Fixed feeRead-only

Microsoft 365 Access & Admin Audit

A $750 fixed-fee review of your Microsoft 365 tenant: stale users, ex-employee access, risky admin roles, guest accounts, shared mailboxes, file ownership, MFA gaps, offboarding leftovers, and the licenses you are still paying for. You get a cleanup plan, not another open-ended IT project.

Fee
$750 fixed, up to 100 users, Microsoft 365 plus up to two adjacent tools.
Turnaround
2 to 3 business days after access or exports are ready.
Access
Read-only or least privilege. Exports work for some scopes.

What the audit covers

This is not broad Microsoft 365 management, helpdesk support, or a generic security score exercise. The audit is built around cleanup: who still has access, who has too much, what still belongs to former users, and what you are still paying for.

  • Active, inactive, former-employee, contractor, and guest accounts that need review.
  • Admin roles, privileged access, role sprawl, and unclear ownership in Entra ID.
  • MFA coverage and visible baseline identity control gaps.
  • Shared mailbox delegates, group access, Teams ownership, and external sharing issues.
  • Files, mailboxes, groups, and OneDrive content still owned by departed users.
  • Licenses that look unused, over-assigned, incorrectly tiered, or redundant.
  • The offboarding gaps that keep creating stale accounts and messy handoffs.

Offboarding leftovers, specifically

Offboarding issues are rarely one setting. They show up across accounts, groups, shared inboxes, files, Teams, guest access, and paid seats. The audit matches known departures and role changes against what still exists in the tenant, and sequences the ownership transfers that have to happen before old accounts can safely be removed.

License waste, connected to its cause

Unused Microsoft 365 spend is usually a symptom of old accounts and weak offboarding, so license cleanup is reviewed together with account status and ownership. Each license finding comes back as an action: reclaim seats tied to inactive or departed accounts, downgrade tiers that do not match the job, verify ambiguous accounts where removal could break mail or workflows, and prevent the same waste from returning with provisioning and offboarding fixes. Where pricing and seat counts are available, findings include annualized savings estimates.

The deliverable

A prioritized cleanup report: every issue with evidence, recommended action, risk, effort, likely owner, and savings where relevant. If you want VXSec to implement the approved fixes, the audit turns into a Cleanup Sprint with a non-destructive change list, owner approvals, dependency checks, and a record of what changed.

Want to know what is sitting in your tenant?

Use the scope check to confirm user count, adjacent tools, access method, and whether the audit is likely to be worth doing. Best fit: growing teams with 20 to 100 users, recurring staff changes, contractors, or no recent access cleanup.

Book a scope check