Home · Business · IT, Data & Security · Cybersecurity
As of 13 August 2026, AI can only partly check your Microsoft 365 security settings.
This still needs a person who signs their name to it.
Can you do it?
15 minutesto a draft.
1 hourto something you’d act on.
Cost, all in£0
Skill neededpower-user
Who has to check ita colleague
What the alternative costsNo priced alternative is provided in the supplied tool data.
If this goes wrong, you can miss a security weakness or apply a setting that disrupts access, email, devices or business operations.
What to actually do
Hand it to a person
The route this page recommends
A person who owns the outcome does this end to end, worth it when the failure is dear.
Use a tool built for this
Second choiceDo it yourself
The distant thirdA chat interface, power-user skill, and roughly 1 hour until you can act on the result.
How to actually do it
- Open the Microsoft 365 admin and security portals with an administrator or read-only reviewer and list which services are in scope, such as identity, email, devices and data protection.
- Export or record the relevant current settings and policies, removing passwords, access tokens, personal data and other secrets before sharing any material.
- Write down the organisation's requirements, accepted risks, user groups, devices, third-party connections and any recent security incidents or configuration changes.
- Paste the requirements and sanitised evidence into the prompt, keeping each export or screenshot labelled with its Microsoft 365 area and collection date.
- Ask the chatbot to produce the evidence table, missing-data list and remediation plan, and reject any finding that is not tied to supplied evidence.
- Open the Microsoft 365 area named for each finding and compare the AI's claimed value with the live setting and the current Microsoft documentation.
- Ask a colleague with Microsoft 365 security knowledge to confirm the high-risk findings and proposed rollback steps before anyone changes production settings.
- Apply approved changes through the normal change process, record the before and after values, and test sign-in, email, devices and affected services.
Prompt
Act as a Microsoft 365 security review assistant, not as an administrator. Analyse only the settings, exports, screenshots and policy requirements pasted below. Do not claim to have accessed Microsoft 365, do not invent settings or Microsoft features, and do not recommend changes that are not supported by the supplied evidence. Identify missing data before reaching a conclusion. Produce: 1. A table with each supplied setting, its observed value, the security purpose, whether it appears aligned with the stated requirements, and the evidence used. 2. A separate list of possible weaknesses, with severity described as low, medium or high only where the evidence supports it. 3. For every possible weakness, explain what could be affected, what additional fact would confirm it, and the exact Microsoft 365 admin area where a colleague should check it. 4. A remediation plan that starts with low-risk, reversible checks and clearly separates investigation from changes. 5. A list of assumptions, omissions and findings that require a qualified security professional. Do not tell me to disable security controls without explaining the risk and rollback. Do not include secrets, access tokens or personal data in your answer. Treat this as a review aid, not a security certification. Organisation type and requirements: [BRIEF DESCRIPTION] Microsoft 365 settings exports, screenshots or reports: [PASTE EVIDENCE HERE] Known incidents, constraints or recent changes: [PASTE DETAILS HERE]
Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.
What it gets wrong
- AI cannot see the complete live tenant unless you give an approved tool access, and pasted exports can omit important settings or dependencies.
- AI cannot know which security baseline, risk tolerance or compliance obligations your organisation has unless you provide them.
- AI cannot safely distinguish every deliberate exception from an insecure configuration in a complex tenant.
- AI cannot take responsibility for an outage, account lockout, data exposure or missed control after its recommendation is followed.
- AI cannot replace a security review that requires evidence from connected identity, endpoint, email and third-party systems.
What caps this at PARTLY: private data access, verification cost and legal accountability.
How we scored this
Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.
| Axis | Score (0–2) |
|---|---|
| Output | 1 |
| Inputs | 1 |
| Verification | 1 |
| Liability | 1 |
| Effort delta | 1 |
| Total | 5 / 10 |
The methodology and its thresholds are published in full.
FAQ
- Can ChatGPT access my Microsoft 365 security settings?
- Not from a normal chat unless you provide an approved integration with the required permissions. It can analyse exports, screenshots and reports that you paste, but it should not be given passwords, tokens or unrestricted administrator access.
- Can AI tell me if my Microsoft 365 tenant is secure?
- Partly. AI can organise supplied settings and identify apparent gaps against requirements you provide, but it cannot establish that the whole tenant is secure without complete evidence, current documentation and human review.
- Is it safe to let AI change my Microsoft 365 security settings?
- Do not let a general chatbot make unreviewed production changes. Use it to prepare a change plan, then have an authorised administrator check the setting, rollback method and impact before applying it.
- What should I give AI to check Microsoft 365 security?
- Give it sanitised settings exports or screenshots, the areas in scope, your security requirements, accepted exceptions and relevant recent changes. Leave out passwords, access tokens and unnecessary personal data, and ask it to identify missing evidence rather than fill gaps by guessing.
Nearby answers
- Can AI compare business antivirus software in the UK?PARTLY
- Can AI generate strong passwords for my business?PARTLY
- Can AI help my business respond to a ransomware attack?PARTLY
- Can AI help me secure my business Wi-Fi network?PARTLY
- Can AI spot a business email scam?PARTLY
- Can AI check whether my business passwords have been leaked?PARTLY
Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.
The newsletter
AI news, new answers and product picks, straight to your inbox.