This audit was generated at m365audit.org.
High
Medium
Low
Organization details, high-level counts, and SharePoint storage usage. Admin portal →
| Active users 47 |
Groups 12 |
Verified domains 3 |
SharePoint storage
Subscribed Microsoft 365 licenses and assigned vs. available seats in your tenant. Licenses section of the Admin portal →
| License | Total | Consumed | Remaining |
|---|---|---|---|
| Microsoft 365 Business Premium | 50 | 47 | 3 |
| Microsoft Teams Phone Standard | 10 | 8 | 2 |
| Power BI Pro | 5 | 4 | 1 |
These domains have been added to the Microsoft 365 admin portal. Domains in admin portal →
Managed: Microsoft 365 manages sign-in for this domain.
Federated: A third-party identity provider manages sign-in via SSO.
| Domain | Authentication | Default | Initial |
|---|---|---|---|
| hopecommunity.example | Managed | Yes | No |
| hopecommunity.onmicrosoft.com | Managed | No | Yes |
| hopefoundation.example | Managed | No | No |
Authentication and identity posture across your Microsoft 365 tenant. Entra admin portal →
How user accounts are protected by MFA registration, Conditional Access, and Security Defaults. Entra admin portal →
| MFA registered 45 |
MFA enforced 43 |
Without enforcement 4 |
| Covered by CA MFA 43 |
Covered by Security Defaults 0 |
Registered only (not enforced) 2 |
Tenant-wide identity configuration including Security Defaults and Conditional Access policy count. Entra admin portal →
| Security Defaults | Disabled |
| Enabled CA policies | 4 |
| Groups | 12 |
| Verified domains | 3 |
Recommended Microsoft 365 settings for nonprofit organizations, grouped by area. ✅ aligned · ❌ action recommended · — not verified. Entra admin portal →
Tenant-wide settings that affect security posture across Microsoft 365, including audit logging and external sharing. Microsoft Purview compliance portal →
| Check | Status | Notes |
|---|---|---|
| Enable Unified Audit Log | ✅ | Unified audit logging is enabled (Microsoft Graph) |
| Show usernames in reports | ✅ | Reports display identifiable usernames (Microsoft Graph) |
| Restrict guest user directory access | ❌ | Guests have limited rather than restricted directory access (Microsoft Graph) |
Microsoft Defender for Office 365 checks verify email and collaboration protections recommended for nonprofit tenants. Microsoft Defender portal →
| Check | Status | Notes |
|---|---|---|
| Anti-phishing policy | ✅ | Anti-phishing protection is configured |
| Safe Links for email messages | ✅ | Safe Links is enabled for email |
| Safe Links for Office applications | ❌ | Safe Links for Office applications is missing from your environment |
| Safe Attachments policy enabled | ✅ | Safe Attachments is enabled |
| Safe Attachments in block mode | ❌ | Safe Attachments is configured for dynamic delivery instead of block mode |
| Zero-hour auto purge (phishing) | ✅ | ZAP for phishing is enabled |
Exchange Online settings for mail transport, archiving, DKIM, and mailbox security. Verified via Microsoft Secure Score recommended actions. Exchange admin portal →
| Check | Status | Notes |
|---|---|---|
| Block external mail forwarding | ❌ | Automatic external forwarding is allowed |
| DKIM signing enabled | ✅ | DKIM is enabled for the primary custom domain |
| Mailbox auditing enabled | ✅ | Mailbox auditing is enabled by default |
| Modern authentication enabled | ✅ | Modern authentication is enabled |
| Shared mailbox sign-in disabled | ❌ | Two shared mailboxes permit direct sign-in |
SharePoint and OneDrive tenant settings for external sharing, sync, and site security. Verified via Microsoft Graph and Microsoft Secure Score recommended actions. SharePoint admin portal →
| Check | Status | Notes |
|---|---|---|
| Disable custom scripts on SharePoint sites | ✅ | Custom scripts are restricted |
| Disable legacy basic authentication for SharePoint | ✅ | Legacy authentication protocols are disabled (Microsoft Graph) |
