Aegisys Cloud Solutions
All posts
ComplianceFebruary 10, 202614 min read

How to Audit Vendor Security Controls

The questions to ask every vendor with access to your Microsoft 365 environment.

Every third-party vendor with access to your Microsoft 365 environment — whether for support, integration, or customization — becomes part of your security posture. A vendor's weak controls can become your breach.

What You Need to Know Before Granting Access

Ask each vendor: What data will they access? How will they authenticate? What is their encryption approach? Are they SOC 2 audited? Do they log all administrative actions? Can those logs be audited?

For high-risk access, require that vendors authenticate using your identity provider, use multifactor authentication, and operate under conditional access policies identical to your own employees. Access should be time-limited and approved through a formal change process.

Vendor Agreements That Protect You

Contracts should specify data handling, security standards, breach notification timelines, and termination procedures. Many vendors push back on strong requirements. If they do, ask yourself whether the convenience is worth the risk.

A reputable vendor will welcome security questions and be able to document their controls. If a vendor resists transparency, that is a red flag.

How Aegisys Can Help

We evaluate vendor security posture and help establish controls that protect your Microsoft 365 environment. Our SOC 2 Type II certification demonstrates our own commitment to security. Get your free assessment and learn how to secure your vendor relationships.

From the Aegisys team

Questions about vendor risk assessment? We can help.

No pitch, no pressure. A straightforward conversation about your vendor landscape and third-party risk controls.

Get your free security assessment
Aegisys mascot