We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Audit and compliance
  2. Microsoft 365 security audit
Microsoft 365 security audit, UAE

Your Microsoft 365 tenant holds the evidence. For how long?

Most UAE organisations have never checked how far back their Microsoft 365 audit log actually reaches, and the answer is frequently 180 days. That gets discovered during an incident, when somebody asks what happened eight months ago. We audit the tenant and tell you what you can prove.

Book a Microsoft 365 security auditSee what we examine
Microsoft 365 tenant security audit for UAE organisations
  • 180 daysThe default many tenants actually have
  • One yearOnly for E5 users, only some workloads
  • Tenant-wideIdentity, mail, data, devices
  • Evidence firstWhat you could prove, not just settings
What we examine

Eight areas of the tenant, in the order attackers care about them.

A Microsoft 365 audit is not a Secure Score screenshot. Secure Score is a useful starting index and it is not evidence of anything. What matters is whether the controls are configured correctly for how your organisation actually works, and whether you could reconstruct what happened if somebody asked.

Identity, because that is where the compromise starts

Who has accounts, which of them are stale, which have never had multi-factor authentication enforced, how administrators authenticate, and whether any authentication path still exists that cannot enforce a second factor. Nearly every Microsoft 365 compromise we have investigated in this market began with a credential rather than with an exploit, so this section is first for a reason.

Conditional access, and the gaps between the policies

Policies look reassuring in a list and the risk lives in what they do not cover: excluded accounts that were meant to be temporary, service accounts outside every policy, break-glass accounts that are neither monitored nor tested, and the combination of conditions that leaves one path open. We read them as a set rather than individually, because that is how an attacker encounters them.

Privileged roles and standing access

How many people hold privileged roles, whether that access is permanent or activated when needed, whether it is reviewed, and who granted it. Global administrator counts in UAE tenants are consistently higher than anyone expects, usually because a consultant, a former employee or a vendor was given the role during a project and nobody removed it afterwards.

Audit log retention, which is the one people have never checked

Microsoft retains Exchange Online, SharePoint, OneDrive and Entra audit records for one year under the Audit Premium default, but only for users licensed at E5 level. Everything else, and every non-E5 or guest user, defaults to 180 days. Most organisations do not know which applies to them until an investigation needs to look further back than they can see. This is the single most valuable finding we produce.

Mail flow, forwarding rules and what leaves the tenant

Transport rules, connectors, external forwarding, and the mailbox rules that quietly move messages to a folder nobody opens. Business email compromise in this region is overwhelmingly about invoice fraud, and the mechanism is almost always a forwarding or filing rule created after a mailbox was accessed. We look for the ones that exist now and for whether you would notice a new one.

Data, sharing and what is exposed by accident

SharePoint and OneDrive sharing settings, links that never expire, anonymous access, guest access to sites, and where sensitive material has been shared outside the organisation without anybody intending it. The finding here is rarely a deliberate act. It is an accumulation of individually reasonable decisions over several years that nobody has ever looked at as a whole.

Devices and whether compliance actually gates access

Which devices are enrolled, whether compliance state is connected to access or merely reported, and how many devices reach company data with no management at all. Reporting a device as non-compliant while still letting it read the mailbox is a very common configuration, and it means the control is informational rather than protective.

Guests, external identities and third parties

Guest accounts accumulate in every long-lived tenant: a contractor from a project that ended, a client contact who changed jobs, a supplier who was invited once. Each is a credential outside your control with a path into your data. We inventory them, establish which are live, and put a review cadence in place, because nobody removes guests without a prompt.

Check this before you need it

You may have 180 days of evidence and believe you have a year.

This is precise, it is verifiable in Microsoft documentation, and it catches organisations at the worst possible moment. The numbers below are Microsoft published defaults, not our estimates.

