Skip to main content

OKAudit365

Your real Microsoft 365 configuration, turned into an audit report that holds up

OKAudit365 reads your tenant in read-only mode and returns a score traceable control by control, the mapping to ISO 27001, ENS and GDPR, and signed evidence anyone can verify.

More than 200 security controls · No agents, no installation · Data held in Spain

OKAudit365 — Regulatory compliance
Tenant posture panel in OKAudit365: overall score out of 100, classification band, comparison with the Microsoft Secure Score and evolution over time.

The problem

Knowing the state of the tenant and being able to prove it are two different things

The Microsoft portal shows the tenant status, but does not produce verifiable evidence.

Governance tools focus on SharePoint and Teams and leave identity, email and endpoints out.

A consultancy report in a spreadsheet gives no way to verify, six months later, what was checked or how.

OKAudit365 closes that gap: a score traced control by control and evidence sealed cryptographically.

Deliverables

What comes out of every audit

Material ready to hand to your board, to a client or to an auditor.

Score from 0 to 100

Five published bands and a control-by-control breakdown: every point traces back to a specific indicator. The methodology is public and versioned, and each audit records which version produced it.

Prioritised remediation plan

Ordered by the points each action recovers. Every action states which console it is applied in — Entra ID, Exchange, Intune, Defender or Purview — and how much the score rises.

Regulatory mapping

ISO/IEC 27001 (Annex A), ENS (Spanish RD 311/2022) and GDPR, with the scope limit declared on each control.

PDF report and export

Two formats, executive and detailed, with the cryptographic fingerprint printed on the cover. Control-by-control CSV export and evidence package.

Sealed evidence

Every audit is sealed with SHA-256. Delivered reports and snapshots keep their evidence and can be re-verified to prove they have not been altered.

History and scheduled scans

Score evolution between scans, with methodology changes flagged to tell them apart from real changes in the tenant. Daily, weekly or monthly cadence, unattended.

Prioritised by recoverable points

Each action shows the points it recovers, its status and the Microsoft 365 service where it applies. The order is determined by the return of each one.

OKAudit365 — Remediation plan
Prioritised remediation plan in OKAudit365: actions ordered by recoverable points, with their implementation status and the Microsoft 365 service they affect.

Where each finding lands

Impact against likelihood, with findings distributed across the grid. The top-right quadrant concentrates what needs attention first.

OKAudit365 — Risk matrix
OKAudit365 risk matrix: an impact-versus-likelihood grid showing the number of findings in each cell and the pillar they belong to.

Control by control, with the scope declared

Each Annex A control shows its findings and the exact remediation, including the console path where it is applied. At the top, inside the report itself, it states which part of the standard can be verified technically and which cannot.

OKAudit365 — ISO/IEC 27001:2022, Annex A
Detail of the ISO/IEC 27001 Annex A mapping in OKAudit365: scope notice, affected controls, findings per control and the specific remediation for each one.

Getting started

How the audit works

No server installation, no agents on devices, no service accounts and no global administrator.

  1. 1

    Authorisation

    You open an admin consent URL and approve the application. A single click.

  2. 2

    Automatic verification

    The platform checks which modules are operational in your tenant and which need an additional permission.

  3. 3

    First scan

    It starts once the permissions have finished propagating in the tenant, which can take several hours. When it finishes there is a score, findings, a remediation plan and a downloadable report.

  4. 4

    Scheduling

    You set the audit cadence and subsequent scans run unattended.

Coverage

What the Microsoft 365 audit evaluates

More than 200 security controls read from the Microsoft Graph API in read-only mode, organised into five pillars weighted by their impact on risk. Efficiency is scored separately, with its own set of controls.

How the method is calibrated

The method is our own and is calibrated against three external references, each with a date and a written rule: the Microsoft Secure Score, the CIS Microsoft 365 Foundations Benchmark as a weight floor, and public incident evidence (Verizon DBIR and the Microsoft Digital Defense Report) for how weight is distributed across pillars.

OKAudit365 — Status by pillar
Status by pillar in OKAudit365: identity and access, email security, endpoints, collaboration and governance, each with its percentage, weight and worst-performing control.
27%

Identity and access

MFA and its quality — phishing-resistant versus SMS —, conditional access and its gaps, global administrators, PIM, unprotected privileged accounts, legacy authentication and inactive accounts.

