Connect your Microsoft 365 tenant and get a full security health report β MFA status, admin roles, risky sign-ins, Conditional Access, SharePoint, devices and more.
Something went wrong.
I have 25+ years of experience in Microsoft 365 and cloud technologies β MFA, Conditional Access, Exchange migrations, Entra ID and more. Feel free to get in touch if you'd like to discuss anything.
π¬ WhatsApp MeMost Microsoft 365 tenants accumulate security gaps over time β accounts created without MFA, Conditional Access policies with unintended exclusions, legacy authentication protocols left enabled, mailbox forwarding rules pointing externally, or admin roles assigned more broadly than necessary. Individually these might seem minor, but together they represent the most common entry points used in real-world account takeover and business email compromise attacks.
This scanner connects to your tenant using Microsoft's official sign-in (the same OAuth flow used by Microsoft's own admin tools) and requests read-only permissions β it cannot make any changes to your configuration. Once connected, it checks your users and MFA registration status, admin role assignments, sign-in risk detections, Conditional Access policies (including a full best-practice findings analysis), SharePoint sharing settings, Intune-managed devices, and mailbox forwarding rules β then summarises everything into a single report with clear pass/fail indicators.
The Conditional Access section goes further than a simple policy list β every policy is analysed against common best practices (such as break-glass account exclusions, legacy authentication blocking, and MFA enforcement coverage) and flagged by severity, with a plain English explanation of what each policy actually does. Both a full security report and a dedicated Conditional Access report can be exported as PDF documents for record-keeping or sharing with stakeholders.
Total users, licensing, and how many have multi-factor authentication registered.
Who holds privileged roles like Global Administrator, and whether the count looks excessive.
Recent sign-in risk detections from Microsoft Entra ID Protection, if available on your licence.
Every policy explained in plain English, plus best-practice findings with severity ratings.
Tenant-wide external sharing settings that could expose data to unintended recipients.
Intune-enrolled devices and their compliance status.
Mailboxes with external forwarding rules configured β a common data exfiltration technique.
Your tenant's Microsoft Secure Score, giving a benchmark against Microsoft's own recommendations.