  • The Audit Premium default policy retains Exchange Online, SharePoint, OneDrive and Microsoft Entra audit records for one year. Everything else defaults to 180 days. So even at the higher licence level, a whole year of history is not what you have across the board, it is what you have for four workloads.
  • That one-year default only applies to activity by users assigned an Office 365 or Microsoft 365 E5 licence, or a Purview Suite or E5 eDiscovery and Audit add-on. Microsoft states directly that if you have non-E5 users or guest users, their audit records are retained for 180 days. Mixed licensing is normal in UAE organisations, which means retention is mixed too, per user.
  • The Audit Standard default is 180 days. It used to be 90, and records generated before 17 October 2023 are still retained on the old 90-day basis. If your last audit was written against the old figure, it is out of date.
  • The trap most people miss: custom retention policies take priority over the default, including custom policies that are shorter. An organisation can have quietly reduced its own retention below the default without anybody connecting that setting to the investigation it will one day prevent. We check what policies exist, not what the licence entitles you to.
Ask us how far back your tenant can actually see
How we audit

Four things that separate an audit from a Secure Score screenshot.

Anybody can export a configuration report. The value is in knowing which settings matter for your organisation, which findings are noise, and what you could actually prove afterwards.

We audit the tenant as configured, not against a generic baseline

A generic baseline produces two hundred findings, most of which do not apply to you, and the important five get lost. We assess how your organisation actually works first, then report what genuinely creates exposure in that context. A shorter report that gets acted on beats a comprehensive one that gets filed.

We tell you what you could evidence, not only what is switched on

The question that matters after an incident is what you can reconstruct. That depends on retention policies, licensing per user and whether anybody has ever run a search successfully. We check all three, and we run a real historical query so you know the capability works before the day you need it.

We do not recommend licence upgrades reflexively

It is easy to answer every finding with a suggestion to move to E5, and sometimes that is genuinely correct, particularly where audit retention or investigation capability is the gap. Often it is not, and the same risk closes with configuration you already own. We separate the two clearly so you can see which findings cost money and which cost attention.

We hand you findings your team can work

Each finding states what it is, why it matters in your context, what to change, and roughly what it takes. Your team can execute it, or we can, and either is fine. What we will not do is produce a report that requires us to interpret it, because that is a dependency rather than a deliverable.

When organisations ask for this

Six situations that bring UAE businesses to a tenant audit.

The trigger shapes the scope. An audit prompted by a client questionnaire looks different from one prompted by a suspected compromise, and we scope accordingly rather than running the same engagement each time.

A client or insurer has sent a security questionnaire

The most common trigger. Somebody needs to answer specific questions about multi-factor authentication, access control, logging and data handling, and nobody internally knows the current state well enough to answer honestly. An audit produces the answers and, more usefully, tells you which ones you should fix before answering.

After a suspicious email or a suspected compromise

A payment nearly went to the wrong account, or a mailbox behaved oddly, or somebody received a message that appeared to come from a colleague. The immediate question is what actually happened, and the answer depends entirely on what your audit log retained. This is where organisations discover their retention position, and it is far too late to change it then.

A regulated firm in DIFC or ADGM

Supervisory expectations cover access control, logging and the ability to investigate, and Microsoft 365 is where most of that evidence lives for a typical firm. The audit retention question is unusually important here, because the period a regulator or an external auditor may ask about can be longer than the period your tenant retains by default.

A business that has changed IT provider

A new provider inherits a tenant configured by somebody else, with administrator accounts, consented applications and conditional access exclusions whose reasons nobody remembers. An independent audit at handover establishes a baseline and, frequently, removes access that should have gone when the previous relationship ended.

An organisation with a data protection obligation

Healthcare entities, firms handling significant volumes of personal data, and anyone in scope of the federal data protection law or a free zone regime. Here the audit focuses on where data actually sits, who can reach it, what has been shared externally and whether you could evidence access if a subject or a regulator asked.

A company that has simply never looked

The healthiest reason, and the least common. The tenant has run for years, staff have joined and left, projects have come and gone, and somebody sensibly wants to know what state it is in. These audits nearly always find several things worth fixing and almost never find a crisis, which is exactly the outcome you want from looking early.

Three tenant positions

What we find when we audit a Microsoft 365 tenant in the UAE.