22%

Email security

EOP anti-phishing and anti-spam, transport rules that bypass the filter, automatic forwarding to external domains, SPF, DKIM and DMARC per domain, and third-party applications with mailbox access.

17%

Endpoints

Intune compliance, disk encryption, operating system lifecycle — devices out of support on Windows 10 and 11 —, update rings, real enforcement of compliance policies and Defender hardening settings, with the detail of which devices fail.

17%

Collaboration

External sharing in SharePoint and OneDrive, anonymous links, guests and their activity, and orphaned sites.

17%

Governance

OAuth applications with permissions over data, expired secrets and certificates, the audit log, the effective quality of policies and Shadow IT.

0 %

Efficiency is scored separately

Cost, licensing and adoption have their own score and play no part in the security score. Mixing spend with posture would distort both.

OKAudit365 — Licences and costs
Licence analysis in OKAudit365: estimated monthly spend, waste, cost per user, recoverable amount and savings opportunities by product.

The quality of MFA

It separates phishing-resistant methods from those an attacker can bypass, and measures the distance between the tenant and full coverage.

OKAudit365 — MFA coverage
MFA analysis in OKAudit365: strength of the default method, methods registered by users, path to full coverage and coverage by domain.

Every control, with its risk and its fix

Email pillar controls are split between those that pass, those that pass only partly and those that fail. Each one explains the specific risk it leaves open, how many points fixing it returns, and carries the step-by-step to do it.

OKAudit365 — Email security
Email security pillar in OKAudit365: controls that pass, are partial or fail, with those requiring action filtered by severity and their step-by-step remediation.

Sites with no active owner

External sharing, syncing on personal devices and unrestricted site creation, alongside the storage piling up with no active owner.

OKAudit365 — SharePoint governance
SharePoint governance diagnostics in OKAudit365: external sharing, syncing on unmanaged devices, unrestricted site creation and the surface of sites without an active owner.

Origin of sign-in attempts

Failed sign-in attempts are classified as attack, suspicion or user error, with their geographic origin, and the report states whether any of them succeeded.

OKAudit365 — Origin of failed sign-ins
Threat panel in OKAudit365: users at risk, Defender alerts, failed sign-ins classified as attack, suspicious or benign, and a world map showing their origin.

Optional modules

They widen the evidence if the client enables them. If a module is not enabled, its sections are declared unavailable with the reason: it never subtracts points and is never read as non-compliance.

  • Exchange Online over a certificate-based connection: the real mail configuration.
  • Purview: DLP, retention, sensitivity labels and their actual adoption.
  • Defender for Endpoint: which devices fail each setting, by name.
  • Defender for Cloud Apps: Shadow IT by network traffic. Which services receive organisation data, how many gigabytes leave, and who is sending information to generative AI services.

What leaves the organisation, and towards which AI

With Defender for Cloud Apps it measures real device traffic: which third-party services receive data, how many gigabytes leave and how much of that goes to generative AI services. The measurement is taken from device network traffic.

OKAudit365 — Shadow IT and generative AI
Applications and Shadow IT panel in OKAudit365: third-party services receiving data, volume sent, low-confidence services and a breakdown of the generative AI services in use.

What actually gets classified, and what enters Copilot

With Purview you see the real adoption of labels — how many are applied consciously and how many by default —, DLP matches and which Copilot interactions touched files classified as sensitive.

OKAudit365 — Purview and AI governance
Purview panel in OKAudit365: events analysed, labelled items, DLP matches, real classification adoption and Copilot interactions with sensitive files.

The real mail configuration

With a certificate-based connection it reads transport rules, EOP policies, anti-spam, anti-phishing and automatic forwarding: what the Graph API does not expose.

OKAudit365 — Exchange Online
Exchange Online configuration in OKAudit365: transport rules, filter bypass, EOP policies, anti-spam, anti-phishing, anti-malware and forwarding configured on mailboxes.

Which devices fail each setting

With Defender for Endpoint you see the recommended settings not yet applied across the estate, with the coverage percentage and how many devices remain exposed on each one. The figures are Microsoft’s, shown as they come.

OKAudit365 — Defender for Endpoint
Pending security settings in OKAudit365: Microsoft Defender recommendations grouped by category, with their severity, the percentage applied and the number of exposed devices.

