Compare

Keep Lighthouse or CIPP for admin. Use ConfigCheckup to prove the work to clients.

Where Lighthouse and CIPP run your tenants, ConfigCheckup assesses them, fixes what you approve with a dry run and a way back, and shows your clients the work. Here is how it fits, fairly.

Start free trial

Moving from another tool? Your plan is free until that contract ends, for up to 6 months. Facts about other products checked October 2026, with sources.

At a glance

The same questions, asked of every tool.

Each cell for another product comes from that vendor’s own public pages and links to the source. Where we could not confirm something, it says “See vendor”.

ConfigCheckup, Lighthouse, CIPP, Inforcer, Augmentt and Octiga, side by side. Facts about other products checked October 2026; each links to its source.
QuestionConfigCheckupLighthouseCIPPInforcerAugmenttOctiga
How it is pricedPer tenant, published monthly prices, no minimum termHow we show it (ConfigCheckup: How it is priced)Free for partners in the Cloud Solution Provider programmeSource (Lighthouse: How it is priced)Free to host yourself; hosted by CyberDrain from €99 a monthSource (CIPP: How it is priced)Per tenant, by quote; 20-tenant minimum, 12-month termSource (Inforcer: How it is priced)Per user, by moduleSource (Augmentt: How it is priced)See vendor (Octiga)
Free plan or trialFree plan for 1 tenant, and a 30-day trial on 3 tenants from your first connected tenantHow we show it (ConfigCheckup: Free plan or trial)Free for CSP partnersSource (Lighthouse: Free plan or trial)Free to host yourselfSource (CIPP: Free plan or trial)See vendor (Inforcer)See vendor (Augmentt)See vendor (Octiga)
Default access to client tenantsRead-only app. Write permissions sit in a separate app the client opts into, and can delete on its ownHow we show it (ConfigCheckup: Default access to client tenants)See vendor (Lighthouse)See vendor (CIPP)See vendor (Inforcer)See vendor (Augmentt)See vendor (Octiga)
Baselines across tenantsEvery tool here does this in some form.One standard for every tenant, with daily drift alerts (Monitor and above)How we show it (ConfigCheckup: Baselines across tenants)A default baseline per tenant, turned into a deployment planSource (Lighthouse: Baselines across tenants)Standards templates applied across tenantsSource (CIPP: Baselines across tenants)Baselines deployed across all tenants, with alignment and drift trackingSource (Inforcer: Baselines across tenants)Secure Autopilot applies baselines across every tenant in one stepSource (Augmentt: Baselines across tenants)Baseline templates deployed across tenants, with posture monitoringSource (Octiga: Baselines across tenants)
How a change is madeDry run, then approval by one or two people (your choice per tenant), a re-check and a way back (Monitor and above)How we show it (ConfigCheckup: How a change is made)Deployment plan tasks: some automated, some confirmed by handSource (Lighthouse: How a change is made)Each standard set to Report, Alert or Remediate; enforced every 12 hoursSource (CIPP: How a change is made)Remediate drift from the baselineSource (Inforcer: How a change is made)Drift fixed automaticallySource (Augmentt: How a change is made)Automatic remediation, around the clockSource (Octiga: How a change is made)
A fix counts as done whenThe tenant is read again and passes. “Marked done” alone never countsHow we show it (ConfigCheckup: A fix counts as done when)See vendor (Lighthouse)See vendor (CIPP)See vendor (Inforcer)See vendor (Augmentt)See vendor (Octiga)
Reads mail, file or chat contentNo. Configuration and activity onlyHow we show it (ConfigCheckup: Reads mail, file or chat content)See vendor (Lighthouse)See vendor (CIPP)See vendor (Inforcer)See vendor (Augmentt)See vendor (Octiga)
Policy areas coveredIdentity, admin access, devices, email, collaboration, threat protection, data and licensingHow we show it (ConfigCheckup: Policy areas covered)See vendor (Lighthouse)See vendor (CIPP)Policy libraries for Intune, Defender and PurviewSource (Inforcer: Policy areas covered)SharePoint, Purview and Teams added to Secure Autopilot on 1 September 2026Source (Augmentt: Policy areas covered)See vendor (Octiga)
Framework readiness reports20 frameworks, including Cyber Essentials, NCSC CAF, ISO 27001 and NIS2, control by controlHow we show it (ConfigCheckup: Framework readiness reports)See vendor (Lighthouse)See vendor (CIPP)See vendor (Inforcer)Baselines from CIS, NIST, SCuBA and Secure ScoreSource (Augmentt: Framework readiness reports)See vendor (Octiga)
Cyber Essentials readinessYes, with your answers for what Microsoft 365 cannot show. Readiness, not certificationHow we show it (ConfigCheckup: Cyber Essentials readiness)See vendor (Lighthouse)See vendor (CIPP)See vendor (Inforcer)See vendor (Augmentt)See vendor (Octiga)
Reports for clientsReport builder with a live preview, chosen sections, PDF, and email to the client, in your brandHow we show it (ConfigCheckup: Reports for clients)See vendor (Lighthouse)See vendor (CIPP)See vendor (Inforcer)Client reportingSource (Augmentt: Reports for clients)See vendor (Octiga)
Client portalA live page per client (Monitor and above)How we show it (ConfigCheckup: Client portal)See vendor (Lighthouse)See vendor (CIPP)See vendor (Inforcer)See vendor (Augmentt)See vendor (Octiga)
Lead health checksFrom one consent link, with the full report emailed to the leadHow we show it (ConfigCheckup: Lead health checks)See vendor (Lighthouse)See vendor (CIPP)See vendor (Inforcer)See vendor (Augmentt)See vendor (Octiga)
Licence savings and Microsoft invoice checkUnused seats costed, and your distributor invoice matched to every tenantHow we show it (ConfigCheckup: Licence savings and Microsoft invoice check)See vendor (Lighthouse)See vendor (CIPP)See vendor (Inforcer)See vendor (Augmentt)See vendor (Octiga)
Account takeover alertsWithin 15 minutes, with containment in one approved step (alerts from Monitor, containment with Monitor)How we show it (ConfigCheckup: Account takeover alerts)See vendor (Lighthouse)See vendor (CIPP)See vendor (Inforcer)Threat alertsSource (Augmentt: Account takeover alerts)Tuned alerts and incident responseSource (Octiga: Account takeover alerts)
Day-to-day user and mailbox adminNo, by design. Settings change only through approved fixesYes, multi-tenant administration from one portalSource (Lighthouse: Day-to-day user and mailbox admin)Yes: users, groups, mailboxes and GDAPSource (CIPP: Day-to-day user and mailbox admin)See vendor (Inforcer)See vendor (Augmentt)See vendor (Octiga)
24-hour security operations centrePeople watching and investigating overnight.No. Pair it with a managed detection service if clients need oneSee vendor (Lighthouse)See vendor (CIPP)Sells a separate Threat Detection & Response productSource (Inforcer: 24-hour security operations centre)See vendor (Augmentt)Incident response and 24/7 automatic remediationSource (Octiga: 24-hour security operations centre)