| Disable Legacy Workflows | ❌ | Legacy workflow features are still available |
| Disable Re-sharing by External Users | ✅ | External users cannot re-share content (Microsoft Graph) |
| Disable SharePoint Store access | ✅ | SharePoint Store access is disabled |
| Disallow downloading infected files from SharePoint | ✅ | Infected file downloads are blocked |
| Enable SharePoint and OneDrive integration with Azure AD B2B | ✅ | Azure AD B2B integration is enabled |
| Set Add Shortcuts To OneDrive button state | ✅ | Add to OneDrive shortcuts are available |
| Hide SharePoint sync button (prefer OneDrive shortcuts) | ❌ | Sync button is visible on personal OneDrive sites (Microsoft Graph) |
Microsoft Teams messaging safety settings for weaponizable file and malicious URL protection. Verified via Microsoft Secure Score recommended actions. Microsoft Teams admin center →
| Check | Status | Notes |
|---|---|---|
| Enable Weaponizable File Protection | ✅ | Weaponizable file protection is enabled |
| Enable Malicious URL Protection | ❌ | Malicious URL protection is missing from your environment |
Microsoft Intune device enrollment and Windows management settings verified via Microsoft Graph where available. Microsoft Intune admin center →
| Check | Status | Notes |
|---|---|---|
| Require MFA to register or join devices | ✅ | MFA is required for device registration (Microsoft Graph) |
| Set device cleanup rules | ✅ | Inactive devices are retired after 90 days (Microsoft Graph) |
| Enable Windows diagnostic data | ❌ | Required Windows diagnostic data is not enabled |
| Set Windows Backup and Restore state | ✅ | Windows backup is configured |
Microsoft Entra ID tenant settings verified via Microsoft Graph where available. Authentication method checks recommend enabling FIDO2, software OATH, TAP, and Microsoft Authenticator protections. Entra admin portal →
| Check | Status | Notes |
|---|---|---|
| Complete Authentication Methods Policy Migration | ✅ | Authentication methods migration is complete (Microsoft Graph) |
| Disable M365 tenant creation by users | ✅ | Non-admin users cannot create tenants (Microsoft Graph) |
| Do not expire passwords | ✅ | Cloud-managed passwords do not expire (Microsoft Graph) |
| FIDO2 security key | ❌ | FIDO2 is not enabled for all users (Microsoft Graph) |
| Software OATH tokens | ✅ | Software OATH tokens are enabled (Microsoft Graph) |
| Temporary Access Pass (TAP) | ✅ | Temporary Access Pass is enabled (Microsoft Graph) |
| Microsoft Authenticator | ✅ | Microsoft Authenticator is enabled (Microsoft Graph) |
| Microsoft Authenticator — passwordless | ❌ | Passwordless Authenticator sign-in is not enabled for all users (Microsoft Graph) |
| Microsoft Authenticator — require location | ✅ | Location information is required (Microsoft Graph) |
| Microsoft Authenticator — number matching | ✅ | Number matching is required (Microsoft Graph) |
Recommended Conditional Access controls matched by policy settings. Entra admin portal →
| Check | Status | What we look for | Matching policy |
|---|---|---|---|
| Require MFA for admins | ✅ | Require MFA for privileged directory roles across all cloud apps. | Require MFA for administrators |
| Block legacy authentication | ✅ | Block legacy client protocols for all users. | Block legacy authentication |
| Require MFA for all users | ✅ | Require MFA for all users and cloud applications. | Require MFA for all users |
| Block high-risk sign-ins | ❌ | Block sign-ins assessed as high risk. | — |
| Require compliant devices | ✅ | Require a compliant or hybrid joined device for sensitive access. | Require compliant devices |
User accounts grouped by mailbox type. MFA enforcement reflects Conditional Access (preferred), Security Defaults, or legacy per-user MFA when tenant-wide policies are not in place. Entra admin portal →
