Service

Infrastructure Audits & Assessments

A clear, evidence-based picture of your environment, with recommendations you can act on.

You cannot plan improvements to an environment you cannot see clearly. Documentation drifts, knowledge leaves with people and small risks accumulate unnoticed.

I deliver infrastructure audits under a defined statement of work, using read-only PowerShell collectors to gather consistent evidence across server estates, Active Directory and Microsoft 365, then turn the findings into clear, prioritised recommendations for technical and business readers.

Common challenges

  • Documentation that is outdated or missing
  • Unknown risk ahead of a migration or a change of IT provider
  • Servers and services nobody is certain are still needed
  • Security questions from insurers or leadership without clear answers
  • No prioritised roadmap for infrastructure investment

What's included

Server estate review

Operating system versions, roles, patching, storage and support status across every server.

Active Directory health

Replication, DNS, FSMO roles, stale accounts, privileged groups and Group Policy analysis.

Microsoft 365 and identity review

Tenant configuration, licensing, conditional access and admin role assignments.

Security posture

Findings mapped to Microsoft Secure Score and Cyber Essentials controls.

Read-only, low-risk collection

Scripts gather evidence without changing anything, so audits are safe to run in production.

Prioritised recommendations

A clear report ranking findings by risk and effort, with a practical remediation roadmap.

Approach

  1. Scope

    Agree objectives, systems in scope and deliverables in a statement of work.

  2. Collect

    Run read-only collectors and review configuration consistently across the estate.

  3. Analyse

    Assess findings against best practice, supportability and security baselines.

  4. Report

    Present prioritised recommendations and a remediation roadmap.

Proven in practice

  • Fourteen-server infrastructure audit delivered with a client-facing recommendations report
  • Reusable read-only PowerShell collectors for consistent evidence across server estates
  • Infrastructure audits delivered under statement of work as part of managed services engagements

Technologies

  • PowerShell
  • Active Directory
  • Windows Server
  • Microsoft 365
  • Entra ID
  • Microsoft Secure Score
  • Cyber Essentials
  • Hyper-V
  • VMware ESXi

Tools change. Good engineering doesn't. I work with the platforms already in place and adapt quickly to new ones.

Frequently asked questions

Will the audit affect our live systems?

No. Data is collected with read-only scripts that do not change configuration, so audits are safe to run in production during business hours.

What do we receive at the end?

A report with an executive summary, detailed findings and recommendations ranked by risk and effort, followed by a walkthrough of the results.

When is an audit most useful?

Before a migration or major upgrade, when taking over an environment from another provider, when documentation is out of date, or when planning next year's IT investment.

Discuss your requirements

Share the details of your Infrastructure Audits & Assessments project and I will outline a practical approach for your environment.

Get In Touch