Free self-assessment for UK & European SMEs
Microsoft 365 Security Audit for UK SMEs — free, and it prices your licences too.
A free Microsoft 365 security audit you can run yourself, right now, without a sales call or giving anyone access to your tenant. Score fourteen of the controls your regulator and your cyber insurer actually ask about, and calculate the Microsoft 365 licence spend you could reclaim on 2026 UK prices. Every figure shows its workings, so the output stands up in a board meeting or a renewal negotiation.
Your organisation
This tailors the regulatory framing of every finding and sets the scale of the impact model. Nothing here is transmitted anywhere.
How to run a Microsoft 365 security audit yourself
A Microsoft 365 security audit answers two questions at once: is the tenant configured to resist the attacks that actually happen, and are you paying for licences nobody uses. Most UK SMEs have never had either question answered properly, because their IT provider sells licences and their auditor does not open the Microsoft 365 admin centre.
You can do a credible first pass yourself in an afternoon. Here is the order that works.
- Pull your licence position. Microsoft 365 admin centre → Billing → Your products. Export assigned versus purchased seats for every SKU, including add-ons bought years ago that nobody has looked at since.
- Find the dormant seats. Reports → Usage → Active users. Anything with no interactive sign-in in 30 days needs a decision; at 90 days it is almost certainly reclaimable.
- Check the identity controls. In the Microsoft Entra admin centre, confirm multi-factor authentication is enforced for everyone, that legacy authentication is blocked, and count how many accounts hold the Global Administrator role.
- Read your Conditional Access exclusion lists. Not the policies — the exclusions. That is where the temporary carve-out from a 2023 project is still sitting.
- Confirm you have a backup. Microsoft’s shared responsibility model makes your content your problem. If the only answer is “retention policies”, you do not have a backup.
- Score it and price it. Run the calculator at the top of this page. It weights the controls, converts the licence findings into an annual figure, and shows the arithmetic behind each one.
If the result says the problem is real but you have nobody to own it, that is what our fractional CIO and IT consulting services exist for. If you would rather have the tenant measured properly than estimated, see the fixed-price Microsoft assessments.
Microsoft 365 security audit checklist: the 14 controls
Microsoft Secure Score rewards roughly 200 settings, most of which will never appear in an incident report. This Microsoft 365 security checklist scores fourteen. Each was chosen because it either shows up repeatedly as the root cause of real Microsoft 365 compromises, or because a UK regulator, cyber insurer or enterprise client will ask you to evidence it in writing.
The number beside each control is its weight out of 98. A control scores full marks for “yes”, half for “partial” and nothing for “no”.
- 10Multi-factor authentication enforced for every userNot “available”, not “for admins” — enforced tenant-wide, including service accounts and shared mailboxes with sign-in enabled. Microsoft is now mandating MFA for admin centre access, and password-only accounts remain the single most common entry point in business email compromise.
- 9Phishing-resistant MFA for privileged accountsPasskeys, FIDO2 keys or Windows Hello for Business for anyone holding an admin role. SMS and push-approval codes are both defeated by real-time phishing proxies, and SMS is being retired as an Entra ID method.
- 8Legacy authentication is blockedIMAP, POP, SMTP AUTH and older Office clients bypass Conditional Access, and therefore bypass MFA entirely. Microsoft’s own analysis attributes the overwhelming majority of password-spray and credential-stuffing attacks to legacy protocols. While legacy auth is open, every identity control above it is advisory rather than enforced.
- 8Conditional Access governs risky sign-insPolicies that respond to device compliance, location and sign-in risk. This is the control that turns a stolen password into a blocked login rather than a mailbox rule quietly forwarding your invoices.
- 7Global Administrator accounts are few, named and dedicatedFour or fewer, no shared credentials, no day-to-day mailbox on an admin account, and break-glass accounts stored offline. Most tenants we assess carry between eight and twenty Global Admins, usually because a previous MSP left theirs behind.
- 7Defender for Office 365 is active and tunedSafe Links and Safe Attachments switched on for mail, Teams and SharePoint, with impersonation protection naming your directors and finance team. Since July 2026 this is bundled into E3 and Business Premium, so a great many firms own it and have never enabled it.
- 7An independent backup protects Microsoft 365 dataMicrosoft’s shared responsibility model covers the platform, not your content. Retention policies and the recycle bin are not a backup. Ask any firm that has recovered from ransomware whether third-party backup was worth £3 per user per month.
