Frequently asked questions
The most frequent questions about our audits and our Microsoft security services. Another question? Contact us.
What is a Microsoft 365 or Entra ID security audit?
It is a tool-based evaluation of your tenant configuration: Conditional Access, MFA, privileged roles, applications, sharing. We measure nearly 300 checks with EntraGUARD, map them to the ANSSI, CIS, NIS2, DORA and MCSB frameworks, then deliver a prioritized remediation plan.
How long does an audit take?
An express assessment gives a first snapshot in a few days. A full Entra ID / M365 or Active Directory audit typically spans one to three weeks depending on environment size, debrief and action plan included.
Does the audit modify our environment?
No. Our tools (EntraGUARD, AdGUARD, AzureGUARD) work read-only and, for the cloud, via Microsoft Graph. No data leaves your environment and no configuration is changed during the audit phase.
Do you operate outside Belgium?
Yes. Engagements cover Belgium, France and Luxembourg, on-site or remotely depending on context.
Are you affiliated with Microsoft?
No. m365expertise is an independent consultancy. The names Microsoft, Entra ID, Azure, Defender, Sentinel and Purview are cited descriptively for the services offered.
Do you help with NIS2 and DORA compliance?
Yes. Our audits are mapped to NIS2 and DORA requirements, and we support remediation as well as building compliance evidence (retention, logging, governance).