Security assessment

A Microsoft 365 security assessment for every tenant you manage.

Identity, email, devices, sharing and apps, checked with read-only consent, scored, and mapped to the frameworks your clients are audited on.

Changes since the last assessment: fixes verified and credited, one marked done but still failing

What you get

Read-only by default

Admin consent to read settings. Nothing is changed unless you grant write permission and approve each change.

Worst first

Findings across every tenant, by severity, with the evidence and how to fix each.

Proof it changed

Each assessment is compared with the last, so a fix counts only once the tenant passes.

Frameworks

Readiness for Cyber Essentials, ISO 27001, NIS2, DORA, SOC 2 and more, control by control.

How it works

  1. 01

    Connect

    One admin consent per tenant, or import them all from Partner Center.

  2. 02

    Assess

    A few minutes per tenant. Anything that could not be read is named, never scored as a pass.

  3. 03

    Act

    Fix, quote, report and track, from the same place.

What it can’t see

Said plainly, so you know what you are buying.

  • It reads Microsoft 365 settings and activity, not mail or file content.
  • Areas a tenant is not licensed for (such as Intune or Entra ID P2) are reported as not collected.

Permissions it uses

Microsoft Graph permissions, granted by the client’s admin.

  • Directory.Read.All
  • Policy.Read.All
  • AuditLog.Read.All
  • Reports.Read.All

Every permission, and why

Questions

Which permissions does it need?
The full list, and why each is needed, is on the data protection page. Write permissions are optional and only used for changes you approve.

See it on your own tenant.

Fourteen days, one tenant, no card. The figures come from your tenant, not from averages.

Start a free trial