Skip to content
Tenant Excellence

Product

What one read-only assessment checks

Seven areas, one sign-in, nothing installed. Each area lists what is read from your tenant, what you get back and which package includes it.

All packages

M365 security and best practices

The posture of the tenant as Microsoft exposes it, plus a CIS-inspired best-practices baseline scored control by control.

What is checked

  • Secure Score and its improvement actions
  • Conditional Access policies, MFA coverage and legacy authentication
  • Privileged roles, guest access and security defaults
  • Best-practices controls with a manual-verification guide where Graph cannot answer

What you get

  • A posture score with verdicts and prioritised findings
  • A best-practices report you can export
All packages

Email security

Every sending domain checked over DNS, with the record found, the record expected and a grade.

What is checked

  • SPF, DKIM and DMARC policy and alignment
  • MX, MTA-STS, TLS-RPT, DNSSEC and BIMI
  • One grade per domain across all verified domains

What you get

  • A domain-by-domain report with the exact change to make
  • Feeds the best-practices and compliance controls
From Complete

Compliance and auditor view

ISO 27001, NCA ECC, SAMA, NIS2 and DORA evaluated from tenant configuration, with proof on every covered control.

What is checked

  • Control status per framework: covered, partial, gap, not assessed
  • Tenant-sourced proof: the Graph or ARM response and its endpoint
  • Evidence you attach where a control needs a document or a screenshot

What you get

  • A 24-hour, read-only auditor link scoped to one framework
  • A compliance action plan you can print
All packages

Risk map

Findings from every framework you report against on one likelihood-by-impact matrix.

What is checked

  • 5 × 5 matrix across identity, email, endpoints, data, apps and monitoring
  • Each cell lists its controls and the frameworks that flag them
  • Filter by asset category

What you get

  • A ranked view of what to fix first
  • Risk by asset for the board pack
All packages

Users and licences

Seat use and adoption over 90 days, so unused premium licences and dormant accounts are visible.

What is checked

  • Assigned versus active licences, with editable unit prices
  • Adoption tiers for Teams, Exchange, OneDrive, SharePoint and Copilot
  • Dormant accounts and their licence assignments

What you get

  • Reclaim findings with an estimated saving
  • An inactive-users export with tiers and licences
Premium

Azure

Subscriptions read through Azure Resource Manager and Resource Graph; nothing is changed.

What is checked

  • Health check: identity and RBAC, Defender for Cloud, governance, network exposure, data protection, operations
  • Security findings, vulnerabilities and end-of-life intelligence
  • Configuration review with why-and-fix guidance
  • Cost: spend, idle resources and Advisor savings

What you get

  • Azure compliance against the same five frameworks
  • A unified Microsoft 365 and Azure dashboard
All packages

AI insights

A remediation plan and guided answers from Microsoft Work IQ, called from your browser under your own identity.

What is checked

  • Counts and statuses only: no names, addresses, domains or evidence text leave the browser
  • Needs the Work IQ service principal, consent and a Copilot-credits policy in your tenant

What you get

  • A prioritised remediation plan across findings
  • Guided chat about your results

Request a demo

See it on a real tenant

A demo walks through every area on the Contoso demo tenant or, with consent, on yours.

0 / 2,000