Microsoft 365 Audit & Remediation
Publicada el 2026-07-29
Descripción de la oferta
I need a seasoned Microsoft 365 professional to carry out an end-to-end audit of our tenant and then close every gap you discover. The scope is deliberately broad: security settings, user permissions, and data-compliance configurations all need a deep dive. The end goal is clear—bring our environment in line with ISO 27001 and prove it with evidence that will satisfy an external auditor. You will start by reviewing our existing company-wide security policies, mapping them to the current Microsoft 365 configuration, and highlighting where reality falls short of policy or ISO 27001 best practice. Expect to work across Azure AD roles, Conditional Access, MFA enforcement, SharePoint/OneDrive sharing rules, Purview sensitivity labels, Intune device compliance, Defender for Office threat policies, and anything else that touches data protection. Deliverables I expect • A detailed audit report (findings, risk level, ISO 27001 control reference) • A prioritized remediation plan with clear configuration steps • Implementation of approved fixes within Microsoft 365, verified in a follow-up scan • Updated or newly drafted policy wording where controls change • A post-remediation checklist we can hand straight to our ISO auditor Acceptance criteria • All high- and medium-risk findings remediated or formally accepted by us • Tenant passes your final configuration scan with no critical alerts • Documentation is complete, plain-English, and maps each change to the relevant ISO 27001 clause If this plays to your strengths with PowerShell, Security & Compliance Center, and the broader Microsoft security stack, I’m ready to get started right away.
Skills
Fuente original: freelancer