Product
What one read-only assessment checks
Seven areas, one sign-in, nothing installed. Each area lists what is read from your tenant, what you get back and which package includes it.
M365 security and best practices
The posture of the tenant as Microsoft exposes it, plus a CIS-inspired best-practices baseline scored control by control.
What is checked
- Secure Score and its improvement actions
- Conditional Access policies, MFA coverage and legacy authentication
- Privileged roles, guest access and security defaults
- Best-practices controls with a manual-verification guide where Graph cannot answer
What you get
- A posture score with verdicts and prioritised findings
- A best-practices report you can export
Email security
Every sending domain checked over DNS, with the record found, the record expected and a grade.
What is checked
- SPF, DKIM and DMARC policy and alignment
- MX, MTA-STS, TLS-RPT, DNSSEC and BIMI
- One grade per domain across all verified domains
What you get
- A domain-by-domain report with the exact change to make
- Feeds the best-practices and compliance controls
Compliance and auditor view
ISO 27001, NCA ECC, SAMA, NIS2 and DORA evaluated from tenant configuration, with proof on every covered control.
What is checked
- Control status per framework: covered, partial, gap, not assessed
- Tenant-sourced proof: the Graph or ARM response and its endpoint
- Evidence you attach where a control needs a document or a screenshot
What you get
- A 24-hour, read-only auditor link scoped to one framework
- A compliance action plan you can print
Risk map
Findings from every framework you report against on one likelihood-by-impact matrix.
What is checked
- 5 × 5 matrix across identity, email, endpoints, data, apps and monitoring
- Each cell lists its controls and the frameworks that flag them
- Filter by asset category
What you get
- A ranked view of what to fix first
- Risk by asset for the board pack
Users and licences
Seat use and adoption over 90 days, so unused premium licences and dormant accounts are visible.
What is checked
- Assigned versus active licences, with editable unit prices
- Adoption tiers for Teams, Exchange, OneDrive, SharePoint and Copilot
- Dormant accounts and their licence assignments
What you get
- Reclaim findings with an estimated saving
- An inactive-users export with tiers and licences
Azure
Subscriptions read through Azure Resource Manager and Resource Graph; nothing is changed.
What is checked
- Health check: identity and RBAC, Defender for Cloud, governance, network exposure, data protection, operations
- Security findings, vulnerabilities and end-of-life intelligence
- Configuration review with why-and-fix guidance
- Cost: spend, idle resources and Advisor savings
What you get
- Azure compliance against the same five frameworks
- A unified Microsoft 365 and Azure dashboard
AI insights
A remediation plan and guided answers from Microsoft Work IQ, called from your browser under your own identity.
What is checked
- Counts and statuses only: no names, addresses, domains or evidence text leave the browser
- Needs the Work IQ service principal, consent and a Copilot-credits policy in your tenant
What you get
- A prioritised remediation plan across findings
- Guided chat about your results
Request a demo
See it on a real tenant
A demo walks through every area on the Contoso demo tenant or, with consent, on yours.