- 7Data Loss Prevention covers client, personal and financial dataDLP policies across Exchange, SharePoint, OneDrive and Teams that actually block or warn, rather than sitting in audit-only mode since the pilot. This is the control that fails hardest under UK GDPR and SRA confidentiality scrutiny — and the ICO’s 72-hour reporting clock starts whether or not you noticed.
- 6Just-in-time privileged accessPrivileged Identity Management, so admin rights are activated for a window with justification and an approval trail rather than held permanently. DORA’s ICT risk requirements point squarely at this.
- 6Unified audit logging is on, with retention that meets your rulesDefault audit log retention is often shorter than the window you would need to reconstruct an incident, and shorter than FCA record-keeping expectations. You cannot enable a log retrospectively.
- 6External sharing and guest access are governedAnonymous “anyone with the link” sharing disabled or expiry-bound, guest accounts reviewed on a schedule, and a named owner for every SharePoint site. Sharing sprawl is how data leaves quietly, without anyone attacking anything.
- 6Devices are enrolled and compliance is enforcedIntune enrolment with policies that check encryption, patch level and antivirus state, plus a Conditional Access rule that refuses non-compliant devices. Enrolment without enforcement is inventory, not security — and device management is one of the five Cyber Essentials control areas.
- 6The incident response plan has been tested this yearA written plan naming who declares an incident, who calls the insurer, who talks to the regulator and within what deadline — rehearsed at least once. Operational resilience rules judge you on the rehearsal, not the document.
- 5Leavers lose access, sessions and tokens within 24 hoursDisabling the account is not enough if refresh tokens stay valid and the licence stays assigned. This is where the security audit and the cost audit meet: the seats you never reclaimed are the identities you never revoked.
Closing these is the substance of our Microsoft 365 security hardening engagement — same checklist, done rather than scored.
Microsoft 365 cost optimisation: the six places money leaks
Across the tenants Innoligo has assessed, reclaimable Microsoft 365 spend clusters into six patterns. The calculator tests for all six. They are listed roughly in order of how much money each usually represents.
1. Over-provisioned licence tiers
The largest single line, almost every time. Someone buys Microsoft 365 E5 for the whole company because the security team needed Defender for Endpoint Plan 2 for thirty people. The gap between E5 and E3 is £18.10 per user per month — £217.20 a year, per person, for features nobody opens. The same logic applies one tier down: under 300 staff, Business Premium carries most of what a typical knowledge worker needs from E3 at roughly half the price.
2. Add-ons you already own
The quietest waste and the easiest to fix. Entra ID Plan 1 is included in Business Premium and both Microsoft 365 E3 and E5, yet firms routinely still carry standalone Entra P1 seats bought before they moved to a bundle. From July 2026, Defender for Office 365 Plan 1 and additional Intune capability moved into E3, and Security Copilot capacity and advanced Intune management moved into E5. Buy any of those separately today and you are about to start paying twice. The add-on step of the calculator matches every add-on against the suites you hold and flags the overlap automatically.
3. Inactive and orphaned licences
Leavers, ended projects, contractors, test accounts, mailboxes inherited from an acquisition. Each one is both a cost line and a live identity. Unused Microsoft 365 licences are the rare finding that improves the security score and the P&L in the same action.
4. Copilot seats nobody uses
Microsoft 365 Copilot is the fastest-growing line on UK SME Microsoft bills and by far the least measured. A seat generating three prompts a week is not adoption, it is a subscription. Measure usage per seat, reassign rather than renew, and treat Copilot as a pool that follows real use. Getting that adoption right is its own discipline — see our AI and Copilot adoption work.
5. Month-to-month billing on a stable headcount
Buying without an annual commitment costs roughly 20% more per seat. That premium is worth paying for genuinely seasonal headcount. It is not worth paying on the core of a business whose staffing has been flat for three years. The usual answer is a hybrid: annual term on the stable base, month-to-month on the fluctuating margin.
6. Frontline workers on desktop suites
Shop-floor, warehouse, clinical and shift staff who need email, Teams and web apps on a shared device rarely need a full desktop suite. Microsoft 365 F3 exists for exactly this population. The saving is modest per head and material at scale — and it needs the most care, because F-plans genuinely do less.
If you want this fixed rather than measured, that is our Microsoft 365 and Azure cost optimisation service.
