Auditex for Microsoft 365

Microsoft 365 audits.
Evidence you can check.

Collect read-only posture evidence from Microsoft 365 and Entra ID, keep raw evidence on your machine and prepare a verified report pack with finding-to-evidence links and recorded coverage gaps.

Read-only, for tenants you own or may audit.
Not certification, not legal advice and not guaranteed security.

Explore
Auditex for Microsoft 365: Terminal running Auditex on the Microsoft 365 demo, with proof-table, API-inventory and verify-pack results.View screenshot
Rendered from Auditex’s offline demo run on its sample tenant
Read-onlyNo content readsLocal raw evidence

Explore the evidence

From a read-only run
to a pack you can hand over.

Every finding.
Backed by evidence.

Findings cover mail flow, app credentials, cross-tenant access and DNS posture. Each one links to the normalised record it came from, so a reviewer can check it instead of trusting it.

Findings from the demo tenant: three critical, five high and five medium, each with its collector.View screenshot

Every call.
On the record.

The API inventory lists each call the run made and the class of data it touched. Tenant writes and content reads fail validation.

API call inventory showing five GET calls, read-only and no content reads.View screenshot

In detail

Verified.
Before handover.

The customer pack carries checksums for every file. auditex report verify-pack checks them and the required contract artifacts before handover. Compare runs locally to review changes and drift.

Customer pack verification: 37 files checked, 18 checksum lines, no issues.View screenshot

Get started with Auditex.

  1. Get Auditex.

    Clone the repository and install it with Python 3.11 or newer on macOS, Linux or Windows. Google Workspace and MCP support use optional dependencies.

  2. Grant read-only access.

    Run auditex setup-guide for the exact roles or scopes, then sign in with a reader account for a tenant you are authorised to audit.

  3. Review the pack.

    Read the findings, proof table and API inventory locally, then run auditex report verify-pack before you hand anything over. Review recorded coverage gaps alongside the findings.

Good to know

A few details.

Does Auditex change anything in my tenant?

No. The public audit surface is read-only. The separate lab-bootstrap toolkit is a distinct setup tool. Validation fails a run whose API inventory reports tenant writes or mailbox and file content reads.

Where does the evidence go?

Raw evidence stays on the machine that ran the audit. Normalised records, findings and MCP-ready report packs (for Model Context Protocol clients) are the surfaces meant for review and for AI assistants.

Is the report a certification?

No. Auditex is not certification, not legal advice and not guaranteed security. It gives a reviewer evidence to check; a person still makes the judgement.

Who may run it?

Only people who own the tenant or have the owner’s written authorisation. In the UK, unauthorised access is an offence under the Computer Misuse Act 1990; similar laws apply elsewhere.

What does it cost?

Nothing. Auditex is free and open source under the Apache License 2.0. Source, docs, issues and releases live on GitHub.

Tenant evidence.
Kept local.

View Auditex on GitHub