Skip to content
Tenant Excellence

Know where your Microsoft tenant stands, with the proof to show for it.

A read-only assessment of Microsoft 365 and Azure: security posture, licences, email security and compliance against ISO 27001, NCA ECC, SAMA, NIS2 and DORA. Every finding carries evidence read from your tenant.

Built for

  • IT directors
  • CISOs
  • Compliance and risk officers
  • Microsoft partners
  • Entra ID
  • Conditional Access
  • Secure Score
  • Exchange Online
  • SharePoint
  • Teams
  • OneDrive
  • Intune
  • Defender
  • Purview
  • Licence use
  • DNS
  • Azure Resource Manager
  • Resource Graph
  • Cost Management
Write permissions requested
0
the consent screen lists read scopes only
Frameworks
6
five regulations and the M365 best-practices check
Auditor link lifetime
24 h
read-only, scoped to one framework, then it expires
Steps to a first result
3
register, consent, run in the browser
  • Read-only access

    Delegated permissions your administrator grants through Microsoft’s consent screen.

  • Runs in your browser

    The assessment reads your tenant from the browser session, not from our servers.

  • Tokens never stored

    Microsoft access tokens stay in the browser and are never stored on our servers.

  • You choose what is kept

    Only evidence you attach and 24-hour auditor snapshots leave the browser.

The problem

The audit asks for proof. The tenant already has the answers.

  1. 01Evidence is collected by handScreenshots, PowerShell exports and email threads, repeated for every framework and every audit cycle.
  2. 02Findings without proof are opinionsA control marked covered needs the policy, the setting or the record behind it, with its source.
  3. 03Frameworks overlap, tools do notNIS2, DORA, ISO 27001, NCA ECC and SAMA ask for the same tenant facts in different words.

What it assesses

One read-only assessment, seven areas

  • All packages

    M365 security and best practices

    Secure Score, Conditional Access, MFA, privileged roles and a CIS-inspired best-practices check.

  • All packages

    Email security

    SPF, DKIM, DMARC, MX, MTA-STS, TLS-RPT, DNSSEC and BIMI for every domain, with a grade.

  • From Complete

    Compliance and auditor view

    ISO 27001, NCA ECC, SAMA, NIS2 and DORA controls with tenant-sourced proof and a 24-hour auditor link.

  • All packages

    Risk map

    A 5 × 5 likelihood-by-impact matrix of findings across identity, email, endpoints, data, apps and monitoring.

  • All packages

    Users and licences

    Seat use, unused premium licences, dormant accounts and per-user adoption over 90 days.

  • Premium

    Azure

    Health check, security findings, configuration review, cost insights and compliance for your subscriptions.

  • All packages

    AI insights

    Remediation plans and guided answers from Microsoft Work IQ, called under your own identity with counts and statuses only.

How it works

Three steps, no agent, nothing installed

  1. 1Register the app and grant consentYour administrator registers the application and approves read-only permissions on Microsoft’s consent screen. The list on that screen is the whole permission set.
  2. 2Run the assessment in the browserSign in with your Microsoft account. The browser reads the tenant through Microsoft Graph and Azure Resource Manager and evaluates every control locally.
  3. 3Act on the results and share proofWork through findings by severity, attach evidence where a control needs it and hand your auditor a read-only link that expires in 24 hours.

In depth

Give the auditor a link, not a folder

Every covered control shows the data Microsoft Graph returned and the endpoint it came from. One click creates a read-only snapshot for one framework; it needs no account and expires after 24 hours.

  • Structured proof per control, with its Graph or ARM source
  • Scoped to one framework, read-only, no sign-in for the auditor
  • Expires after 24 hours; creation is written to the audit log
Learn more

In depth

See exposure by asset, not by tool

Findings from every framework you report against land on one likelihood-by-impact matrix. Filter by asset category to see what to fix first.

  • Identity, email, endpoints, data, apps and monitoring
  • Each cell lists its controls and the frameworks that flag them
  • Same tenant view, same sign-in
Learn more

In depth

Know which licences are used

Adoption tiers for Teams, Exchange, OneDrive, SharePoint and Copilot from 90-day usage reports, with dormant accounts still holding premium licences flagged.

