Skip to content
MS Cloud Support

Free · Self-serve · Read-only · No call required

Free Microsoft 365 security assessment

Review your Microsoft 365 security with read-only access. Available evidence and licences determine which controls can be assessed.

Continue to Microsoft sign-in
Ask for onboarding help (optional)

We use these details to help with assessment onboarding. Next you will continue to our dashboard and Microsoft sign-in. We never ask for your Microsoft password here. Review our privacy policy before submitting.

You need a Microsoft 365 Global Administrator to approve the read-only consent. You can revoke it yourself at any time.

The client dashboard on the Contoso sample tenant: grade D+ at 51%, 70 of 101 controls with a verified verdict, and a map of all 101 controls
The dashboard · Contoso sample tenant

The assessment catalogue

101 controls. Each one explained.

Identity, email, Teams, sharing, Defender, devices and more. The free assessment reads your tenant with read-only consent. Every result includes its evidence and confidence.

Measured coverage depends on your licences and the evidence available. Unavailable or uncertain controls are distinguished from confirmed failures.

Identity · 17
Privilege · 11
Email · 12
Defender · 8
Sharing · 10
Teams · 12
Data · 8
Application · 7
Power Platform · 9
Device · 4
Logging · 3

101 controls · 11 domains

Point at a cell, or tab in and use the arrow keys, to read the control it checks.

  • verified
  • needs evidence
  • at risk
  • not measured
List all 101 controls

Identity

  • IAM-001 Require MFA for all users
  • IAM-002 Block legacy authentication
  • IAM-003 MFA registered for all active users
  • IAM-004 Security Defaults OR Conditional Access in force
  • IAM-005 Sign-in risk policy enabled
  • IAM-006 User risk policy enabled
  • IAM-007 High-risk users are blocked or remediated
  • IAM-008 Phishing-resistant MFA available/enforced for all users
  • IAM-009 SMS/Voice is not an allowed primary MFA method
  • IAM-010 Microsoft Authenticator shows login context (number matching)
  • IAM-011 Migrated off legacy per-user MFA to the Authentication Methods policy
  • IAM-012 Cloud account password expiration disabled
  • IAM-013 Guest sign-ins require MFA
  • IAM-014 Self-service password reset with strong verification
  • IAM-015 Device registration/join requires MFA
  • IAM-016 Device code authentication flow blocked
  • IAM-017 Admin notification on high-risk users

Privilege

  • ADM-001 Global Administrator count right-sized
  • ADM-002 Break-glass emergency account exists and is CA-excluded
  • ADM-003 Privileged roles are PIM-eligible, not permanently active
  • ADM-004 Admins require phishing-resistant MFA
  • ADM-005 Privileged users are cloud-only accounts
  • ADM-006 Privileged role activation requires approval
  • ADM-007 Privileged role activation/assignment alerting
  • ADM-008 Access reviews for privileged roles and guests
  • ADM-009 Privileged role provisioning restricted to PIM/PAM
  • ADM-010 Alert on Global Administrator activation
  • ADM-011 Privileged users use finer-grained roles instead of Global Administrator

Email

  • EXO-001 External mailbox auto-forwarding blocked
  • EXO-002 SPF record published
  • EXO-003 DKIM signing enabled for all domains
  • EXO-004 DMARC record published
  • EXO-005 DMARC policy enforced (p=reject)
  • EXO-006 SMTP AUTH disabled tenant-wide
  • EXO-007 Mailbox auditing enabled
  • EXO-008 External sender identification enabled
  • EXO-009 Connector/IP allow-list not used to bypass filtering
  • EXO-010 Additional storage providers disabled in Outlook on the web
  • EXO-011 Contact folders not shared with all domains
  • EXO-012 Calendar details not shared with all domains