Facts about other products are taken from each vendor’s own public pages, checked October 2026. “See vendor” means we could not confirm it from their pages, not that they lack it. Products change: check the vendor’s site for the current position.

Tool by tool

What each tool is for, and what ConfigCheckup adds.

Microsoft 365 Lighthouse

Free for partners in the Cloud Solution Provider programme.

Microsoft’s portal for managing many customer tenants, with deployment plans built from its own baseline.

Where it is strong
Built in by Microsoft, free, and already open on most MSPs’ screens for day-to-day multi-tenant administration.
What ConfigCheckup adds
90 checks mapped to 20 frameworks, client-ready reports and a portal, lead health checks, licence savings, the Microsoft invoice check and CSP seat changes matched to licences in use, and fixes that are approved, checked again and can be rolled back.
Use both?
Yes. Lighthouse for running tenants; ConfigCheckup for assessing them and proving it to clients.

Sources: Microsoft Learn: Lighthouse FAQ, Microsoft Learn: Lighthouse overview

Lighthouse is free, so keep it. Use ConfigCheckup alongside it.

Start free trial

CIPP

Free to host yourself (you pay the Azure running costs); hosted by CyberDrain from €99 a month.

An open-source multi-tenant administration portal, with standards that report on, alert on or remediate settings across tenants, enforced every twelve hours.

Where it is strong
Breadth of tenant administration (users, mailboxes, standards across every tenant) at a very low price, with a large community.
What ConfigCheckup adds
Scores, framework readiness and reports written for clients, a client portal, prospecting, Cyber Essentials readiness, and automatic fixes that dry-run against the live tenant first, run under a named person’s approval, are checked again and can be rolled back.
Use both?
Yes. Many MSPs administer tenants in CIPP; ConfigCheckup is where clients see the posture and approve the work.

Sources: CIPP: Standards and drift, CyberDrain pricing

Paying CyberDrain to host CIPP? Your ConfigCheckup plan is free until that contract ends, for up to 6 months. How the switch offer works

Start free trial

Inforcer

Per tenant, by quote, with a 20-tenant minimum and a 12-month term. Threat Detection & Response is priced per mailbox user.

A platform for building Microsoft 365 security baselines and deploying them across tenants, with alignment and drift tracking.

Where it is strong
Deep policy libraries for Intune, Defender and Purview, and a large MSP customer base.
What ConfigCheckup adds
Published monthly pricing with no minimum, prospecting with an emailed report, client reports and portal, framework readiness reports, licence savings and the Microsoft invoice check.
Use both?
Possible, though both hold tenants to a baseline. Choose by what your clients need to see.