  • Heavy, active, light and inactive tiers per workload
  • Per-user detail: meetings, messages, mailbox and file activity
  • Export inactive users with their licence assignments
Learn more

In depth

Check every sending domain

SPF, DKIM, DMARC, MX, MTA-STS, TLS-RPT, DNSSEC and BIMI, read over DNS, with a grade per domain and the record that needs to change.

  • One grade per domain, one check per record
  • The exact record found and the record expected
  • Feeds the best-practices and compliance controls
Learn more

Frameworks

Evaluated against your tenant configuration

Each framework maps to controls evaluated from Microsoft 365 and Azure settings. Pick the frameworks your obligations require.

  • ISO 27001

    From Complete

    International

    ISO/IEC 27001:2022 Annex A technical controls, evaluated from tenant configuration.

  • NCA ECC

    From Complete

    Saudi Arabia

    Essential Cybersecurity Controls of Saudi Arabia’s National Cybersecurity Authority (ECC-2:2024).

  • SAMA

    From Complete

    Saudi Arabia · financial sector

    Saudi Central Bank Cyber Security Framework, for financial institutions under SAMA supervision.

  • NIS2

    From Complete

    European Union

    Directive (EU) 2022/2555 security measures for essential and important entities.

  • DORA

    From Complete

    European Union · financial sector

    Regulation (EU) 2022/2554 ICT risk-management requirements for the financial sector.

  • Every tenant · every package

    A CIS-inspired configuration baseline for Microsoft 365. Advisory; not a CIS certification.

Results are configuration indications drawn from your tenant. They are not an audit opinion or a certification.

Packages

Choose the depth. The rigour does not change.

Every package runs the same read-only assessment. What changes is how much of your estate it covers and how many frameworks it reports against.

  • Essential

    Microsoft 365 security, email security and best practices.

    • M365 Security Assessment
    • M365 Best Practices Check
    • Email Security Posture Assessment
    • SPF / DKIM / DMARC Assessment
    • AI Insights & Recommendations

    Pricing on request · one tenant per company

    Request a demo
  • Complete

    Adds the five compliance frameworks, proof and the auditor view.

    Most complete
    • Everything in Essential
    • M365 Compliance Assessment (ISO 27001, NCA ECC, SAMA, NIS2, DORA)
    • M365 Compliance Auditor View
    • M365 Compliance Automated Evidence Generation
    • Azure Compliance Auditor View
    • Azure Compliance Automated Evidence Generation

    Pricing on request · one tenant per company

    Request a demo
  • Premium

    Adds Azure across the board and the unified dashboard.

    • Everything in Complete
    • Azure Health Check
    • Azure Security Assessment
    • Azure Configuration Review
    • Azure Optimization Insights
    • Azure Compliance Assessment (ISO 27001, NCA ECC, SAMA, NIS2, DORA)
    • Unified M365 & Azure Dashboard

    Pricing on request · one tenant per company

    Request a demo
Compare all 16 features

Questions

Questions we hear first

For anything else, ask during the demo. The call is run by the people who built the checks.

Does anything from our tenant get stored on your servers?

Assessment data stays in the browser. The only tenant-derived data we store is what you choose to create: evidence you attach to a control and auditor snapshots, which expire after 24 hours. We also keep account records and a 90-day audit log.

Can the assessment change anything in our tenant?

No. The permissions requested are read-only and are listed on Microsoft’s consent screen before anything is authorised.

Does it read our email or files?

No. The service is not designed to read email, chat, file or recording content. It reads configuration and usage metadata.

Is a covered control a certification?

No. Results are configuration indications drawn from your tenant. They support your audit; they are not an audit opinion or a certification.

Where do the AI insights go?

From your browser to Microsoft’s Work IQ, under your own Microsoft identity. The payload contains counts and statuses only, never names, addresses or evidence text.

How many tenants can one company assess?

One tenant per company during the beta.

Request a demo

See the assessment on a real tenant

Tell us about your estate and we will schedule a walkthrough on a demo tenant or, with consent, on yours.

  • Read-only access
  • Runs in your browser
  • Tokens never stored
  • You choose what is kept

0 / 2,000