Defender

  • DEF-001 Microsoft Secure Score baseline
  • DEF-002 Preset security policies (Standard or Strict) enabled
  • DEF-003 Safe Attachments enabled
  • DEF-004 Safe Links enabled
  • DEF-005 Anti-phishing impersonation protection configured
  • DEF-006 Common attachment / malware filter configured
  • DEF-007 Security alerts enabled
  • DEF-008 Security alerts routed to a monitored address / SIEM

Sharing

  • SHR-001 External sharing not set to "Anyone
  • SHR-002 Guest access restrictions configured
  • SHR-003 '"Anyone" link expiration and permission limited'
  • SHR-004 Default sharing link scope is specific people
  • SHR-005 Reauthentication required for external users
  • SHR-006 SharePoint custom scripts disabled
  • SHR-009 OneDrive external sharing limited
  • SHR-010 Default file/folder sharing permission is view-only
  • SHR-011 '"Anyone" link permission is view-only'
  • SHR-012 Guest invitations restricted to inviters

Teams

  • TMS-001 External access (federation) restricted
  • TMS-002 Contact with unmanaged / Skype consumer users blocked
  • TMS-003 Anonymous users cannot start meetings
  • TMS-004 Meeting lobby admits authenticated users only
  • TMS-005 Third-party and custom app usage governed
  • TMS-006 Teams email integration disabled
  • TMS-007 External participants cannot request control of shared desktop
  • TMS-008 Internal users cannot initiate contact with unmanaged users
  • TMS-009 Only agency-approved Microsoft apps installable
  • TMS-010 Meeting recording restricted
  • TMS-011 Dial-in (PSTN) users cannot bypass the meeting lobby
  • TMS-012 Live events are not forced to always record

Data

  • DLP-001 DLP policies protect sensitive information
  • DLP-002 Sensitivity labels published
  • DLP-003 Retention policy configured
  • DLP-004 Custom DLP policy scoped to Exchange, OneDrive, SharePoint, Teams, and Devices
  • DLP-005 DLP policy blocks sharing sensitive information with everyone
  • DLP-006 DLP policy notifies and educates users
  • DLP-007 Restricted-apps list defined for endpoint DLP
  • DLP-008 Endpoint DLP blocks restricted apps and unwanted Bluetooth transfers

Application

  • APP-001 User consent to apps restricted
  • APP-002 No over-privileged / illicit OAuth grants
  • APP-003 Admin consent request workflow enabled
  • APP-004 Group owner consent restricted
  • APP-005 App registration restricted to admins
  • APP-006 No stale or long-lived app credentials
  • APP-007 Application password (secret) credential addition blocked

Power Platform

  • PWR-001 Environment creation restricted to admins
  • PWR-002 Trial environment creation restricted
  • PWR-003 DLP policy on the default environment
  • PWR-004 Power Platform tenant isolation enabled
  • PWR-005 Non-default environments covered by a DLP policy
  • PWR-006 Power Platform connection allow-list configured
  • PWR-007 Content Security Policy enforced for Power Apps
  • PWR-008 Power Pages site creation restricted to admins
  • PWR-009 Share with Everyone disabled in Power Apps

Device

  • DEV-001 Intune compliance policies exist
  • DEV-002 Conditional Access requires a compliant / hybrid-joined device
  • DEV-003 Disk encryption (BitLocker/FileVault) enforced
  • DEV-004 Mobile app protection (MAM) policies configured

Logging

  • LOG-001 Unified audit log enabled
  • LOG-002 Sign-in and audit logs exported to durable storage / SIEM
  • LOG-003 Audit log retention adequate

After the assessment

A free start. A clear choice about what comes next.

Your first successful live Microsoft 365 assessment starts a 15-day dashboard trial. Exploring sample data first does not use up that live trial. No card is required and there is no automatic paid conversion.

If you do not continue

Keep your summary

Your stored score, grade, headline counts and reading date remain visible. Existing ticket history stays available.

New scans, detailed findings and evidence, remediation guidance, drift and new dashboard tickets pause when the trial expires. Your Microsoft services keep running; trial expiry does not change their settings.

