Cognify Works

Microsoft 365

What we look at in a Microsoft 365 environment review

A Microsoft 365 review is less about finding misconfigured settings and more about understanding how the tenant is actually used and run.

Microsoft 365Cognify Works
Microsoft 365 environment review across administration, collaboration, identity, and licensing

A Microsoft 365 tenant accumulates decisions over time. Some were made deliberately during setup, others during a busy week when something needed to work immediately. A useful environment review does not start from a checklist of every possible setting. It starts by understanding how the organization uses the tenant, then looks at the areas most likely to be creating friction or risk.

Administration and ownership

Who has administrative roles, and do they need them? Are global administrator accounts limited and protected? Is there a clear owner for the tenant as a whole, and for individual workloads like Exchange, Teams, and SharePoint? Many issues that look technical turn out to be questions of ownership — nobody was responsible for deciding.

Identity and access

Sign-in methods, MFA coverage, Conditional Access policies, guest access, and how accounts are created and removed when people join or leave. These controls determine who can reach everything else in the tenant, so they are always part of the review.

Collaboration structure

How Teams and SharePoint sites are created, named, and retired. Whether sharing settings match how the organization actually works with partners and clients. Whether there are large numbers of inactive Teams, ownerless sites, or organization-wide sharing links on content that should be more restricted.

Licensing and usage

Whether licenses match the people and features actually in use. Unassigned licenses, licenses assigned to departed employees, and features the organization pays for but has not configured are common findings. The goal is not only cost — it is understanding which capabilities are available and not yet being used.

Devices and data protection

Whether devices that access company data are managed, what baseline policies exist, and how sensitive information is identified and protected. Retention and backup are part of this conversation too: Microsoft 365 availability is not the same as the organization being able to recover data it deleted or lost.

What comes out of a review

The most useful output is a prioritized list: what should be addressed soon because it carries real risk, what would meaningfully reduce friction, and what can wait. A long inventory of findings is less valuable than a clear view of where to start and who should own each step.

Keep reading

Related articles from our practice.

Microsoft Entra identity and access controls connecting users, devices, and applications

Security & Identity

Identity before more security tools

Most Microsoft environments already include strong identity controls. The gap is usually configuration and ownership, not another product.

Cognify Works

Get started

Bring us the environment behind the question.

Tell us what you are working through and the systems involved. We will help determine the next useful step.

Book a discovery call
Talk to Cognify