A Microsoft 365 security audit of the tenant you already run.
F Creative Studio 360 reviews identity, mail, files, Teams and devices for organisations in any country, against the baseline that applies to them.
Microsoft secures the service. The audit looks at what you configured in it.
The review covers a Microsoft 365 tenant: Microsoft Entra ID, Exchange Online, SharePoint, OneDrive, Microsoft Teams, Microsoft Intune, Microsoft Defender and Microsoft Purview.
F Creative Studio 360 does not change the tenant during the audit. Access is read-only, and only for the tenant you authorise.
- Mail, files and identity in one tenant
- A Microsoft 365 tenant holds the accounts people sign in with, the mail they send, and the files they share. A gap in any one of those is a gap in the others.
- Defaults are a starting point
- A new tenant is usable on day one. That is not the same as a tenant whose sharing, guests and administrator roles match the risk you actually carry.
- Detection is not the same as configuration
- A detection product can alert you. It does not, by itself, close an open sharing link, a legacy sign-in path, or an administrator account that never steps down.
- The benchmark that applies to you
- The review is mapped to the framework you have to show, wherever the people and the tenant are based.
What the audit covers
Configuration is compared with the CIS Microsoft 365 Foundations Benchmark and with Microsoft Secure Score as one input. Secure Score records that a control exists. The audit also asks whether that control is set in a way that matches your risk.
- Identity
- Conditional Access, guest access, multi-factor coverage, legacy authentication, sign-in risk, and whether privileged roles are standing or time-bound.
- Mail flow, external forwarding, anti-phishing and anti-spam, shared mailboxes, mailbox auditing, and whether SPF, DKIM and DMARC are in place. We review the settings. We do not send a phishing test.
- Files
- External sharing, anonymous links, sensitivity labels, site permissions, sync restrictions and data-loss rules on SharePoint and OneDrive.
- Teams
- Guest access, federation, who can create a team or a channel, meeting and recording settings, and which apps have been granted access.
- Devices
- Compliance policies, encryption, update rings, app protection, and how personal devices are separated from devices the organisation owns.
- Data governance and detection
- Retention, labelling, insider-risk and eDiscovery settings where the licence includes them, plus how Defender is configured inside the same tenant.
Identity reviews include Conditional Access and Privileged Identity Management. Mail reviews include SPF, DKIM and DMARC. Device reviews include BitLocker where Windows devices are in scope.
How an audit runs
The sequence is the same in any country. People keep using mail, files and meetings while the review is read-only.
- 1
Confirm the tenant
Which services are in scope, and who can grant read-only administration for the review.
- 2
Read the configuration
Identity, mail, files, Teams, devices and compliance settings, compared with the baseline you named.
- 3
Rate the gaps
Findings with evidence, ordered by what would change the outcome, not by how many settings differ from a template.
- 4
Hand back a roadmap
A summary for leadership and a technical list the team that owns the tenant can apply. The tenant is not changed during the audit.
What you receive
- A gap view against the baseline you named, with evidence.
- A reading of Microsoft Secure Score, including controls that are present but not set for your risk.
- Notes on sharing, guests, forwarding and administrator roles.
- A note on which findings the current licences can close.
- A remediation roadmap and a summary a board can read.
Standards the audit can align to
F Creative Studio 360 maps the findings to the references that apply where you operate. The usual set is the CIS Microsoft 365 Foundations Benchmark, Microsoft security baselines, and the NIST Cybersecurity Framework.
The Essential Eight is added only when the organisation is measured against it. Alignment is not a certification. Controls such as Defender for Identity are reviewed only when the licence includes them.
Common questions
What is a Microsoft 365 security audit?+
It is a review of how your Microsoft 365 tenant is configured: identity, mail, files, Teams, devices and data governance. F Creative Studio 360 compares that configuration with the baseline you need and returns a roadmap. It does not certify the tenant.
Where do you deliver this?+
For organisations in any country. The technical review is the same. The report is mapped to the obligations that apply where you operate, such as the CIS Microsoft 365 Foundations Benchmark or the NIST Cybersecurity Framework. A local rule, such as the Essential Eight, is added only when that organisation is measured against it.
How is this different from a cloud security audit?+
A cloud security audit reviews infrastructure accounts: networks, storage, logging and workloads. This audit stays on the Microsoft 365 tenant people use for mail, files, chat and devices. The two can be scoped together when you need both.
How is this different from a penetration test?+
This audit reads configuration. A penetration test tries to show that a weakness can be used. F Creative Studio 360 does not send phishing mail or change the tenant as part of the audit. A test can be a separate engagement when you want proof as well as a review.
Do we need an E5 licence?+
No. The review covers the licences you already have, including a mix. Some controls, such as Defender for Identity and Purview insider risk, exist only on certain licences. The report says which findings you can close now, and which ones a licence change would unlock. It does not require you to change licences.
We already have Microsoft Defender. Do we still need this?+
Defender detects and responds. It does not, by itself, correct a Conditional Access policy, a sharing setting, or an administrator account without a second factor. The audit includes the Defender configuration and the settings it depends on.
Will you change our tenant?+
No. The audit is read-only unless a remediation engagement is agreed afterwards. People keep working while the review is underway.
How much does it cost, and how long does it take?+
It depends on the size of the tenant and which services are in scope. A scoping conversation with F Creative Studio 360 is the way to get a quote and a sensible duration. There is no obligation to proceed.
Start with the tenant that is already live.
F Creative Studio 360 will look at the services in use and the reason for the review, then say what a sensible audit includes.
