Audit Microsoft 365 security — SharePoint permissions, oversharing, privileged access, Copilot readiness. 25 dedicated security and audit tools.
Frequently asked questions
What does the Microsoft 365 security audit cover?
SharePoint permissions, oversharing, privileged access, Copilot readiness, Conditional Access posture, Entra ID role exposure and 25 dedicated audit tools backed by Microsoft Graph metadata.
Is any file content collected during the audit?
No. Audits read Microsoft Graph metadata only and nothing is persisted server-side. Microsoft Defender for Cloud Apps collects file metadata and content and retains it 180 days; GTools.pro does not.
Can audit evidence be exported for ISO 27001 / SOC 2?
Yes. Reports export to JSON, CSV and signed PDF point-in-time evidence packs suitable for ISO 27001, SOC 2 and DORA control evidence.
How does this compare to Defender for Cloud Apps?
Defender for Cloud Apps is bundled into Microsoft licensing, ingests file content and shares it across Defender XDR, Sentinel, Purview and Entra ID Protection. GTools.pro is a point-in-time evidence tool that reads only the metadata needed for the chosen audit and persists nothing server-side.
Audit limitations and drawbacks
The M365 security audit is a detective control, not for live remediation. Watchtower enumerates roles, shared links, MFA posture, Conditional-Access coverage, and Defender alert state — then reports. Remediation is never automatic: the operator acts on the findings inside Entra ID, Defender XDR, or Purview using the existing admin consoles.
Severity rankings use the documented internal heuristic and may diverge from Microsoft Secure Score. Coverage stops at the Graph permission surface granted to the audit app; workloads behind tenant-licensed add-ons (Defender XDR, Purview eDiscovery Premium) require the matching license to enumerate. The audit cannot detect what Microsoft does not expose via Graph — a known limitation of any Graph-based scanner.