HomeFeaturesPricingBlogGuides
Sign in Sign up
This is a sample report for a made-up business, so you can see exactly what your free audit looks like. Yours uses your own Microsoft 365.Get my free audit
MICROSOFT 365 AUDIT · EXAMPLE LTD · 18 PEOPLE

Your IT health check

We checked sign-in security, email, backups and licences. Here's what we found, what it means for the business, and what to fix first. No jargon.

Needs attentionA few quick fixes would move this into the 80s.
4
Fix now
5
Worth fixing
2
All good
£711
a year on unused licences
Your top 3 fixes
1Turn on two-step sign-in for the 5 people without itAbout 15 minutes
2Start backing up your email and filesSet up in a day
3Check the mailbox that forwards email to Gmail5 minutes
The picture

Failed sign-in attempts, last 30 days

212 attempts. The spike on days 13 and 14 looks like a password-guessing attack.

30 days agoToday

Where the attempts came from

6 countries where Example Ltd doesn't do business.

United Kingdom61
Russia44
China38
Nigeria27
United States24
Brazil11
Vietnam7

Two-step sign-in (MFA)

13 of 18 people are protected.

  • 13 protected
  • 5 password only
  • 2 of them are admins

Licences: bought vs in use

6 licences nobody's using, about £711 a year.

Business Standard
16 of 20 used
Teams Essentials
0 of 2 used
Exchange Online (Plan 1)
3 of 3 used
What we found, in plain English
Fix nowSign-in security

5 of 18 people can sign in with just a password

What it is
Two-step sign-in (MFA) means a password alone is not enough: you also approve the sign-in on your phone.
Why it's a risk
Passwords leak all the time, through phishing emails, reused passwords and data breaches on other websites. Without the second step, a leaked password is all a criminal needs.
What could happen
Someone could read and send email as your staff, change bank details on invoices, or quietly download your customer files, and you might not notice for weeks.
The fix
Turn on two-step sign-in for the 5 people. About 15 minutes, and we can walk each person through it.
Fix nowSign-in security

Nothing forces safe sign-in across your business

What it is
Microsoft can enforce rules such as "always use two-step sign-in" and "block sign-ins from abroad". None are switched on for you.
Why it's a risk
Without enforcement, safety depends on every individual setting things up themselves, and attackers only need the one person who didn't.
What could happen
One unprotected account is enough to get into your email, files and Teams.
The fix
Switch on sign-in rules so sign-ins only work with two-step sign-in, from approved places and devices.
Fix nowEmail

1 mailbox copies email to an outside address

What it is
One mailbox automatically forwards every email to a personal Gmail address.
Why it's a risk
Sometimes this is deliberate, but it's also the first thing criminals set up after breaking into a mailbox, so they can keep reading your email even after the password is changed.
What could happen
Confidential emails, invoices and customer details quietly leave the business, and fake "change of bank details" emails become much easier to send.
The fix
Check the forward with the person, remove it if it shouldn't be there, and block automatic forwarding outside the company.
Fix nowBackups

Your email and files aren't backed up

What it is
Microsoft keeps your data running, but it isn't a backup. Deleted items are only kept for a limited time, and ransomware or a disgruntled leaver can wipe or encrypt everything.
Why it's a risk
Microsoft's own terms recommend a separate backup, and most small businesses don't realise they need one until it's too late.
What could happen
Lose a mailbox or a shared folder and it may be gone for good, along with the customer history in it.
The fix
Add a Microsoft 365 backup that copies email, OneDrive, SharePoint and Teams every day, kept for as long as you need.
Worth fixingLicences

6 licences nobody's using, costing about £711 a year

What it is
4 spare Business Standard licences (people who've left) and 2 Teams Essentials licences nobody has opened.
Why it's a risk
Licences don't switch themselves off when people leave, so the cost carries on quietly every month.
What could happen
About £711 a year spent on nothing, and it grows every time someone leaves.
The fix
Reuse the spare licences for new starters, cancel Teams Essentials (Business Standard already includes Teams), and right-size at your March renewal.
Worth fixingSign-in security

4 people have the keys to everything

What it is
A Global Administrator can change anything in your Microsoft 365: users, email, security settings and billing.
Why it's a risk
Every admin account is a master key. The more there are, the more chances an attacker has to steal one.
What could happen
If any one admin account is compromised, the attacker controls your whole company's email and files, and can lock you out.
The fix
Keep two Global Admins at most, both with strong two-step sign-in, and give everyone else only the access they need.
Worth fixingEmail

Criminals could send emails pretending to be you

What it is
Email has three safety records (SPF, DKIM and DMARC) that tell the world which emails really come from your company. Your DMARC record is missing.
Why it's a risk
Without it, anyone can send an email that looks exactly like it came from you.
What could happen
Your customers and suppliers could receive fake invoices or payment requests "from you", which damages trust and can cost them, or you, real money.
The fix
Add the missing record, then tighten it step by step so genuine email keeps flowing.
Worth fixingEmail

2 shared mailboxes can be signed in to directly

What it is
Shared mailboxes (like info@ or accounts@) are meant to be opened through people's own accounts, not signed in to with a password.
Why it's a risk
A shared mailbox with its own sign-in is a forgotten back door: often an old password, rarely with two-step sign-in.
What could happen
Mailboxes like accounts@ hold invoices and payment details, exactly what fraudsters are after.
The fix
Switch off direct sign-in for these mailboxes. Nobody loses access, because people keep opening them through their own accounts.
Worth fixingSign-in security

212 failed sign-in attempts in 30 days, from 6 countries outside the UK

What it is
These are attempts to sign in to your accounts that failed: wrong passwords, blocked sign-ins and expired sessions.
Why it's a risk
Attempts from countries where you don't work are usually automated password-guessing attacks.
What could happen
If one of those guesses works, the attacker gets the same access as the member of staff.
The fix
Block sign-ins from countries you don't work in, and make sure two-step sign-in is enforced.
Email is flowing normallyNobody is blocked from sending email.
Guest access is under control3 guests, all added in the last 6 months.

Want yours?

The same report for your own business: free, no card, and no obligation.