Access and data when you leave

For your own IT team

Continue with the Basic pack

US$99 / tenant / month

Continue using detailed evidence, remediation guidance, repeat assessments, drift and assessment-related tickets. The same read-only assessment access applies.

Request activation from Your pack in the dashboard. Your request is saved with a reference and progress history in Service requests. We arrange an invoice and confirm activation. General IT helpdesk and changes performed for you are separate managed services.

View dashboard pricing

For ongoing engineering support

Become a managed-service client

Agree an engineer-led service for your Microsoft cloud, users and devices. We scope the support, changes and automation you want before requesting management access.

Published managed plans start at US$89 per user/month, with a 10-user minimum. Microsoft licences and onboarding are separate. A dashboard subscription does not automatically start this service.

See the managed onboarding steps

Need help choosing after your trial expires? You can still request pack activation or contact us directly.

Explore the dashboard, assessment steps and coverage

Why this one is different

How to interpret your assessment

Review the evidence, costs and access boundaries before deciding what to do.

Findings that fit your licences

Failing controls are ranked by severity, with the evidence behind each verdict. Controls that need a licence you do not have are listed separately as not assessed, and never counted as passing or failing.

Unverified means unverified

If we cannot measure a control in your tenant, it is reported as not assessed. It is never quietly counted as a pass, and never inflated into a failure to make the report look busy.

Read-only, and revocable

The assessment app reads settings and security signals. It does not write to your tenant. Your Global Administrator grants the consent, and can remove it from the Azure portal at any time without contacting us.

The product

What the dashboard looks like

Screenshots and a recorded walkthrough using an illustrative sample tenant. Your dashboard shows the evidence available for your tenant; features and layout can differ from this recording.

Recorded on the current dashboard with an illustrative Contoso sample, not customer results or proof of live coverage. Silent recording with captions on screen; no audio track or client data.
Findings page: 70 of 101 controls assessed, 31 without a verified verdict, 12 critical or high controls failing, with filters by severity, status, framework and confidence
Findings: filter by severity, status, framework or confidence, then open any finding to see its evidence.
Conditional Access page: 1 of 8 evaluated controls enforced, 7 coverage gaps and 3 not licensed, each gap naming the policy to create
Conditional Access, control by control, with the policy each gap needs.
Read the walkthrough as text
  1. A recorded walkthrough of the client dashboard using an illustrative Contoso sample. The figures are examples, not your tenant's results.
  2. The overview opens on what needs your attention: verified critical and high failures, ranked by risk.
  3. All 101 controls on one map: passing, failing, needing verification, or not assessed.
  4. The grade and its history. Controls we could not check are never counted as passing.
  5. Since your last scan: what was fixed, what regressed and what is still open.
  6. Findings: filter by severity, status, framework or confidence, and export to CSV.
  7. Each finding opens to the evidence behind the verdict and the fix to apply.
  8. Conditional Access, control by control: what is enforced, what is a gap, and what your licence does not cover.
  9. Remediation is ranked by risk. Nothing changes in your tenant: each fix starts as a request to an engineer.
  10. Ask for help from any finding. Each ticket shows who owns it, the next update and the whole conversation.
  11. Free, self-serve and read-only. Revoke access from Entra ID at any time.

How it works

Four steps, and none of them is a sales call

From the moment you click start to the moment you are looking at findings.

Step 1

Sign in with Microsoft

Tell us who you are, then use your work account. No new password and no software to install.

Step 2

A Global Admin approves consent

Microsoft shows the exact read-only permissions on its own consent screen. Nothing runs until an admin approves it there.

Step 3

The scan runs

We read available configuration through Microsoft Graph and evaluate a catalogue of 101 controls. Coverage depends on your licences, permissions and available evidence; unsupported checks are marked not assessed.

Step 4

Your dashboard appears

Findings, evidence and priorities in the browser, ready to work through or hand to whoever owns the tenant.

Scope

Exactly what we touch

Worth reading before you take this to whoever owns your tenant. It is the question they will ask.