The middle column is the most common by a wide margin. The tenant was set up competently at some point, then five years of staff changes, projects and consultants happened, and nobody looked at the whole thing again.
Global administrator count controlled
Audited and maintainedFew, reviewed
Set up once, then driftedGrown quietly
Defaults, largely untouchedWhoever asked
MFA enforced on all privileged accounts
Audited and maintained
Set up once, then driftedMostly
Defaults, largely untouchedPartially
Conditional access exclusions justified
Audited and maintained
Set up once, then driftedForgotten
Defaults, largely untouchedNone exist
Audit retention known and deliberate
Audited and maintained
Set up once, then drifted
Defaults, largely untouched
External forwarding controlled
Audited and maintained
Set up once, then driftedSometimes
Defaults, largely untouched
Guest accounts reviewed
Audited and maintained
Set up once, then drifted
Defaults, largely untouched
Device compliance gates access
Audited and maintained
Set up once, then driftedReported only
Defaults, largely untouched
Third-party app consent governed
Audited and maintained
Set up once, then drifted
Defaults, largely untouched
Could reconstruct an incident from last year
Audited and maintainedProbably
Set up once, then driftedOnly within 180 days
Defaults, largely untouchedUnlikely
How common in the UAE market
Audited and maintainedUncommon
Set up once, then driftedThe default
Defaults, largely untouchedSmaller firms
Feature
Audited and maintained
Set up once, then drifted
Defaults, largely untouched
Global administrator count controlled
Few, reviewedGrown quietlyWhoever asked
MFA enforced on all privileged accounts
MostlyPartially
Conditional access exclusions justified
ForgottenNone exist
Audit retention known and deliberate
External forwarding controlled
Sometimes
Guest accounts reviewed
Device compliance gates access
Reported only
Third-party app consent governed
Could reconstruct an incident from last year
ProbablyOnly within 180 daysUnlikely
How common in the UAE market
UncommonThe defaultSmaller firms
What you can actually prove

Audit evidence available in a Microsoft 365 tenant, by default.

Every figure here is a Microsoft published default for audit log retention, current as of the Microsoft Learn documentation in June 2026. Custom retention policies you have created override these in either direction, which is why an audit checks the policies rather than reading the licence.
SituationDefault retention
Audit Standard, logs on or after 17 October 2023180 days
Audit Standard, logs before 17 October 202390 days
Audit Premium, Exchange Online records, E5 userOne year
Audit Premium, SharePoint and OneDrive, E5 userOne year
Audit Premium, Microsoft Entra records, E5 userOne year
Audit Premium, all other activities180 days by default
Any activity by a non-E5 user180 days
Any activity by a guest user180 days
With a 10-year audit retention add-on, plus E5Up to 10 years
A custom policy shorter than the defaultThe shorter custom policy wins
Maximum retention policies per organisation50
How the audit runs

Five stages, typically one to two weeks.

The work is mostly read-only and does not disrupt users. What we need is properly scoped access and a short conversation about how your organisation actually operates, because that determines which findings matter.
  1. 1

    Scope, access and context

    What is in scope, what read access we need and how it is granted, and a conversation about how the business works: who travels, who uses personal devices, which third parties have access, what the compliance drivers are. Findings are worthless without this context, because whether a setting is a risk depends on what your people actually do.

  2. 2

    Identity and access review

    Accounts, privileged roles, authentication methods, conditional access as a set rather than as a list, stale accounts, guests and third-party application consent. This stage produces the highest-severity findings in most tenants, and it is where we spend the most time.

  3. 3

    Data, mail and device review

    Sharing configuration and what is currently shared externally, mail flow rules and forwarding, connectors, and how device compliance relates to access. We look at what exists now rather than only at what the policy allows, because the gap between the two is usually where the finding is.

  4. 4

    Evidence and retention check

    What your audit retention actually is, per licence and per custom policy, and a real historical search run to confirm the capability works. We tell you how far back you can genuinely see, which is frequently different from what people believe and is the finding clients most often say they are glad they got.

  5. 5

    Report, prioritise, and fix

    Findings by severity with the context that makes them severe, separated into what costs configuration effort and what would cost licensing. Then remediation, by your team or by us. We are happy either way, and where you want it we re-audit afterwards so the improvement is documented rather than assumed.

“The finding that mattered was not a misconfiguration. It was that we could only see 180 days back, and we had assumed a year. Three months later we had an incident that started before that window, and knowing the limit in advance completely changed how we handled the investigation.”
IT Director
Professional services group, DIFC · Client reference available on request
Straight answers

What organisations ask about a Microsoft 365 audit.