Sources: Inforcer pricing update, Inforcer platform

Moving from Inforcer? Your ConfigCheckup plan is free until that contract ends, for up to 6 months. How the switch offer works

Start free trial

Octiga

From $1 per user a month, by mailbox licences in each client tenant (as listed on G2).

Microsoft 365 security for MSPs: baselines across tenants, monitoring, alerts and automatic remediation of drift and incidents.

Where it is strong
Automatic remediation around the clock, licence-agnostic baselines, and a single multi-tenant dashboard.
What ConfigCheckup adds
Priced per tenant rather than per user, so large clients cost no more; client reports, a portal and framework readiness; licence savings and the Microsoft invoice check; and every automatic fix dry-run first and reversible.
Use both?
Possible, though both remediate. Choose by pricing model and by what your clients need to see.

Sources: Octiga, Octiga pricing on G2

Moving from Octiga? Your ConfigCheckup plan is free until that contract ends, for up to 6 months. How the switch offer works

Start free trial

Augmentt

Per user, from $250 a month for one module and 300 users; Alerts from $99 a month for 1,000 seats.

A Microsoft 365 command centre for MSPs: baselines, drift detection and auto-remediation (Secure Autopilot), threat alerts, and client reporting.

Where it is strong
Baselines from CIS, NIST, SCuBA and Secure Score deployed in one click, with drift fixed automatically and low-noise alerts. Since 1 September 2026, Secure Autopilot also covers SharePoint, Purview and Teams.
What ConfigCheckup adds
Per-tenant pricing with a Free plan; prospecting with an emailed report; licence savings, the Microsoft invoice check and CSP seat changes; and automatic fixes limited to reversible, lower-risk changes within a size limit.
Use both?
Possible, though both cover baselines and alerts. Choose by pricing model and the reports you need.

Sources: Augmentt pricing, Augmentt: Secure Autopilot, Augmentt: what’s new, September 2026

Moving from Augmentt? Your ConfigCheckup plan is free until that contract ends, for up to 6 months. How the switch offer works

Start free trial

ScubaGear, Maester and Monkey365

Free.

Free, open-source PowerShell tools that assess one tenant at a time against a baseline (CISA SCuBA, community tests, CIS) and write a report.

Where it is strong
Free, transparent and trusted by engineers; ScubaGear is CISA’s own tool for its baselines.
What ConfigCheckup adds
No scripts to run or maintain: every tenant assessed on a schedule, history and trends, reports a client can read, approved fixes, and CISA SCuBA readiness from the same checks.
Use both?
ConfigCheckup does the same job across every client without scripting; engineers can still run the tools for a second opinion.

Sources: CISA: SCuBA project, Monkey365 on GitHub

Free tools have no contract to wait out. Try ConfigCheckup on the same tenants and compare the reports.

Start free trial

What it does

What you get in ConfigCheckup.

  • 90 checks across identity, admin access, devices, email, collaboration, threat protection and licensing, each with evidence and steps.
  • 81 with an approved fix: a dry run against the live tenant, approval by one or two people (your choice per tenant; with two, at least one is not the person who raised it), a re-check, and a rollback.
  • Self-healing, with guardrails: approve a policy in advance and covered fixes run on their own when drift appears; only reversible, lower-risk fixes, within a size limit, each reported.
  • 20 frameworks, including Cyber Essentials, CISA SCuBA, ISO 27001, NCSC CAF and NIS2, with a readiness report for each.
  • Account takeover alerts: impossible travel, new countries, password spraying, MFA fatigue, and containment in one approved step or automatically.
  • Prospecting: a lead health check from one consent link, kept apart from your clients, with the full report emailed to the lead.
  • Money found: unused licences, Copilot seats nobody opens, invoice lines that do not match the tenant, and CSP seat counts changed in Partner Center as approved changes.
  • Fits your stack: tickets in HaloPSA, ConnectWise, Autotask or NinjaOne, alerts and approvals in Teams or Slack, and an API with webhooks.

Honestly

Where ConfigCheckup is not the tool.

  • Day-to-day administration

    Creating users, resetting passwords in bulk, managing mailboxes: use Lighthouse, CIPP or the admin centres. ConfigCheckup changes settings only through approved fixes.

  • A 24-hour security operations centre

    Security events alert you, and high-confidence takeovers can be contained automatically, but nobody investigates them overnight for you. Pair ConfigCheckup with a managed detection service if clients need that.

  • Networks and endpoints

    ConfigCheckup reads Microsoft 365. It does not scan networks or install an agent on devices; device evidence comes from Intune.

See it on one of your own tenants.

Read-only consent, a first assessment in minutes, and nothing changed without your approval.

Start free trial

30 days of everything in Automate on up to 3 tenants, from your first connected tenant. No card. Then Free unless you choose a plan.