Permissions
Read-only- Directory.Read.All
- User.Read.All
- Policy.Read.All
- DeviceManagement*.Read.All
- SecurityEvents.Read.All
- Sites.Read.All
FAQ
Read-only Graph and PowerShell. Collection in 15-30 minutes. Okta is not a false miss. Empty Intune is not a pass.
Graph .Read scopes. Defender for Endpoint if you authorize the API. A Global Administrator consents once. Nothing is written back to the tenant.
Collection is 15-30 minutes. Analysis is automatic. You walk the HTML the same day. A consultant-led M365 assessment is $15-30k and a binder nobody opens twice.
You hand over an encrypted credentials file. Collection runs against Graph and PowerShell. Reports from customer assessments stay in that customer folder. They never mix.
Guest in Teams, sharing on in SharePoint, no Conditional Access. Secure Score lists three settings. We list the way out, and the control that closes it.
Still asking
An installer creates the Entra app, lists every permission before consent, and encrypts credentials. A Global Administrator and about five minutes.
We detect federated versus managed domains and whether the IdP declares MFA. You will not get "MFA not configured" because Entra is not the factor that fires.
The assessment runs on any Microsoft 365 tenant. P2, Intune, Defender for Endpoint P2: those checks drop to informational or not assessed. No fake critical on a SKU you do not own.
Register independently, keep timestamped history, generate comparison reports. Built for MSPs and internal multi-tenant shops.
Dozens of findings is typical, including a handful of paths that span more than one service. Confirmed stays in the report. License-limited becomes a note. Empty stays empty.
CIS Microsoft 365 is verified on Graph. NIST CSF 2.0 is mapped. ISO 27001 and GDPR Art. 32 are aligned, and labelled that way. The auditor hears the difference.
Tell us the tenant size. We walk the report live.