It depends on your licensing and on any custom policies, and the honest answer for most UAE organisations is less far than they assume. Under the Audit Premium default, Exchange Online, SharePoint, OneDrive and Microsoft Entra records are retained for one year, but only for users assigned an E5 licence or an equivalent add-on. All other activities default to 180 days, and Microsoft states that non-E5 users and guest users have their records retained for 180 days regardless. Audit Standard defaults to 180 days. So a mixed-licence tenant has mixed retention, per user.

It is a useful index and it is not an audit. Secure Score is calculated against a Microsoft baseline that does not know your business, so it awards points for controls you may not need and it cannot see the specific misconfiguration that would actually harm you. We have audited tenants with strong scores and a conditional access exclusion that made most of the policy set irrelevant. Use it to track direction over time, not to answer whether you are secure.

No. The review itself is read-only and users notice nothing. What can be disruptive is remediation, particularly anything touching authentication, and that is why we separate the two and plan changes with you rather than applying them during the audit. If we find something genuinely urgent, an active compromise indicator for instance, we tell you immediately rather than waiting for the report.

No, and we would be doing you a disservice to imply otherwise. A well-configured tenant on lower licensing is meaningfully more secure than a poorly configured one on E5, and most of the highest-severity findings we produce are configuration rather than capability. Where E5 genuinely earns its place is investigation and evidence: longer audit retention for key workloads, and the tooling to work an incident properly. If you are regulated or hold sensitive data, that is a real argument. If you are not, configuration first.

Few, and every one of them for a reason somebody can state. There is no universal number, but the pattern we find is consistent: the count grows because a consultant needed it during a project, a vendor asked for it, or someone was granted it to solve a problem quickly, and nothing removes it afterwards. Along with the count, the questions worth asking are whether that access is permanent or activated when needed, whether it is reviewed, and whether every one of those accounts has multi-factor authentication genuinely enforced.

Conditional access with exclusions that nobody can justify. The policy set looks robust in a list, and then a service account, a break-glass account that was never tested, or an exception created for one person during a trip turns out to sit outside all of it. The second most common is external mail forwarding being possible and unmonitored, which is the mechanism behind most invoice fraud in this region. Neither costs money to fix.

Yes, within limits set by licensing. You can create custom audit log retention policies, up to fifty per organisation, with durations from seven days to seven years, and a ten-year option where you hold the ten-year audit log retention add-on alongside E5. Creating or changing one requires the Organization Configuration role. The important caveat is that custom policies take priority over the default in both directions, so a custom policy shorter than the default silently reduces what you retain, which we check for specifically.

We tell you immediately rather than putting it in the report, and we stop and agree the next step with you before doing anything that could destroy evidence. Preserving what the tenant still holds becomes the priority, which is time-sensitive precisely because of the retention limits discussed on this page. Depending on what we find, that may mean an incident response engagement rather than continuing the audit, and we would say so plainly rather than continuing to bill an audit around a live problem.

One to two weeks for a typical UAE organisation. We need scoped read access to the tenant, granted in a way you control and can revoke, and roughly two hours of conversation with somebody who knows how the business works. That second part matters more than people expect: the difference between a finding that is serious and one that is noise is almost always context about how your people actually work.

They can, and there is a reason to prefer an independent review: your provider configured the tenant, so an audit by them is an assessment of their own work. That is not an accusation of bad faith, it is a structural problem that applies to any provider including us where we run the estate. Where we manage a client tenant, we say plainly that our audit is not independent and we are comfortable with a third party reviewing it.

They accumulate in every tenant more than a year or two old, and almost nobody removes them without a prompt. A contractor from a project that finished, a client contact who has changed employer, a supplier invited once for a file transfer. Each is a credential outside your control with a path into your data, and their audit records are retained for 180 days regardless of your licensing. We inventory them, identify which are live and which are dormant, and put a review cadence in place.

Yes, and the sharing configuration is usually where the most uncomfortable findings sit. Anonymous links that never expire, sites shared with external parties years ago, and files reachable by people nobody would consciously grant access to. The pattern is not misconduct, it is accumulation: a series of individually reasonable decisions that nobody has ever reviewed collectively. Note that SharePoint and OneDrive records get one year of retention under the Premium default for E5 users, which helps if you need to investigate.

