Product

Every finding is one you can fix this week.

Okta is not a false MFA miss. E3 is not a PIM emergency. Empty Intune is not twenty-four greens. 229 controls, 23 paths, your SKU, your IdP.

Three mediums is not a plan. One path is.

Guest in Teams, sharing on in SharePoint, no Conditional Access. Secure Score lists three settings. We list the way out, and the control that closes it.

Attack path

23 cross-service correlations
Teams Guest access on
SharePoint External sharing
Entra No CA on guests
Path Data leaves the tenant

Your IdP already does MFA. We will not pretend it does not.

Okta, Ping, ADFS, any SAML or OIDC. If the domain says the IdP handles MFA, Entra is not scored as “MFA missing.” That is a week of false positives you never open.

MFA by provider

Federation-aware
Okta 280 Federated. IdP MFA on.
Entra ID 132 Managed. 91% Microsoft MFA.

412 enabled users. Coverage counted where it actually fires.

PIM is critical on P2. It is a note on E3.

Findings follow the SKU you bought. No ticket to enable a feature the tenant cannot turn on. E3, E5, P1, P2, Intune: severity moves with the license.

Same gap, right severity

License-aware
Entra ID P2 PIM not configured Critical
Microsoft 365 E3 PIM not configured Informational

Empty is empty. It never becomes a pass.

229 controls. Each one is excellent, good, needs work, a gap, not applicable, or not assessed. Missing Intune stays visible. It does not inflate the grade.

One status per control

229 unified
Critical gap
DMARCNo record on the primary domain.
Not assessed
Device encryptionIntune returned no data.
Good
Privileged MFACollected identity data is clean.

Say CIS out loud. Whisper ISO.

CIS Microsoft 365 is verified on Graph. NIST CSF 2.0 is mapped. ISO 27001 and GDPR Art. 32 are aligned, and labelled that way. The auditor hears the difference.

Compliance confidence

Three tiers
CIS M365 Verified Direct Graph checks
NIST CSF 2.0 Mapped By function
ISO / GDPR Aligned Technical controls only

Sized to the tenant

A 40-user shop is not graded like a bank.

Five org-size tiers. Thresholds, attack surface, and complexity are separate. The control score and the executive grade sit on the same curve.

Micro1-10 users
Small11-50 users
Mid-market51-250 users
Enterprise251-1000 users
Large enterprise1001+ users
  • MSPs. Baselines and deltas. Show what changed, tenant after tenant.
  • MITRE ATT&CK. A gap is a technique, not a checkbox.
  • Zero Trust. Identity, devices, data. Verify, least privilege, assume breach.
  • Defender for Endpoint. Per-device hardening. Silent if the API is not authorized.
  • License waste. Idle users and unused SKUs in the same pass.
  • White-label HTML. Your brand on the report. Excel for the tracker.
  • FAIR, if you need dollars. On top of the control list, not instead of it.
  • Read-only. Graph and PowerShell. Nothing written back.

You already have the data. You do not have the hour.

Tell us the tenant size. We walk the report live.