Microsoft 365 E3 vs E5: what you actually pay for
The most common licensing question we get from UK SMEs, and the one with the most expensive wrong answer. At UK list prices from July 2026, Microsoft 365 E5 costs £51.60 per user per month against £33.50 for E3 — £619.20 versus £402.00 a year. Over 100 people that difference is £21,720 annually.
What the extra buys, in plain terms:
- Entra ID Plan 2 — Identity Protection risk signals, access reviews, and Privileged Identity Management. If you want just-in-time admin rights, this is the line item that provides it.
- Defender for Endpoint Plan 2 — full endpoint detection and response with automated investigation, rather than the antivirus-plus baseline in Defender for Business.
- Defender for Office 365 Plan 2 — threat hunting, attack simulation training and automated remediation on top of the Plan 1 Safe Links and Safe Attachments now bundled into E3.
- Purview advanced compliance — eDiscovery Premium, Insider Risk Management, Communication Compliance and advanced auditing.
- Power BI Pro and Teams Phone — genuine value if you use them, dead weight if you do not. Check before you count them as justification.
The decision rule we apply: E5 is worth it for the users who generate the risk or hold the sensitive data, and rarely worth it for everyone else. A mixed estate — E5 for the executive team, finance, IT and anyone handling client money; E3 or Business Premium for the rest — is almost always cheaper and no less defensible to a regulator. Neither the FCA nor DORA names a licence; both describe outcomes. An unconfigured E5 tenant scores worse in this assessment than a well-run Business Premium one, and costs three times as much.
Microsoft 365 licensing audit: a worked example
An FCA-regulated wealth manager in the South East. 120 mailboxes, licences bought in three waves over five years by two different IT providers — which is to say, a completely ordinary tenant. Every figure uses the July 2026 UK list prices.
| Licence | Seats | £/user/mo | Annual |
|---|---|---|---|
| Microsoft 365 E5 | 30 | 51.60 | £18,576 |
| Microsoft 365 E3 | 70 | 33.50 | £28,140 |
| Business Standard | 12 | 10.80 | £1,555 |
| Microsoft 365 F3 | 8 | 7.70 | £739 |
| Microsoft 365 Copilot | 25 | 24.70 | £7,410 |
| Entra ID Plan 1 (bought standalone in 2021) | 60 | 5.40 | £3,888 |
| Total | 205 seats | £60,308 |
Now the five findings, with the arithmetic in full.
| Finding | Calculation | Annual saving |
|---|---|---|
| 9 E3 seats with no sign-in in 30 days | 9 × £33.50 × 12 | £3,618 |
| 60 standalone Entra ID P1 seats on users already holding E3 or E5 | 60 × £5.40 × 12 | £3,888 |
| 18 E5 users with no E5-only feature use in 90 days → E3 | 18 × (£51.60 − £33.50) × 12 | £3,910 |
| 25 E3 users → Business Premium (headcount is under 300) | 25 × (£33.50 − £16.90) × 12 | £4,980 |
| 11 Copilot seats under four prompts a week | 11 × £24.70 × 12 | £3,260 |
| Total reclaimable | £19,656 |
That is 32.6% of the licence bill, which is higher than typical — we deliberately picked a messy tenant. The range we normally find in a UK SME is 12% to 22%. Anything above 30% usually means two providers have been buying licences without talking to each other, which is exactly what happened here.
The other side of the ledger
The same firm scored 46 out of 100 on the security controls: MFA enforced but not phishing-resistant for admins, legacy authentication still open for a line-of-business application, no third-party backup, DLP in audit-only mode, and eleven Global Administrators. Model five days of disruption from a business email compromise that reaches finance:
- Lost productivity: 120 people × £290 loaded day rate × 5 days = £174,000
- Revenue impairment: £14m ÷ 260 trading days × 5 days, trading at 60% = £107,692
- Response, forensics, legal and notification: £25,000 + (120 × £150) = £43,000
- Modelled cost of one incident: ≈ £325,000
The point is not the precision of £325,000 — it is a scenario, not a forecast. The point is the ratio. Licence savings of £19,656 a year fund the entire remediation programme and a verified audit several times over, before a single pound of new budget is requested. That is the argument that gets signed off, and it is why this page calculates both halves rather than only the frightening one. The government’s annual Cyber Security Breaches Survey is a useful sense-check on how often UK businesses of your size actually experience this.
Microsoft 365 price list UK 2026
Microsoft’s 2026 commercial price increase took effect on 1 July 2026 and raised list prices across most Microsoft 365 and Office 365 suites. It applies globally, including the UK and the Eurozone, and reaches existing customers at their next renewal rather than immediately mid-term. The figures below are the per-user, per-month UK list prices the calculator uses as defaults. All exclude VAT, and CSP or volume pricing may differ from list. Microsoft publishes current retail figures on its own UK Microsoft 365 pricing pages.
| SKU | Before | From 1 July 2026 | Change |
|---|---|---|---|
| Microsoft 365 Business Basic | £4.60 | £5.40 | +17% |
| Microsoft 365 Business Standard | £9.60 | £10.80 | +13% |
| Microsoft 365 Business Premium | £16.90 | £16.90 | 0% |
| Office 365 E1 | £7.70 | £7.70 | 0% |
| Office 365 E3 | £20.60 | £23.30 | +13% |
| Office 365 E5 | £34.10 | £36.80 | +8% |
| Microsoft 365 E3 | £31.00 | £33.50 | +8% |
| Microsoft 365 E5 | £49.00 | £51.60 | +5% |
| Microsoft 365 F1 | £1.73 | £2.30 | +33% |
| Microsoft 365 F3 | £6.20 | £7.70 | +24% |
| Microsoft 365 Apps | £11.70 | £13.70 | +17% |
| Entra ID Plan 1 | £4.60 | £5.40 | +17% |
| Entra ID Plan 2 | £6.90 | £7.70 | +12% |
| Enterprise Mobility + Security E3 | £8.10 | £9.20 | +14% |
| Enterprise Mobility + Security E5 | £12.60 | £13.90 | +10% |
| Defender Suite | £9.20 | £9.20 | 0% |
| Purview Suite | £9.20 | £9.20 | 0% |
| Windows E3 | £5.40 | £5.90 | +9% |
| Windows E5 | £9.90 | £11.50 | +16% |
Three things worth knowing before your next renewal. First, the increases are not uniform: Business Premium and Office 365 E1 stayed flat, while the steepest percentage jumps landed on the lower-cost frontline plans rather than the flagship enterprise suites. Second, Microsoft reviews GBP and EUR pricing against the US dollar roughly twice a year and adjusts local list prices independently of any global change, so a UK renewal quote can carry both the July increase and a separate currency adjustment. Third, Enterprise Agreement volume-tier discounts were removed in late 2025, flattening large accounts to list pricing at their next renewal — which for some estates pushes the real increase well past the headline percentage.
Microsoft 365 Copilot was not part of the July 2026 update. The calculator uses £24.70 per user per month as an indicative figure; adjust it to your own agreement.
Microsoft 365 compliance requirements by sector
The controls barely change between sectors. What changes is who asks, how hard, and what evidence they will accept.
Financial services — FCA and DORA
SYSC expects proportionate systems and controls, and the FCA’s operational resilience regime expects you to have identified important business services, set impact tolerances and tested that you can stay within them. For EU-facing firms, DORA adds explicit ICT risk management, incident reporting deadlines and third-party oversight duties. In Microsoft 365 terms: Conditional Access, privileged access management, audit log retention that survives an investigation, and a tested incident plan naming who reports to whom and when.
Legal — SRA
Client confidentiality under the SRA Standards and Regulations is the hinge. Anonymous SharePoint links, guest accounts never reviewed, and DLP left in audit-only mode are the three findings that become a reportable event fastest. Firms handling client money should also expect their PII insurer to ask specifically about MFA coverage and email impersonation protection.
Healthcare — NHS DSPT
The Data Security and Protection Toolkit is an annual self-declaration with real consequences for supplier status. Its expectations map closely onto the identity and device controls above, and it is unusually explicit about leaver processes and audit logging.
Manufacturing, logistics and energy — NIS2
If you supply into EU essential-services sectors, NIS2 pushes accountability up to management level and requires supply chain security measures. Boards are personally in scope, which changes who signs off remediation. This is the ground our UK–EU compliance and resilience work covers.
Everyone else — Cyber Essentials and UK GDPR
Cyber Essentials is increasingly a condition of winning enterprise and public-sector work rather than a nice-to-have. Its five control areas map almost one-to-one onto the first six items in this assessment, and certification runs through the NCSC’s delivery partner IASME. If you cannot answer “yes” to MFA, legacy authentication and device management, certification will not pass.