Directly, because for most organisations the majority of personal data lives in Microsoft 365. The federal data protection law and, for DIFC and ADGM firms, their own regimes require you to know what you hold, control access to it and be able to respond to requests and incidents. A tenant audit tells you where that data actually is, who can reach it, what has been shared externally and whether you could evidence access. We map findings against the obligations that apply to you rather than reporting them generically.

A tenant drifts continuously, because people join and leave, projects grant access, and Microsoft changes defaults. Annually is a reasonable cadence for most organisations, with an additional review after a significant change such as a merger, a change of IT provider or a large migration. What matters more than frequency is that the second audit is comparable to the first, so it measures whether anything actually improved rather than restating a fresh set of opinions.

We scope per organisation rather than publishing a figure, driven mostly by user count, how many services are in scope and whether you want remediation included or only the assessment. What we will tell you free, in the first conversation, is how to check your own audit log retention position, because that single answer is often the most valuable thing to come out of this whole exercise and you should not have to pay to find it out.
Tenant health check

Fifteen things to check in your own tenant this week.

You can work through most of these yourself, and we would rather you did than left them unexamined. The first group is identity, the second is what leaves the tenant, the third is whether you could evidence any of it afterwards.

Identity, where it starts

  • How many accounts hold Global Administrator?
    The number is nearly always higher than the answer people give.
  • Is multi-factor authentication enforced on every one of them?
    Enforced, not enabled, not encouraged.
  • Are there accounts excluded from conditional access?
    Check why, and whether the reason still exists.
  • Do you have break-glass accounts, and have they been tested?
    Untested emergency access is not emergency access.
  • How many accounts have not signed in for 90 days?
    Each one is a live credential nobody is watching.

What leaves the tenant

  • Is external mail forwarding blocked or monitored?
    The classic business email compromise mechanism.
  • Do any mailboxes have rules filing mail to obscure folders?
    Worth looking at directly, not just in policy.
  • Can users create anonymous sharing links that never expire?
    Check the setting and check what already exists.
  • How many guest accounts exist, and who owns each?
    They accumulate and nobody removes them unprompted.
  • Which third-party applications have consent in your tenant?
    Consented apps are a standing access path.

Could you evidence it

  • How far back does your audit log actually reach?
    Check the retention policies, not the licence brochure.
  • Do you have any custom retention policies, and are any shorter than the default?
    Custom policies override the default in both directions.
  • Are all your users E5, or is licensing mixed?
    Retention is per user. Mixed licensing means mixed evidence.
  • Has anybody ever run a real audit log search?
    The first time should not be during an incident.
  • Is device compliance connected to access, or only reported?
    Reported non-compliance changes nothing on its own.
Related reading

The pages around this one.

IT audit services in Dubai

The wider audit practice, and how to tell which kind of engagement your situation actually calls for before anybody quotes for one.

Learn more

Microsoft Entra

The identity layer underneath everything on this page: conditional access, privileged access and the controls that close the findings we most often report.

Learn more

NIST CSF 2.0 assessment

If you want a picture across the whole security function rather than one platform, this is the broader framework a tenant audit feeds into.

Learn more
Next step

Go and check how far back your audit log reaches.

It takes a few minutes, it is free, and for most organisations the answer is different from what they assumed. If you would like help checking it, or a full review of the tenant behind it, that is a short conversation and we will tell you what we would look at first.

Book a Microsoft 365 security auditCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

DMARC Audit UAE

Stop exact-domain spoofing, and keep your mail delivering

Learn more

Active Directory Audit

Privilege paths, service accounts and local admin passwords

Learn more

IT Audit Services Dubai

Assessment, technical test or certification, scoped properly

Learn more

Microsoft Entra

Identity and access management solutions

Learn more

Microsoft Security Dubai

Entra, Defender, Purview, Sentinel, and what you already own

Learn more

NIST CSF 2.0 Assessment

Know where you stand, without committing to certification

Learn more

Microsoft Defender

Advanced endpoint and email threat protection

Learn more

UAE PDPL Compliance

Federal Decree-Law 45 of 2021 readiness and operations

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy