AI is changing how Australian business works.
The ones who do it properly will compound the advantage.
Anonymised at our discretion — real Evisent engagement, May 2026
Case study · Microsoft 365 audit · two-week engagement
$4,070 in savings. Seven high-severity findings. Two weeks. What an Evisent audit actually walks into.
A 35-staff Australian wholesale business — referred to in this case study as Hartwell Trading Pty Ltd — engaged Evisent in May 2026 to run a read-only Microsoft 365 audit. The brief was cost optimisation. The brief was met. But the audit also surfaced seven high-severity security findings — including an admin account with no MFA, signed into 17 staff workstations.
EVISENT // FINDINGSMAY 2026
Audit summary
HARTWELL TRADING · 35 STAFF
| Findings | Count |
|---|---|
| High severity | 7 |
| Medium severity | 5 |
| Low severity | 1 |
| Annual savings | $4,070 |
| 2-WEEK READ-ONLY ENGAGEMENT |
$4,070
Confirmed annual cost savings
7
High-severity
security findings
17
Workstations signed into shared admin
2 wks
Read-only audit
delivery time
The setup
The brief was cost optimisation. We met it. Then we kept going.
Hartwell Trading is a 35-staff Australian wholesale business with a Microsoft 365 Business Premium tenant, a third-party email gateway, and an incumbent IT provider that had been in place for several years. The leadership team came to Evisent with a specific question: "is there money we're paying Microsoft that we shouldn't be?"
The answer turned out to be yes — about $4,070 a year in unused or over-assigned licences, recoverable inside a four-week window before the next annual renewal. That was the immediately quantifiable answer. The harder answer came alongside it.
The engagement at a glance
Engagement type: Read-only M365 audit, similar in shape to an AI Readiness Sprint
Duration: Two weeks
Scope: Identity & access, Conditional Access, endpoint & email security, data sharing, licensing, operational hygiene
Output: 27-page audit report, board-ready summary, prioritised remediation roadmap
Microsoft Secure Score (at audit): 66.8%
What we found
Six findings that mattered most.
The full report contains thirteen findings across security, licensing, and operational hygiene. Below are the six that most shaped the conversation with Hartwell's leadership team. Headline numbers preserved; identifying detail anonymised.
The incumbent IT provider's admin account had no MFA — and was signed into 17 staff workstations
High · Identity
The most material finding of the audit. The incumbent IT provider held a shared administrative account that was excluded from the tenant's "Require MFA for all users" policy, held permanent Global Administrator role (the highest privilege level Microsoft 365 offers), and was configured as the Windows sign-in identity on approximately seventeen staff workstations.
SharePoint and OneDrive set to "Anyone" — anonymous links never expired
High · Data sharing
External sharing was configured at the most permissive setting Microsoft offers. Anonymous "Anyone" links — which work without sign-in — never expired. Folders shared anonymously permitted upload back into them. Twenty-nine of thirty-five SharePoint sites had external sharing enabled at the site level.
The domain was unprotected against email spoofing
High · Email security
The domain's DMARC policy was set to p=none — a monitoring-only configuration that allows receiving mail servers to report on unauthenticated mail but does not block it.
The malware defences in their Microsoft licences had not been switched on
High · Endpoint Hartwell's Microsoft 365 Business Premium subscription included Microsoft Defender preset security policies — protections specifically designed to block the malware patterns used in over 90% of real-world attacks against businesses this size. None had been enabled.
$3,670/yr in unused licences — recoverable inside the four-week renewal window
High · Licensing
Fourteen user accounts held paid Microsoft 365 licences but were not active users.
Staff phones accessing company email were not managed at all
High · Endpoint / Data
Microsoft Intune — included in Business Premium licences — had zero mobile devices enrolled.
The harder answer
What we found was a setup that could have been used to defraud the company.
We weren't asked to investigate whether a prior compromise had occurred. we were asked to assess the current state. But the current state read like the inheritance from one: a shared admin account exempt from MFA, the same identity active on seventeen workstations.
What this means for businesses like Hartwell
The audit was a Sprint by another name.
The engagement Hartwell ran with us is structurally the same shape as our fixed-price AI Readiness Sprint — read-only, two weeks, fixed-scope, board-ready output.
If you're a Hartwell-shape buyer
10-200 staff, Microsoft 365 tenant, an incumbent IT provider you haven't deeply audited in years, an upcoming renewal you'd like to size correctly. Start with the Sprint.