02

Is MFA enforced for every active user, including admins?

No exclusions, no exceptions, no legacy auth bypass.

Evidence · Authentication methods report

Q03

Are break-glass accounts documented and tested?

Stored independently of the standard password manager, with documented annual test.

Evidence · Break-glass procedure document

Q04

Is legacy authentication blocked at the tenant level?

Basic auth, IMAP and POP turned off unless explicitly required.

Evidence · Authentication methods policy

02

Conditional Access

Policies should be written down, named, and reviewed.

Conditional Access is the actual security boundary.

Conditional Access has quietly become the most consequential part of any Microsoft 365 tenant. It is also the most common area where well-meaning configuration drifts over time without leadership ever being aware.

Q01

Is there a documented Conditional Access policy library?

Each policy named, scoped, and assigned a clear business purpose.

Evidence · Policy export, reviewed quarterly

Q02

Are sign-ins from outside Australia blocked or challenged?

Either explicit geo-block, or named locations with risk-based step-up.

Evidence · Sign-in logs by country

Q03

Are unmanaged devices restricted from accessing tenant data?

Compliant or hybrid-joined devices only for sensitive resources.

Evidence · Device compliance policies

Q04

Is privileged access protected by stricter Conditional Access?

Admin roles require phishing-resistant MFA and trusted devices.

Evidence · Privileged role policy

03

Backup

Microsoft does not back up your tenant.

Recoverability is the leadership question, not retention.

Microsoft operates the platform. The data inside it is the customer's responsibility. A tenant health check confirms there is an independent, tested, retainable copy of mailboxes, OneDrive, SharePoint and Teams content.

Q01

Is Microsoft 365 data backed up by an independent third party?

Mailboxes, OneDrive, SharePoint and Teams content, retained outside the tenant.

Evidence · Backup vendor and retention policy

Q02

When was the last successful test restore?

Dated, signed-off restore of a real mailbox or document set.

Evidence · Most recent restore log

Q03

How long is data retained after a user leaves?

Aligned to record-keeping obligations, not the default 30-day tenant window.

Evidence · Retention schedule

Q04

Where is the backup data physically stored?

Australian sovereign hosting where data residency matters to the business.

Evidence · Backup vendor data residency statement

04

Licence rationalisation

Most tenants carry licences they no longer need.

Cost is the visible problem. Sprawl is the real one.

Microsoft licensing has become one of the single largest line items in many SMB technology budgets. A health check confirms the business is paying for what it uses, has the right SKU for its security posture, and is not duplicating capability with third-party tools.

Q01

What is the current licence mix and assigned headcount?

Business Basic, Standard, Premium, E3, E5 and any add-ons.

Evidence · Licence assignment report

Q02

Are there licences assigned to users who have left?

Removed promptly as part of the offboarding runbook.

Evidence · Offboarding procedure

Q03

Is the security posture matched to the licence tier?

Defender, Intune and Conditional Access features actually enabled rather than just available.

Evidence · Secure Score, licence utilisation

Q04

Are third-party tools duplicating Microsoft 365 capability?

Common in MFA, MDM, backup and threat protection.

Evidence · Tool inventory vs licence entitlements

05

Data sovereignty

Where the data physically lives is a leadership question.

Privacy Act 1988 obligations attach to the data, not the platform.

Most Microsoft 365 tenants used by Australian businesses are provisioned in the Australia East and Australia Southeast regions, but the question is no longer simply where the tenant is hosted. It is which sub-services, including Teams transcription, Copilot, and recent AI features, process data outside Australia.

Q01

Which Microsoft data residency region holds the tenant?

Australia East and Southeast for most Australian businesses.

Evidence · Tenant data location report

Q02

Are AI and Copilot features processing data outside Australia?

Some features route through US or EU regions even when the tenant is Australian.

Evidence · Microsoft service health and data residency statement

Q03

Have Privacy Act obligations been mapped against the tenant?

Specifically Australian Privacy Principles 8 (cross-border disclosure) and 11 (security).

Evidence · Privacy impact assessment

Q04

Is data classification applied to sensitive content?

Microsoft Information Protection labels or equivalent, applied to financial, HR and clinical records.

Evidence · Sensitivity label policy and adoption rate

06

Governance cadence

A health check is a moment. Governance is a rhythm.

Documented review cycles outlive any individual provider.

The single strongest predictor of a healthy Microsoft 365 tenant is not which provider manages it. It is whether the business runs a documented governance cadence. The questions below ask whether that cadence exists, not who attends.

Q01

Is there a quarterly Microsoft 365 governance review?

Attendees, agenda and outputs documented.

Evidence · Last four governance review minutes

Q02

Is Secure Score tracked over time?

Reviewed at each governance cycle with explicit accept-or-improve decisions.

Evidence · Secure Score trend graph

Q03

Are admin actions logged and reviewable?

Unified audit log enabled, retention aligned to record-keeping obligations.

Evidence · Audit log retention policy

Q04

Is there a documented incident response plan specific to the tenant?

First hour, communication tree, evidence preservation, OAIC notification path.

Evidence · M365 incident response runbook

The deliverable

What a tenant health check report actually contains.

The output of the engagement is a written report a director can read in fifteen minutes and an engineer can deliver from. Six sections, quantified findings, a costed remediation roadmap. Below is the section structure and a sanitised excerpt from a recent engagement.

Typical engagement

Duration

2 weeks

Length

20 to 30 pages

Audience

Board and IT

Includes

Read-out call

01

Tenant snapshot

Plan tier, identity posture, conditional access state, Defender deployment, sensitivity label coverage, Purview retention. The one-page brief a director can read first.

02

Identity and Conditional Access audit

Global Admins named, MFA coverage quantified, break-glass tested, legacy auth state. Each finding mapped to the Essential Eight identity controls.

03

Backup and recoverability evidence

Independent backup vendor, retention policy, date of last successful test restore, sovereignty position. The leadership-facing answer to 'are we recoverable'.

04

Licence rationalisation and Secure Score trend

Licence mix vs assigned headcount, leavers still licensed, Secure Score over the last four quarters, duplicate capability across third-party tools.

05

Data sovereignty and AI surface

Where the tenant data physically lives, which AI and Copilot features route outside Australia, sensitivity label adoption rate, Privacy Act mapping.

06

Prioritised remediation roadmap

Findings sorted Now, Next, Later. Each item costed in engineer hours and licence dollars. Directors-readable at the front, delivery plan at the back.

Excerpt: Section 06 prioritised findings

Sanitised
Book a tenant health check

Two-week engagement. Read-out call included. Indicative pricing on the first call.

If you would like a documented review

A tenant health check is a fixed-scope advisory engagement.

We document findings against the six chapters above, score each one against a written rubric, and hand the report to the business. There is no requirement to change provider, change licensing, or buy anything. Many businesses use the report to strengthen the relationship they already have.

A health check is an advisory exercise. The findings belong to the business.

Cookie Preferences

We use cookies to improve your experience, analyse site traffic, and personalise content. By clicking "Accept All", you consent to our use of cookies. Privacy Policy

Privacy Act 1988 compliant. Your data is never sold.