Home Tools FAQ About Contact
Free Security Tool

M365 Security
Scanner

Connect your Microsoft 365 tenant and get a full security health report β€” MFA status, admin roles, risky sign-ins, Conditional Access, SharePoint, devices and more.

πŸ”
Connect Your M365 Tenant
Sign in with your Microsoft 365 admin account. We request read-only permissions β€” we never modify anything in your tenant.
Read-OnlyUsers & MFA Admin RolesSign-in Logs Conditional AccessSecure Score SharePointDevices
πŸ”’ You will be redirected to Microsoft to sign in Β· Read-only access Β· No data stored on our servers
Connected

⚠️ Scan Error

Something went wrong.

Running security scan…
Security Report

Issues Found? Happy to Help.

I have 25+ years of experience in Microsoft 365 and cloud technologies β€” MFA, Conditional Access, Exchange migrations, Entra ID and more. Feel free to get in touch if you'd like to discuss anything.

πŸ’¬  WhatsApp Me
About This Tool

Why Run a Microsoft 365 Security Health Check?

Most Microsoft 365 tenants accumulate security gaps over time β€” accounts created without MFA, Conditional Access policies with unintended exclusions, legacy authentication protocols left enabled, mailbox forwarding rules pointing externally, or admin roles assigned more broadly than necessary. Individually these might seem minor, but together they represent the most common entry points used in real-world account takeover and business email compromise attacks.

This scanner connects to your tenant using Microsoft's official sign-in (the same OAuth flow used by Microsoft's own admin tools) and requests read-only permissions β€” it cannot make any changes to your configuration. Once connected, it checks your users and MFA registration status, admin role assignments, sign-in risk detections, Conditional Access policies (including a full best-practice findings analysis), SharePoint sharing settings, Intune-managed devices, and mailbox forwarding rules β€” then summarises everything into a single report with clear pass/fail indicators.

The Conditional Access section goes further than a simple policy list β€” every policy is analysed against common best practices (such as break-glass account exclusions, legacy authentication blocking, and MFA enforcement coverage) and flagged by severity, with a plain English explanation of what each policy actually does. Both a full security report and a dedicated Conditional Access report can be exported as PDF documents for record-keeping or sharing with stakeholders.

Coverage

What Gets Checked

πŸ‘€

Users & MFA

Total users, licensing, and how many have multi-factor authentication registered.

πŸ›‘οΈ

Admin Roles

Who holds privileged roles like Global Administrator, and whether the count looks excessive.

⚠️

Risky Sign-ins

Recent sign-in risk detections from Microsoft Entra ID Protection, if available on your licence.

πŸ”’

Conditional Access

Every policy explained in plain English, plus best-practice findings with severity ratings.

πŸ“

SharePoint Sharing

Tenant-wide external sharing settings that could expose data to unintended recipients.

πŸ’»

Managed Devices

Intune-enrolled devices and their compliance status.

πŸ“§

Mail Forwarding

Mailboxes with external forwarding rules configured β€” a common data exfiltration technique.

πŸ“Š

Secure Score

Your tenant's Microsoft Secure Score, giving a benchmark against Microsoft's own recommendations.

Policy Name