Security Assurance · GRC · Secure AutomationRemote delivery for growing technology businesses
Security Assurance Insight

10 Microsoft 365 Controls That Commonly Create Audit Problems

Microsoft 365 can produce strong security evidence, but identity and governance gaps are easy to accumulate.

Published 2026-09-03 · Tech Turn Technology

1. Standing privileged access

Permanent high-privilege roles without business need or review evidence increase exposure.

2. MFA gaps

Administrative, legacy or exception accounts can fall outside the intended MFA coverage.

3. Conditional Access exceptions

Policies may exist but contain broad exclusions that weaken the expected control.

4. Dormant accounts

Inactive users, guests and service identities can remain enabled long after business need ends.

5. Offboarding evidence

The account may be disabled, but the organisation cannot prove who approved or completed each required action.

6. Guest access

External users can accumulate across Teams, SharePoint and M365 groups without ownership or expiry.

7. SharePoint permission sprawl

Site-level and sharing permissions can diverge from documented access expectations.

8. Device compliance gaps

The policy says devices must be compliant, but unmanaged or non-compliant endpoints still access data.

9. Audit-log retention assumptions

Teams assume logs exist for the full review period without checking licence and retention configuration.

10. Access reviews without closure

A review campaign is run, but exceptions, removals and follow-up are not retained as complete evidence.

Need an evidence-based view of your own environment?
Use the Readiness Review to define scope and the first assessment.