microsoft it audit software

Microsoft IT Audit Software Consulting

Microsoft IT audit software refers to the Azure and Microsoft 365 tooling — Entra ID access reviews and PIM, Purview audit logs, Defender for Cloud Apps, Microsoft Sentinel, and Power Platform's admin center — used to test and document IT general controls (ITGCs) across identity, change management, and operations, independent of which ERP those ITGCs ultimately support. IT audit in a Microsoft-centric enterprise increasingly means testing the tenant itself — access provisioning, privileged role management, change control over configuration — rather than testing inside any single application, because the tenant's identity and logging layer is what every downstream financial system, including but not limited to Dynamics 365, actually relies on for its own access control.

The four ITGC domains, mapped to specific Microsoft tenant controls

IT audit frameworks — COBIT, and the ITGC structure most external auditors use in practice — organize testing into access to programs and data, program changes, program development, and computer operations. In a Microsoft tenant, access to programs and data maps to Entra ID provisioning and deprovisioning plus Conditional Access; program changes maps to change management over Power Platform flows, Azure DevOps pipelines, and Entra ID Conditional Access policy edits; program development maps to how custom Power Apps and Power Automate flows touching financial data move from a developer's personal environment into a governed Managed Environment; and computer operations maps to backup, incident response, and the Purview audit log's own retention and completeness.

The practical value of mapping to this four-domain structure is that it gives IT audit a testing plan that does not depend on knowing the ERP's internals. A tester can complete access-to-programs-and-data testing entirely from Entra ID sign-in logs and access review records, without needing SAP or Dynamics-specific security-role knowledge, because the question at this layer is whether the right person has SSO access at all — the ERP-specific question of whether that person's role within the ERP creates a segregation-of-duties conflict is a separate, later test.

Sampling privileged access and Conditional Access in Entra ID

The highest-value ITGC test in a Microsoft tenant is privileged role sampling through Privileged Identity Management: pulling PIM activation history for Global Administrator, Application Administrator, and any custom role capable of altering SSO configuration for a financially relevant application, and confirming each activation had a business justification, a time-boxed duration, and — where required — an approval. Standing (non-expiring) assignment of these roles outside PIM is the single most common ITGC exception IT auditors find in Microsoft tenants that have not deliberately migrated off legacy always-on admin accounts.

Conditional Access testing follows a similar sampling logic but on policy configuration rather than activation history: pulling the Conditional Access policy set via the Microsoft Graph API or the admin center, confirming policies actually enforce what the control narrative claims (device compliance required for finance-system sign-in, MFA required tenant-wide, legacy authentication blocked), and checking the policy's modification history in the Purview audit log to confirm no undocumented change occurred mid-cycle. A control narrative describing a Conditional Access policy that was quietly disabled for troubleshooting three months prior and never re-enabled is a common finding this test surfaces.

Change management for Power Platform and Azure resources touching financial data

Program-change testing in a Microsoft tenant extends beyond traditional application code to Power Automate flows, Power Apps, and any Azure Logic App or Function touching a financially relevant data source. Because Power Platform's citizen-development model allows a maker to modify a flow's logic without a formal deployment pipeline, the ITGC question becomes whether Managed Environments and a defined promotion process (dev, test, production environments with solution-based deployment) exist for in-scope flows, versus flows built and modified directly in a production environment by their original author with no change ticket.

Computer-operations testing closes the loop by confirming the evidence infrastructure itself is sound: Purview audit log retention configured for at least the length of the audit cycle, Microsoft Sentinel or an equivalent SIEM retaining sign-in and Conditional Access events beyond the 90-day Entra ID default, and a documented incident-response process for the tenant covering how a compromised privileged account would be detected and contained. An ITGC program that thoroughly tests access and change controls but has never verified that the underlying audit log actually retains long enough to support next year's testing sample is a gap auditors increasingly probe directly.