What we read

  • Entra ID configuration: admin roles, guest access, user and group settings
  • Conditional Access and authentication method policies
  • Available mailbox settings and security signals; checks without sufficient service evidence are marked not assessed
  • Available SharePoint tenant sharing and external access settings
  • Device compliance and Intune policy configuration, where you are licensed for it
  • Your subscribed licences, so we can tell what you are entitled to switch on

What this assessment does not do

  • The assessment does not write to your tenant. No policy is created, changed or deleted.
  • The assessment does not request email-message, document or chat-reading permissions. Mailbox settings and logs can still contain personal information; see the permission catalogue below.
  • We do not read or store passwords, and we never ask for one.
  • We do not install an agent, a script or any software on your devices.
  • An admin does not need to stay signed in. The consented read-only application access persists until you revoke it.

What you get

A dashboard you can act on the same day

No slide deck, no maturity score with nothing behind it.

A catalogue of 101 controls

Live findings reference the configuration and evidence we can retrieve. Unavailable or unverified checks are disclosed as not assessed, so the catalogue is not a promise of 101 measured results.

A confidence grade on every finding

You can see how sure we are of each result and what evidence it came from, so you know which items to act on and which to check first.

Framework mapping

Findings are mapped to CIS, CISA ScubaGear and NIST CSF, which makes the report usable in an audit conversation or an insurance questionnaire.

A prioritised fix list, cheapest first

Ordered by risk, with the changes that cost nothing on your current licences at the top.

What it does not do yet

  • • This assessment covers Microsoft 365. Azure has a separate, customer-initiated read-only snapshot for an explicitly connected subscription. It shows the resource, security and cost evidence the Azure APIs return, with permission and coverage gaps stated. It is not a comprehensive Azure control assessment. Microsoft 365 consent does not cover Azure subscriptions.
  • • It reports, it does not remediate. Nothing is changed for you.
  • • There is no emailed PDF report. Full results are available in the dashboard during the trial or an active plan; summary access remains after expiry.

Becoming a client

From findings to an agreed managed service

Start a managed onboarding request in the dashboard. Your engineer records the scope, terms, access review, pilot and handover evidence so you can follow progress. Completing the assessment, paying for the Basic pack or recording a milestone does not automatically grant management permissions.

  1. 01

    Choose the service

    Review the findings together. Agree which users, tenants, subscriptions and devices are in scope, what is excluded, and the service and licence costs.

  2. 02

    Agree ownership and terms

    Name your technical and billing contacts and who may approve changes. Confirm support hours, response targets, escalation, cancellation and data-handling terms in your service order.

  3. 03

    Review the access request

    Your administrator reviews each application, delegated role or device tool, its purpose, scope and revocation method. Assessment consent does not cover these additional permissions.

  4. 04

    Validate before go-live

    Check the connections, ticket route, notifications and agreed procedures with a pilot. Record the baseline, change windows and rollback approach before management starts.

  5. 05

    Run the agreed service

    Track requests and findings, review changes and their verification, and revisit service coverage with your engineer. The service order sets the reporting cadence and review schedule.

Permissions & automation

Different work needs different access

There is no single “autonomous MSP” permission. Read-only assessment consent, paid service activation and permission to make a change are separate decisions. The exact management request depends on your chosen workloads and tasks.

Assessment and Basic pack: the read-only permission catalogue

The paid dashboard uses the same assessment app; it does not request write access simply because you pay. The catalogue below matches the platform onboarding list. Review Microsoft's actual consent screen before accepting.

Directory, authentication and applications

Directory objects, memberships, privileged roles, registered authentication methods, app grants and licences. Authentication method records can include registered phone numbers.

  • Directory.Read.All
  • RoleManagement.Read.Directory
  • UserAuthenticationMethod.Read.All
  • Application.Read.All
  • Organization.Read.All

Policies and security signals

Policy and sharing settings, sign-in/audit records, usage reports and Microsoft security signals. Logs and reports can identify individual accounts.