Access security

What it asks for and what it cannot do

36 permissions, all read-only. The answers the security committee will ask for, provided up front.

Read-only

No write permission over the tenant. It modifies nothing and deletes nothing.

Never content

It reads configuration, metadata and security signals. Never message bodies, files or Teams conversations.

No global administrator

No service accounts either. The Exchange module uses a certificate with a read-only role.

Data held in Spain

Azure, Spain Central region. Processing and storage in Spain, with a dedicated container per client.

Permissions justified one by one

The list is audited against the code and delivered justified at onboarding. If a permission stops being used, it is removed.

Verifiable and revocable

The consent is recorded in your Entra ID: the 36 permissions can be reviewed there and removed from Enterprise applications, with no action needed from us.

Method honesty

How it avoids false positives and false greens

A report is only useful if whoever signs it can defend it. These rules live inside the product.

  • If a data point cannot be read, the control is skipped rather than inventing a result. Absence of findings is never presented as compliance.

  • Capabilities that depend on licensing — Entra ID P1 and P2, Intune, Purview — do not penalise if you have not purchased them.

  • The report states how much of the catalogue could be evaluated in your tenant. A control that does not apply, because the service is not licensed or not in use, neither counts as non-compliance nor inflates the score: it is removed from the calculation and declared.

  • If a collection is truncated by volume, it is flagged as partial.

  • When a data point allows two legitimate readings, it is flagged for manual review instead of picking the worst one.

  • The mapping to the CIS Microsoft 365 Foundations Benchmark covers part of the catalogue and is declared control by control: it cites the topic and level of each equivalent recommendation, without reproducing its text.

What makes it different

  • It evaluates the full security posture of the tenant: identity, email, endpoints, collaboration and governance.
  • It includes the mapping to ENS (Spanish RD 311/2022), for public administration and the companies that work with it.
  • It delivers evidence sealed with SHA-256 that can be verified months later.
  • It is multi-tenant: built for consultancies and MSPs auditing portfolios of clients.
  • Being read-only and using no service accounts, its approval by the security committee is easy to justify.

Limits

What OKAudit365 is not

The limits of the scope, declared up front.

It is not a certification

OKAudit365 shows controls with evidence for and against. Certifying is the job of an accredited body.

It does not protect or block

It audits and produces evidence. It is not an antivirus, an EDR or a firewall: it does not stop an attack in progress.

It does not go beyond Microsoft 365

The scope is the tenant. Whatever happens on your local network, your servers or other clouds is out of scope.

Options

Two ways to engage OKAudit365

A project with a beginning and an end, or a continuous service. The platform is the same in both cases.

Project

One-off audit

For a specific need: preparing an ISO 27001 or ENS audit, answering a client, or learning the real state of the tenant.

  • Full tenant scan
  • Executive and detailed report, with sealed evidence
  • Prioritised remediation plan
  • 30 days of platform access to work through the plan
  • On closure, deletion of the client container with written confirmation
Request a quote

Continuous service

Subscription

To stay in control over time: every change in the tenant shows up in the next scan and remediation is verified.

  • Automatic scans, daily or weekly, plus manual scans
  • Platform always available, with history and regulatory snapshots
  • Three levels of support: platform only, quarterly review or monthly review with the Okiou team
  • Annual commitment, billed monthly or quarterly
Request a quote

The price is set by the tenant’s user band and is communicated in the proposal. Remediation work and derived projects are quoted separately.

Frequently asked questions

Do you need global administrator permissions?

No. Onboarding uses an admin consent URL that approves the application in read-only mode. No service accounts are created. The Exchange module, if enabled, uses a certificate with a read-only role.

Can it affect the tenant or our users?

No. OKAudit365 holds no write permission: it modifies nothing, deletes nothing, and installs no agents or software on devices. Users do not notice the scan.

What if we do not have Entra ID P2, Intune or Purview?

Controls that depend on those licences do not penalise. Their sections are declared unavailable stating the reason, and the score is calculated on what can actually be evaluated.

What happens after the audit?

The report and the evidence package are yours, and the remediation plan can be executed by your own team. If you prefer us to implement it, we quote from the plan itself, with the scope closed before starting.

Request an audit

Tell us the size of your organisation and we will send the proposal and next steps within one business day.

Required fields