Microsoft 365 and AI Security Audit — Copilot, documents and access
Copilot, SharePoint, Teams, OneDrive, and Outlook can expose documents, customer data, and credentials faster than IT can react. The audit reviews permissions, data sources, and approval workflows — within an agreed scope and with written authorisation.
What the audit covers
01. Microsoft 365 permissions and roles
We review who has access to Microsoft Copilot, which repositories are reachable, and whether permissions match real business roles rather than historical defaults.
02. Document sources for AI
We identify which files in SharePoint, OneDrive, Teams, and email can be used as context for Copilot — including external documents received from customers, suppliers, or partners.
03. Data classification and labels
We check whether the company applies sensitivity labels (e.g. GDPR, financial, medical) and whether Copilot respects those classifications. No classification means no AI boundary.
04. AI output approval policies
We verify who reviews content generated by AI before it is sent, published, or used in a decision process. Without output control, Copilot can become an unintended leak or manipulation channel.
05. Logs, alerts, and change history
We check whether the organisation has access to Copilot logs, alerts on unusual activity, and change history for key files. Without provenance, incident response is guesswork.
Engagement plans
Starter — single M365 audit
Review of permissions, document sources, and data classification. Report with priorities in business and technical language.
individual quotation
Growth — audit plus AI policy
M365 audit plus a written AI use policy: document source rules, data classification, output approval procedures.
individual quotation
Enterprise — audit, implementation, monitoring
Audit, AI policy, Microsoft 365 implementation, and recurring reviews after configuration changes, new applications, or incidents.
individual quotation
Before and after
- Before: many employees use Copilot, document sources are not classified, no output approval policy. After: clear permission list, data classification, and Copilot use rules.
- Before: customer document flows into Copilot, AI processes hidden instructions. After: external documents are treated as untrusted, output is verified before use.
- Before: no Copilot logs or alerts. After: full AI output provenance and alerts on unusual operations.
What this service does not include
- It is not a Microsoft 365 penetration test or an attempt to take over accounts — the audit operates only within an agreed scope and with written authorisation.
- It does not analyse AI model source code (Copilot, GPT, Claude) — the audit reviews your working environment, not the AI vendor.
- It does not replace a regulatory compliance audit (NIS2, DORA, GDPR) — it can complement one, but not substitute for it.
- We do not promise "100% Microsoft 365 security" — we organise risks and priorities, but no audit eliminates all risk.
Frequently asked questions
Does the M365 audit require administrator access?
Yes. The audit needs read-only access to the Microsoft 365 admin centre, audit logs, and Copilot settings. Access is granted by the client and revoked at the end of the engagement.
How long does a Microsoft 365 and AI audit take?
A standard audit takes 5 to 10 business days, depending on the number of users, applications, and integrations. The final report contains priorities and concrete remediation guidance.
Does the audit cover Copilot and other AI tools?
Yes. We review Microsoft Copilot configuration, the use of other AI assistants integrated with M365, and the general AI use policy in business processes (custom agents, OpenAI/Anthropic integrations).
Do I need management authorisation?
Yes, the audit requires formal authorisation from the board or a person delegated to manage IT infrastructure. We provide a standard authorisation and scope template before work begins.
How is an M365 audit different from a vulnerability audit?
The M365 audit focuses on configuration, permissions, and AI workflows in the Microsoft ecosystem. The Vulnerability Audit covers a selected domain, website, or web application within an agreed scope. The two services complement each other.
Related services
- When you want to test the technical resilience of a website or application → Vulnerability Audit
- When you want to protect your domain from impersonation → Email and Domain Audit
- When you need a one-shot view of external exposure → Internet Exposure Scan
- When you need continuous monitoring of exposure changes → Digital Exposure Monitoring
Request a Microsoft 365 and AI audit
We define the audit scope after a short briefing: number of M365 users, Copilot usage, AI integrations, regulatory requirements. We return with a work plan and an indicative delivery time.
Eng. Marcin Białczyk, CHORS.NET operator — learn how I work.