  • Policy.Read.All
  • SharePointTenantSettings.Read.All
  • AuditLog.Read.All
  • Reports.Read.All
  • SecurityEvents.Read.All

Mailbox settings

Mailbox configuration can include the text of automatic out-of-office replies, working hours and language. This is broader than a simple configuration flag; it does not grant Mail.Read or Mail.Send.

  • MailboxSettings.Read

Licensed services

Risk detections, Intune device/configuration records and Defender hunting data where the tenant's licences and access support them. Unavailable coverage is disclosed in the results.

  • IdentityRiskyUser.Read.All
  • IdentityRiskEvent.Read.All
  • DeviceManagementManagedDevices.Read.All
  • DeviceManagementConfiguration.Read.All
  • ThreatHunting.Read.All

Read-only access can still return personal information in logs, directory records and mailbox settings. We do not request permissions to read email messages, documents or chats. Microsoft Graph permission definitions explain the scope of each grant.

Microsoft 365 management: task-specific delegated roles or application consent

Human administrators may use a customer-approved delegated relationship such as GDAP where the partner relationship supports it, or separately agreed tenant roles. GDAP is granular and time-bound; it does not automatically authorize a separate unattended application.

An unattended application needs its own explicitly consented API permissions. For example, changing Conditional Access can require Policy.ReadWrite.ConditionalAccess; updating Intune configuration can require DeviceManagementConfiguration.ReadWrite.All. Those permissions can affect access or many devices. They are examples to review for a selected task, not a bundle requested by this assessment.

Before agreeing a management grant, review the named app or role, who will use it, affected resources, permitted actions, expiry/review date and how to remove it. Do not send us an administrator password through an enquiry form.

Microsoft's GDAP overview · Application permission reference

Azure: separate subscription or resource-group delegation

Azure uses a separate read-only snapshot for each connected subscription. An authorized customer administrator starts collection in the dashboard. The results show the resource, security and cost evidence Azure actually returns, with source times and any missing permissions or coverage. Opening a page or saving connection details does not start collection.

Microsoft 365 consent does not cover Azure resources. Azure needs separately reviewed access at the agreed scope; cost and security APIs may require additional permissions or product availability. A visible subscription does not prove a particular role or complete assessment coverage. Read-only collection does not change resources.

Managed Azure work needs separately reviewed Azure RBAC roles at the agreed subscription or resource-group scope. Some management roles also expose data or keys, so “resource management” should not be read as a promise of no data access. We must review the actual roles for your service.

Azure Lighthouse roles and scope

Devices, backups and remote support: additional tools only when agreed

The browser assessment installs no endpoint agent. Device management may require Intune enrolment, and remote support or backup services may require a separately approved tool, app or agent. The onboarding scope should name the devices, data accessible, remote-session controls, retention and removal procedure before deployment.

What is automated today?

The platform supports Microsoft 365 read-only assessments and scheduled rescans for eligible, connected tenants. Azure snapshots are collected separately when an authorized administrator requests them; they are not continuous monitoring or a comprehensive control assessment. Support requests are recorded for review and do not guarantee an automated response.

Unattended tenant remediation is not enabled through this trial or the Basic pack. Managed changes require an agreed procedure and the necessary access and approval. Buying a plan, granting read access or pressing Request help is not approval to alter a policy, disable a user or wipe a device.

Questions to settle before service starts

Who approves changes, and how do we see what happened?

Agree named approvers, any narrowly defined pre-approved procedures, maintenance windows and escalation contacts in your service scope. Authorized customer approvers can review a specific proposal in the dashboard and record approval or denial. Review its target, expected impact, verification and rollback plan before deciding.

Execution is separate and currently paused. Recording approval does not mean a change has run. A request, an approved proposal and a verified completed change are different states; ask for completion evidence before treating a recommendation as implemented.

What support, reporting and incident response are included?

