FAQ

Will it write? It will not.

Read-only Graph and PowerShell. Collection in 15-30 minutes. Okta is not a false miss. Empty Intune is not a pass.

The installer asks for read. It never asks for write.

Graph .Read scopes. Defender for Endpoint if you authorize the API. A Global Administrator consents once. Nothing is written back to the tenant.

Permissions

Read-only
Read
  • Directory.Read.All
  • User.Read.All
  • Policy.Read.All
  • DeviceManagement*.Read.All
  • SecurityEvents.Read.All
  • Sites.Read.All
The installer lists every scope before consent.
Write None Nothing written back.

4-6 weeks is a project. This is a meeting.

Collection is 15-30 minutes. Analysis is automatic. You walk the HTML the same day. A consultant-led M365 assessment is $15-30k and a binder nobody opens twice.

Time to report

Same day
Consultant
4-6 weeks
Circle360
< 1 hour
15-30 minCollect
MinutesAnalyze
Same dayWalk it

Your tenant does not land in a marketing pile.

You hand over an encrypted credentials file. Collection runs against Graph and PowerShell. Reports from customer assessments stay in that customer folder. They never mix.

Where the data sits

Per tenant
01
Encrypted credentials You hand over the file. Nothing in clear.
02
Read Graph and PowerShell Collection only. No write-back.
03
customers/your-domain/ Reports stay in that folder. Not a shared pile.

Secure Score counts settings. Attackers count paths.

Guest in Teams, sharing on in SharePoint, no Conditional Access. Secure Score lists three settings. We list the way out, and the control that closes it.

Attack path

23 cross-service correlations
Teams Guest access on
SharePoint External sharing
Entra No CA on guests
Path Data leaves the tenant

Still asking

Installer. IdP. SKU. MSP.

How is it deployed?

An installer creates the Entra app, lists every permission before consent, and encrypts credentials. A Global Administrator and about five minutes.

What if we use Okta, ADFS, or Ping?

We detect federated versus managed domains and whether the IdP declares MFA. You will not get "MFA not configured" because Entra is not the factor that fires.

Do we need E5?

The assessment runs on any Microsoft 365 tenant. P2, Intune, Defender for Endpoint P2: those checks drop to informational or not assessed. No fake critical on a SKU you do not own.

Multiple tenants?

Register independently, keep timestamped history, generate comparison reports. Built for MSPs and internal multi-tenant shops.

What does a first pass find?

Dozens of findings is typical, including a handful of paths that span more than one service. Confirmed stays in the report. License-limited becomes a note. Empty stays empty.

Which frameworks, and how sure?

CIS Microsoft 365 is verified on Graph. NIST CSF 2.0 is mapped. ISO 27001 and GDPR Art. 32 are aligned, and labelled that way. The auditor hears the difference.

You already have the data. You do not have the hour.

Tell us the tenant size. We walk the report live.