Microsoft 365, security, and distribution groups in your directory. Visibility is Public, Private, or Hidden membership (Microsoft 365 groups default to Public when unset). Entra admin portal →
| Display name | Type | Mail-enabled | Visibility | |
|---|---|---|---|---|
| All Staff | [email protected] | Microsoft 365 | Yes | Public |
| Board Members | [email protected] | Microsoft 365 | Yes | Private |
| Programs Team | [email protected] | Security | Yes | Private |
| Intune - Managed Devices | — | Security | No | Private |
| Volunteers | [email protected] | Distribution | Yes | Private |
| Development Team | [email protected] | Microsoft 365 | Yes | Private |
| Finance Committee | [email protected] | Microsoft 365 | Yes | Private |
| Event Coordinators | [email protected] | Distribution | Yes | Private |
| Leadership | [email protected] | Security | Yes | Private |
| MFA Registration Campaign | — | Security | No | Private |
| Conditional Access Exclusions | — | Security | No | Private |
| Newsletter Subscribers | [email protected] | Distribution | Yes | Public |
OAuth consents with sensitive mail, file, or directory access. Review for shadow IT. Entra admin portal →
| Application | Consent type | Granted to | Permissions |
|---|---|---|---|
| Community CRM Connector 2c6e4e78-6d39-4a4d-9421-54dc694a3431 |
Tenant-wide | All users | Mail.Read, Files.ReadWrite.All, User.Read.All |
| Volunteer Scheduling Export b8302f25-a3d1-41db-b421-b55d9ab42f11 |
Tenant-wide | All users | Directory.Read.All, Calendars.Read |
Exceptions and risks are listed below to keep this audit concise.
Active member accounts not covered by Conditional Access MFA, Security Defaults, or legacy per-user MFA enforcement. Entra admin portal →
| Display name | User principal name | MFA registered |
|---|---|---|
| Jamie Carter | [email protected] | Yes |
| Drew Wilson | [email protected] | No |
| Skyler Davis | [email protected] | Yes |
| Robin Clark | [email protected] | No |
Administrative roles with standing access — review regularly and follow least privilege. Entra admin portal →
| Role | Users (sign-in names) |
|---|---|
| Exchange Administrator | [email protected] |
| Global Administrator | [email protected] |
| Security Administrator | [email protected] |
| SharePoint Administrator | [email protected] |
| Teams Administrator | [email protected] |
No interactive or non-interactive sign-in in the last 90 days. Entra admin portal →
| Display name | User principal name | Days inactive |
|---|---|---|
| Former Program Manager | [email protected] | 184 |
| Seasonal Volunteer | [email protected] | 132 |
| Legacy Service Account | [email protected] | 418 |
Shared mailboxes should remain sign-in disabled and unlicensed. Users should access them via delegated Full Access on their own accounts. Exchange admin portal →
| Mailbox | Login | Issue |
|---|---|---|
| Donations | [email protected] | Sign-in enabled |
| Programs | [email protected] | Licensed and sign-in enabled |
These mailboxes forward incoming mail to an address outside your verified domains. Review each destination and remove any forwarding that is not expected. Exchange admin portal →
| Mailbox | Forwards to | Keeps copy | |
|---|---|---|---|
| Executive Director | [email protected] | [email protected] | Yes |
| Events | [email protected] | [email protected] | No |
Mailboxes at or above 90% of prohibit send/receive quota. Exchange admin portal →
| User | Used | Quota | % Used | |
|---|---|---|---|---|
| Morgan Patel | [email protected] | 47.1 GB | 50.0 GB | 94.2% |
Inbox rules that may forward, redirect, delete, or act on all incoming mail. Review regularly to confirm they are legitimate. Exchange admin portal →
| User | Rule | On | Action | When |
|---|---|---|---|---|
| [email protected] | Forward event registrations | Yes | Forward externally |
|
| [email protected] | Delete automated alerts | Yes | Delete message |
|