How to Audit Microsoft 365 Privileged Access
A privileged-access audit should reconcile role inventory, business need, safeguards and review evidence.
Build the population
Export current privileged role assignments, eligible assignments and relevant service or emergency accounts. Define the population before selecting samples.
Identify standing privilege
Separate permanent role assignments from eligible or just-in-time access. Investigate the business need for high-impact permanent privileges.
Test safeguards
Review MFA, Conditional Access, PIM or equivalent controls, separate admin identities and emergency-access design.
Test authorisation and review
Sample assignments back to approval records and recent access reviews. Check whether removal decisions were actually completed.
Inspect exceptions
Document exclusions, stale assignments and service-account constraints. A known exception should have an owner, risk decision and review date.
Conclude on operating effectiveness
The conclusion should reflect whether the control operated throughout the period, not only whether the current screen looks secure today.
Use the Readiness Review to define scope and the first assessment.