Microsoft 365 Security Audit for Small Business | Flat-Fee
Microsoft 365 Security Audit

Your business runs on Microsoft 365. Is it configured to protect you?

Most M365 tenants are one checkbox away from a breach — MFA gaps, forgotten forwarding rules, wide-open sharing. This flat-fee audit reviews every security-relevant setting in your tenant and hands you a plain-English report on what to fix, in what order.

Delivered in 3 business days · Read-only access · No contracts

M365 Security Audit
Prepared for Sample Client Co. · 32 users
94
Settings reviewed
17
Findings
4
Critical
Admin accounts without MFA3 found · critical
Legacy authenticationenabled · disable
External mail forwarding6 rules · review
Anyone-link file sharingunrestricted · restrict
Priority: 3 administrator accounts can be signed into with only a password — the #1 way business email compromise starts.
Default ≠ secure
Microsoft 365 ships configured for convenience — securing it is left to you
#1
business email compromise is the costliest attack on small businesses — and it starts in M365
$0
for most fixes — they're settings changes in licenses you already pay for
0 hours
of your team's time — read-only access, no installs, no disruption
See for yourself

How locked down is your tenant? Answer five questions.

No email required, no signup — an instant read on the five settings attackers check first. Be honest; "not sure" is the most common answer, and it counts.

Your tenant grade appears here as you answer.
What we audit

Your entire Microsoft 365 stack — every corner of the tenant.

Full coverage of the Business Premium security suite: Entra ID, Exchange Online, Intune, Defender, and Purview — benchmarked against Microsoft's own security guidance and CISA's recommendations, not a generic checklist.

Entra ID — identity & sign-in

  • MFA coverage — every user, every admin, no exceptions unaccounted for
  • Admin role sprawl and unused privileged accounts
  • Legacy authentication protocols attackers exploit
  • Conditional Access policy design and gaps

Email & Exchange Online

  • Forwarding and transport rules quietly exfiltrating mail
  • Anti-phishing, anti-spoofing, and safe-attachment policies
  • SPF, DKIM, and DMARC — configured and enforcing
  • Mailbox permissions and delegation review

Files, sharing & Teams

  • SharePoint and OneDrive external-sharing exposure
  • "Anyone" links and anonymous access to company files
  • Teams external access and guest permissions
  • Data-leakage paths out of your tenant

Intune — devices & endpoints

  • Device compliance policies — what's allowed to touch company data
  • Endpoint configuration and security baselines
  • Mobile and BYOD app protection
  • Update and encryption enforcement across the fleet

Purview — data protection & insider risk

  • Data loss prevention policies for the data that matters
  • Sensitivity labeling and information protection
  • Insider Risk Management configuration and coverage
  • Retention — keeping what you must, purging what you shouldn't

Defender — monitoring & response

  • Defender for Business / Office 365 policy configuration
  • Audit logging enabled and retained — evidence when you need it
  • Secure Score review with prioritized improvements
  • Alerting for the events that actually matter
Get My Risk-Free Estimate

Custom flat-fee quote · no payment info · one business day

How it works

Three steps. Zero hours of your team's time.

1

Check out online

Pick your tier and pay by card. You'll receive simple instructions to grant time-limited, read-only auditor access — we can see settings, never change them, and never read email content.

Your time: 10 minutes
2

We audit your tenant

Every identity, email, sharing, and defense setting reviewed against Microsoft and CISA benchmarks by a Microsoft-certified security specialist — not a script.

Your time: none
3

Get your report & fix-it plan

Within 3 business days: every finding explained in plain English, ranked by real risk, with click-by-click remediation guidance your IT person can follow. Access is revoked on delivery.

Your time: one coffee + a 30-min call

Audited by a Microsoft-certified security specialist

This isn't a generic scan reseller. Your audit is performed personally by Edith Forestal — CISSP, CISM, and holder of Microsoft's own security certifications across 365 administration, identity, security operations, and Azure.

MS-102 SC-300 SC-200 AZ-500
// About the founder

Your audit isn't generated by a tool. It's signed by a person.

I'm Edith Forestal. I've spent over a decade building and running technology companies — and Microsoft 365 security is where I live: identity, email, endpoints, and the data flowing between them. I hold Microsoft's own certifications across 365 administration, identity, security operations, and Azure, alongside CISSP and CISM.

Every audit is performed and signed by me personally — and I'm the one on your findings call. No account managers, no offshore SOC, no upsell script.

CISSP CISM MS-102 SC-300 SC-200 AZ-500
Edith L. Forestal, CISSP — Microsoft-certified security specialist
Edith Forestal | Founder
CISSP, CISM, and
security consultant
LinkedIn
Your estimate

Every tenant is different. Your price should be too.

Answer a few quick questions about your environment and I'll send you a custom, flat-fee quote within one business day. Risk-free — no payment info, no obligation, and the estimate is yours either way.

Custom flat-fee quote within one business day · no payment info · no obligation

Request received.

Your custom estimate is being prepared — expect it from Edith within one business day.

Questions

The things every owner asks first.

What access do you need — can you read our email?

We use a time-limited, read-only auditor role (Global Reader). It lets us see how your tenant is configured — it cannot change settings, and it cannot open or read the content of anyone's email or files. Access is removed the day your report is delivered, and the report documents exactly what was accessed.

Is this a full Microsoft 365 security audit?

Yes — 90+ security-relevant settings across the Business Premium stack: Entra ID identity and MFA, admin roles, Conditional Access, legacy authentication, Exchange Online mail flow and anti-phishing, SharePoint/OneDrive/Teams sharing, Intune device compliance, Purview data protection and Insider Risk, audit logging, and Defender policies, benchmarked against Microsoft's security guidance and CISA's recommendations for M365.

How much does a Microsoft 365 security audit cost?

Every quote is a custom flat fee scoped to your tenant — most small-business audits land well under what security firms charge ($2,500–$8,000, billed hourly). Answer the five scoping questions above and you'll have your exact number within one business day, with no payment info and no obligation.

Will you fix the problems too?

The report is written so your existing IT person (or IT company) can make the changes — most are settings, not purchases, with click-by-click instructions included. If you don't have anyone, the findings call includes honest guidance on getting the work done.

We just set up M365 recently — do we still need this?

New tenants are often the most exposed: Microsoft's defaults favor convenience, and setup guides rarely cover security hardening. An audit early is far cheaper than an incident later — and gives you a clean baseline to maintain.

Who performs the audit?

Edith L. Forestal — CISSP, CISM, and holder of Microsoft's security certifications (MS-102, SC-300, SC-200, AZ-500), with over a decade running technology companies. Every audit is performed and signed personally, not generated by a scanning tool.

Three business days from now, you could know your tenant is locked down.

Or that it isn't — and exactly how to fix it, in order, mostly for free. Either answer beats not knowing.

Get Your Risk-Free Estimate
© 2026 Forestal Security LLC · Kokomo, Indiana
Edith L. Forestal, CISSP, CISM, CASP+/SecurityX · Founder