Free self-assessment vs a verified Microsoft 365 audit
This tool is honest about its limits. It scores what you already know. A verified audit measures what you do not.
| Question | This free self-assessment | Verified Innoligo audit |
|---|---|---|
| Inactive licences | Your estimate | Measured from sign-in logs, per seat |
| Feature utilisation | Your estimate | 90-day usage per E5-only workload |
| Conditional Access coverage | Yes / partial / no | Policy-by-policy gap map, including exclusions |
| Privileged accounts | Your count | Full role assignment export, including nested and guest |
| Shadow admin paths | Not visible | Application consents, service principals, legacy delegations |
| External sharing exposure | Not visible | Every anonymous link, by site and age |
| Output | This page, printable | Board pack, remediation plan, regulator evidence pack |
Innoligo delivers these as fixed-price Microsoft assessments with UK-registered delivery partners agreed with you before signoff. If the finding is that you need someone to own this permanently rather than fix it once, that is a fractional CIO conversation instead. Recent examples are in our case studies.
Microsoft 365 security audit FAQs
What is a Microsoft 365 security audit?
A structured review of how a Microsoft 365 tenant is configured against known attack paths and regulatory expectations, covering identity, email, data, devices and administrative access — plus, done properly, the licensing position that funds the fixes. It is not the same as a penetration test, which attacks the perimeter, or a compliance audit, which checks paperwork.
Is this Microsoft 365 security audit actually free?
Yes, and there is no email gate. The assessment runs entirely in your browser, produces a printable summary, and asks for nothing in return. We publish it because firms who run it and find a £20,000 licensing problem tend to come back when they want it fixed properly.
Does my data leave my computer?
No. There is no server call and no analytics on the calculation. Every figure you type stays in the page’s memory and disappears when you close the tab. Print or save to PDF to keep the result.
How accurate are the savings figures?
As accurate as your inputs. The arithmetic is exact and shown in full, but it relies on your estimate of how many seats are inactive or over-provisioned. Default unit prices are Microsoft UK list from 1 July 2026 and exclude VAT, so CSP or EA customers should overwrite them. In practice a self-assessment understates savings, because the seats people forget about are the ones nobody remembers to count.
What is a good Microsoft 365 security posture score?
Above 85 means the fundamentals are in place and the remaining work is depth and drift. Between 65 and 85 is where most well-run UK SMEs sit — no glaring holes, but gaps a determined phishing campaign would find. Below 40 usually means MFA is incomplete or legacy authentication is still open, and the sensible response is to stop reading and fix those two this week.
Which Microsoft 365 licence do I need to satisfy the FCA or DORA?
Neither regulator names a licence. They describe outcomes: control of privileged access, evidence of what happened, resilience you have tested. Business Premium can satisfy most of it for a firm under 300 people. E5 buys Entra ID P2, Defender for Endpoint Plan 2 and advanced Purview capability, which makes several outcomes easier to evidence — but only when configured. An unconfigured E5 tenant scores worse than a well-run Business Premium one, and costs three times as much.
Does Microsoft back up my Microsoft 365 data?
Not in the sense you need. Microsoft guarantees platform availability and replicates your data for its own resilience. Recovering a mailbox deleted 200 days ago, or rolling a SharePoint library back to the morning before ransomware encrypted it, is your responsibility under the shared responsibility model. Retention policies and the recycle bin are not a backup.
How do I find unused Microsoft 365 licences?
Microsoft 365 admin centre → Billing → Your products shows purchased versus assigned seats, which catches licences bought and never allocated. Reports → Usage → Active users shows assigned seats with no recent sign-in, which catches the bigger problem. Cross-reference both against your HR leaver list; the gap between those three sources is where the money is.
Can I use this if I am on an Enterprise Agreement rather than CSP?
Yes — replace the default unit prices with your EA rates. Be aware that EA volume-tier discounts were removed in late 2025, so accounts that held them flatten to list pricing at their next renewal. If your EA renewal is within twelve months, model your fully loaded cost rather than the headline increase.
How much does a verified Microsoft 365 audit cost and how long does it take?
Fixed price, scoped to your tenant size, typically delivered in two weeks from read-only access to board pack. Email amitsh@innoligo.com with your headcount and sector for a figure, or book a 30-minute call and we will tell you straight away whether an audit is even the right thing for you.