Selection Criteria

What actually differentiates the options

  • ·PIM activation history retained and exportable for the full audit cycle, covering every role capable of altering SSO configuration for an in-scope financial application.
  • ·Conditional Access policy configuration and modification history accessible via Purview audit log or Microsoft Graph, not reconstructed manually from admin center screenshots.
  • ·Power Platform Managed Environments enforced for any environment hosting flows or apps classified as touching financial data, with a defined dev-to-production promotion process.
  • ·Purview audit log retention configured to exceed one full audit cycle plus remediation window — the 90-day default is insufficient for annual ITGC testing.
  • ·A documented incident-response runbook specific to tenant-level compromise (privileged account takeover, Conditional Access bypass) reviewed at least annually.
Compliance Matrix

Requirement, control, evidence

RequirementControlEvidence
ITGC — access to programs and dataEntra ID Conditional Access enforcing MFA and device compliance for sign-in to all in-scope financial applications, tested against the live policy configuration.Conditional Access policy export via Microsoft Graph, cross-referenced against the control narrative for a sample of in-scope applications.
ITGC — privileged access managementPIM requiring time-boxed, justified activation for Global Administrator and any role capable of modifying SSO configuration for financial systems.PIM activation history report for a sample period, confirming duration limits and approval trail for each activation.
ITGC — program changes (Power Platform and Azure resources touching financial data)Managed Environments and solution-based deployment enforced for flows and apps classified as financially relevant, blocking direct production edits.Power Platform admin center environment classification export and deployment history for a sample of in-scope flows.
ITGC — computer operations (evidence infrastructure integrity)Purview audit log retention configured to exceed the audit cycle length; Sentinel or equivalent SIEM retaining sign-in and Conditional Access events beyond the Entra ID default.Retention policy configuration export and a sample query confirming log availability for events older than 90 days.
ROI Model

What this actually costs

Cost driverLowHighWhat moves it
ITGC control-mapping and gap assessment across Entra ID, Purview, and Power Platform admin center$30,000$90,000Scales with number of in-scope applications relying on tenant SSO and whether a prior-year ITGC baseline already exists.
PIM rollout and Conditional Access remediation (closing standing-access and policy-gap findings)$40,000$150,000Depends on number of privileged roles requiring migration off standing access and complexity of existing Conditional Access policy set.
Power Platform Managed Environments and change-management process build for financially relevant flows$25,000$95,000Higher end reflects environments with a large existing inventory of ungoverned citizen-developed flows requiring retroactive classification.
Assumptions
  • · Ranges assume Microsoft 365 E3/E5 or Entra ID P1/P2 licensing already in place; licensing upgrades are a separate line item.
  • · Figures are illustrative estimates based on typical mid-market to large-enterprise ITGC remediation engagements, not quotes for a specific organisation.
  • · Estimates cover tenant-level ITGC work only — they exclude ERP-specific application controls testing inside Dynamics, SAP, Oracle, or another core system.
Worked scenario

A representative scenario

A hypothetical $450M healthcare services company is preparing for its first PCAOB-integrated 404(b) audit and has historically scoped ITGC testing only to its ERP's native user administration screens. An IT audit readiness assessment in this pattern typically finds that Global Administrator access in the Entra ID tenant has never been reviewed as an ITGC in-scope control, that Conditional Access policies exist but their modification history has not been retained past the 90-day default, and that a Power Automate flow routing vendor payment approvals — built by an AP analyst — runs in the default production environment with no change log. Remediation commonly involves formally adding Entra ID privileged access and Conditional Access to the ITGC control inventory, extending Purview audit log retention to cover the full audit cycle before the next testing period begins, and migrating the payment-approval flow into a Managed Environment with a defined owner. The pattern of ITGC scoping stopping at the ERP's front door while the tenant underneath goes untested recurs frequently enough in first-year Microsoft-heavy 404(b) programmes to be described here as illustrative, not as a specific client outcome.

FAQ

Common questions

Any tenant-level control affecting access, change management, or operations for a system that supports financial reporting — Entra ID provisioning and privileged access, Conditional Access policy enforcement, Power Platform change management for flows touching financial data, and the integrity of the Purview audit log itself.

Next step

Book an assessment

Get a scoping call on microsoft it audit software for your organisation's platform and entity structure.

Book an Assessment →