Basic pack tickets cover assessment findings and posture. General user support, continuous monitoring, out-of-hours response and incident containment depend on the managed service you agree. Confirm coverage hours, response targets, contact channels, reporting cadence and the route for urgent incidents before go-live. A response target is not a guarantee of resolution time.

What happens if we cancel or revoke access?

Trial expiry does not automatically revoke an existing Microsoft grant or delete stored results. To withdraw assessment access, your administrator can remove the assessment enterprise application in Microsoft Entra. Separately review any Azure delegation, GDAP relationship, management app or device tool added for a managed service.

Billing cancellation, access revocation and data deletion are separate steps. Agree notice periods, handover, export and retention/deletion terms in the service order. Submit a data export or deletion request in the dashboard’s Service requests area, which remains available after trial expiry. An authorized administrator can prepare a short-lived, signed-in download of the supported portal records for their export request. Its manifest identifies what is included and what still needs separate collection from providers, files or backups; a portal download does not complete a whole-service export.

You receive a request reference and can follow up there. For enquiry records or help signing in, contact us directly. Our team verifies authority, holds, provider results and the agreed policy before recording wider fulfilment. Submitting a request does not itself delete data, revoke access or cancel billing.

What should our IT or procurement team prepare?
  • Tenant IDs, verified domains, approximate user/device counts and the subscriptions you want covered.
  • An administrator to review consent, a technical owner, a billing contact and named change approvers.
  • Your current Microsoft licences, existing MSP/tools, important dependencies and preferred maintenance windows.
  • Your data residency, retention, security review and contractual requirements. Review the service order and data-processing arrangements before management starts.

Never include passwords, tokens or private keys in the public form.

Review our trust and service boundaries, privacy policy and terms, or ask for a service-scope review.

Questions people actually ask

Can we use this with a production tenant?

The assessment uses read-only Microsoft Graph permissions and does not change tenant settings or install device software. Your administrator should still review the consent and data scope before connecting production: directory records, logs and mailbox settings can contain personal information. Coverage and scan time depend on the tenant and available APIs.

What permissions are we actually granting?

The permission catalogue on this page lists the read-only application permissions used by platform onboarding, including directory, policy, logs, mailbox settings and licensed security/device services. Review the exact grants on Microsoft's consent screen. Buying a plan does not grant write access; managed operations require separate agreement and access.

How do we revoke access afterwards?

Your administrator can remove the assessment enterprise application in Microsoft Entra. Trial expiry alone does not revoke it. Any separate Azure delegation, managed-service app or GDAP relationship must be reviewed separately. Contact contact@mscloudsupport.net to arrange stored-data export or deletion; revoking access and deleting our stored results are separate steps.

What if we are not licensed for everything you check?

Checks that need unavailable licences or evidence are marked not assessed rather than counted as passes or failures. Available improvements and their licence requirements appear in the findings. A framework mapping helps organise the review; it is not a compliance certification.

Who needs to be involved?

A Microsoft 365 Global Administrator reviews and approves the read-only application consent. They do not need to stay signed in for background assessments. Managed onboarding also needs a technical owner, billing contact and named change approvers.

Do we have to become a paying customer?

No. Your first successful live assessment starts a 15-day trial with no card and no automatic charge. After expiry, score summaries and existing ticket history remain available, while detailed findings, repeat scans and new dashboard tickets pause. You can request paid activation or discuss a separate managed service when ready.

What do you do with our data?

We store assessment results and evidence to provide the dashboard and history. These can include personal information from directory records, sign-in logs, authentication methods and mailbox settings, including automatic-reply text. Review the permission catalogue and privacy policy, and discuss any residency or retention requirements before connecting.

Something not covered here? Ask us before you connect anything.

See your posture before someone else finds it

Read-only, revocable, and free. If you would rather have a person walk your tenant with you first, book a 30-minute call with the engineer instead and we will do it together.

Free Self-Serve M365 Security Assessment — MS Cloud Support