How often should we re-run this?
The security half quarterly — configuration drifts, people leave, policies get excluded “temporarily” for a project. The licensing half sixty days before every renewal date, which is while you still have room to change something.
What this Microsoft 365 audit checks
The assessment looks at the controls that matter most when a regulator, auditor or cyber-insurer comes asking — and at the licensing decisions that quietly drain budget:
- Identity and access: multi-factor authentication coverage, admin protection, legacy authentication, and Conditional Access.
- Threat protection: Defender for Office 365, Safe Links and Safe Attachments.
- Data and resilience: Data Loss Prevention, audit logging and retention, and whether you hold an independent backup of your Microsoft 365 data.
- Licensing and cost: unused or unassigned seats, over-provisioned users (for example, E5 licences where E3 would do), and tiers that could be consolidated.
You answer a short set of questions, and the tool scores each area and shows you where the gaps are.
Why these gaps usually go unnoticed
The controls almost always exist inside Microsoft 365 — the problem is that nobody has checked whether they are switched on and configured the way they should be. A licence gets assigned to someone who later leaves. A user is put on the top tier “to be safe” and never moved down. MFA is enabled for most people but not enforced for everyone. None of it shows up until an incident, an audit, or an insurance renewal forces the question. A regular Microsoft 365 security audit is how you catch these before they cost you.
How the free 3-minute check works
- Tell us about your organisation — size and sector, so findings are framed against the right rules.
- Enter your licensing and answer the security questions — honest answers give honest results.
- Get your results instantly — a posture score, your estimated reclaimable spend in pounds, and a prioritised list of findings.
There’s no sign-up and no obligation. You can print or save your results to keep.
Your data never leaves your browser
This is the part we care about most. The entire Microsoft 365 assessment runs locally in your web browser. Nothing you type is transmitted to Innoligo or to any third party, nothing is stored, and we never ask for access to your tenant. For a regulated firm that is rightly cautious about who touches its systems, that means you can get real insight with zero exposure.
Built for regulated UK firms
Innoligo specialises in making high-stakes technology safe for regulated sectors. Every finding in this audit is framed against the expectations that apply to you — the FCA and DORA for financial services, the SRA for law firms, NHS DSPT for healthcare, and Cyber Essentials more broadly. It’s the same regulatory lens we bring to a full engagement, in a form you can try in minutes.
From self-check to verified audit
This tool gives you an honest, indicative picture — but it is a self-assessment, not a substitute for a verified audit. A full Innoligo Microsoft 365 security audit connects securely to your tenant to confirm the figures, surface what self-assessment can’t see, and deliver a board-ready remediation plan mapped to your regulator. If your results show gaps worth closing, that’s the natural next step.
Run the free check above, then book your verified audit when you’re ready.
Frequently asked questions
Is the Microsoft 365 security audit really free? Yes. The self-assessment tool is completely free, with no sign-up and no obligation. You only pay if you choose to commission a full verified audit afterwards.
Does my data leave my computer? No. The tool runs entirely in your browser. Nothing you enter is uploaded, stored, or sent to Innoligo or anyone else.
How long does it take? About three minutes. You answer a short set of questions about your licensing and security setup and get your results on the spot.
What’s the difference between this and a verified audit? This is an indicative self-assessment based on your own answers. A verified audit connects securely to your Microsoft 365 tenant to confirm the findings, go deeper, and produce a prioritised remediation plan and board-ready report.
Will it tell me if I’m compliant with the FCA, SRA or NHS rules? It highlights where your setup may fall short of common regulatory expectations and maps each finding to the relevant framework. It’s a starting point for a conversation, not a formal statement of compliance.
How much could I save on Microsoft 365 licensing? It varies by organisation, but unused seats and over-provisioned users are common and often add up to thousands of pounds a year. The tool gives you an indicative estimate based on the figures you enter.
Results are indicative and generated from self-reported inputs. They do not constitute a verified security or licensing audit, regulatory advice, or assurance of compliance. Microsoft 365 is a trademark of Microsoft Corporation; Innoligo is an independent partner.
It’s an indicative self-check, not a substitute for a verified audit — but in three minutes it’ll tell you whether you’ve got a problem worth a conversation.
If you’re in compliance or IT, I’d genuinely value your feedback on what to add.