Solution · M365 Governance

Microsoft 365 security.Review settingsand sharing.

Conbool M365 Governance compares the tenant settings with a baseline and shows next to it what is actually shared. Continuously instead of on a single day.

Why a one-off review is not enough

A security assessment describes one day. The tenant changes the next.

Defaults are generous

External sharing, invitations by any user and consent to applications are, in many tenants, still set as they were on day one.

Settings say nothing about the inventory

Even a well-configured tenant carries the shares of previous years. The configuration does not show them.

Spread across many consoles

SharePoint, Entra ID and Teams each have their own admin centre. Someone has to assemble the overall picture by hand.

Changes go unnoticed

A setting relaxed for a project is rarely set back. Without a recurring check nobody notices.

How the security audit works

Read-only, no agent, no change to the tenant.

1. Grant consent

A global administrator consents to the application. The check reads the tenant settings and changes nothing.

2. Controls, expected against actual

Ten controls of the Conbool Basis baseline, each with expected value, actual value and result: Met, Deviating or Not checked.

3. Sharing and guests on top

The scan assesses every permission against 13 rules. Settings and inventory appear in one report.

What is checked

Four areas of tenant settings and the actual inventory.

SharePoint and OneDrive

No sharing for anyone without sign-in, no resharing by external users, legacy protocols off, invited address must match the account.

Guests and applications

Only administrators and guest inviters invite. Users do not consent to applications themselves and do not register any.

Sign-in

Multi-factor for administrators and legacy protocols blocked at sign-in.

Administrators

Two to four global administrators: enough for an emergency, few enough for control.

Risky sharing in the inventory

Anonymous links, grants to Everyone, freemail addresses, links without expiry, guests through groups, objects without an owner.

Notification on new deviations

The scheduled scan reports new deviations in tenant settings and new critical and high findings.

Continuous review and one-off assessment

Both have their place. The difference is what happens afterwards.

 
Conbool M365 Governance
One-off assessment
Timing
Daily or weekly
Single date
Scope
Settings and every single share
Usually the configuration only
Result
Score with trend, report as PDF
Document as of that date
Deviations
Reported as soon as a new one appears
Noticed at the next appointment
Fixing shares
Dry run and four-eyes approval in the product
List of measures to work through
Several tenants
Partner view, greatest need for action first
A separate project per tenant

As of October 2026. The right-hand column describes the usual approach without Conbool, not a specific vendor.

FAQ on the Microsoft 365 security audit

What does the Microsoft 365 security audit check?
Ten tenant setting controls from the areas SharePoint and OneDrive, guests and applications, sign-in and administrators. Plus the inventory: every permission in SharePoint, OneDrive, Teams and groups, assessed against 13 rules.
Is this a CIS benchmark for Microsoft 365?
No. The Conbool Basis baseline comprises ten controls and is not a complete benchmark. It covers settings that decide on sharing, guests and administrator accounts.
How does it differ from Microsoft Secure Score?
Secure Score assesses the configuration of the tenant. M365 Governance also reviews the inventory: the single share, the single guest, the object without an owner. The two complement each other.
Does Conbool change the settings itself?
No. The check reads and changes nothing. Each control shows expected and actual value, you make the change in Microsoft 365. Remediation exists for shares only, with a dry run and a second person.
Does this help to configure Microsoft 365 in line with GDPR?
It supports the technical measures: limiting access, giving shares an end date, reviewing guests, evidencing the state. It does not replace a legal assessment.
Does the review cover Exchange Online?
No. Mailbox permissions and transport rules are out of scope. For the security of the mail flow there is Conbool MailGuard.

Know where the tenant stands.

Settings, sharing and guests in one report.