Early access Entra, Intune, Exchange, SharePoint, Teams & more are live

Assess any Microsoft 365 tenant in minutes. Hand over a report people actually read.

M365Assessments connects to a tenant through a guided onboarding wizard with read-only modules, checks identity, device and licensing configuration against best practice, and turns it into a prioritized, plain-English report. It's ready for the QBR, the onboarding, or the board.

  • Read-only by default
  • Per-tenant isolation
  • Built on Microsoft Azure
  • Read-only by defaultRead-only modules. Write-capable access only in two clearly marked opt-in modules.
  • Per-tenant isolationSeparate storage per tenant, row-level security in the database
  • No secrets or certificatesWorkload identity federation with short-lived tokens
  • Built on Microsoft AzureHosted in US Azure regions
Why assessments stall

Manual Microsoft 365 assessments cost too much to do well, so they rarely get done.

Everyone agrees a tenant review is valuable. Almost nobody has the hours to do one properly, consistently, for every customer.

Days of clicking through portals

Entra admin center, Intune, the Microsoft 365 admin center, PowerShell exports, screenshots into a slide deck. It's the same checklist every time, done by hand.

Different every time

What gets checked depends on who ran it and how busy the week was. Next quarter there's nothing reliable to compare against, and nobody can prove things improved.

Hard to turn into work

Raw findings don't sell a Conditional Access project or justify a budget. Customers skim a wall of data, nod, and nothing changes.

The manual way

  • An engineer's day (or three) per tenant
  • Checks vary by who's doing them
  • Global Admin credentials passed around
  • A spreadsheet the customer never opens

With M365Assessments

  • Minutes of runtime, no engineer babysitting
  • The same checks, every tenant, every time
  • A guided consent wizard. No shared passwords
  • A prioritized, plain-English report
How it works

From "add a customer" to a finished report in four steps

No agents to install, no scripts to run, no credentials to collect.

  1. Add a customer tenant

    Enter the customer's primary domain. We look up the Microsoft 365 tenant behind it.

    About 30 seconds
  2. Customer approves the modules

    Send the onboarding link. Their Global Admin approves each module on Microsoft's own consent screen, and the wizard assigns the view-only Global Reader role where needed.

    One click for them
  3. Run the assessment

    Press Run. We collect configuration through Microsoft Graph and analyze it against best practice.

    Minutes for small tenants
  4. Share a clear report

    Prioritized findings, explained in plain English, each with a recommended fix. Ready to present.

    Keep every run on file

See the full walkthrough

What we assess

Deep coverage across Microsoft 365, starting where most breaches start

Every assessment includes your tenant's core profile and Microsoft Secure Score, plus in-depth identity, device and licensing checks. Add modules for email, collaboration and compliance.

Live

Identity & access

Microsoft Entra ID, where attackers start.

  • Conditional Access policies
  • MFA registration & authentication methods
  • Admin roles & Privileged Identity Management
  • Risky users & risky sign-ins
  • Legacy authentication
  • Guest & external access
  • App registrations, enterprise apps & consent grants
  • Domains
Live

Devices

Microsoft Intune, whether endpoints are actually managed.

  • Compliance policies
  • Configuration profiles
  • Endpoint security
  • Windows Autopilot
  • App protection policies
  • Windows Update rings
Live

Licensing & usage

Where the money goes, and whether it's used.

  • Subscriptions & SKUs
  • License utilization & unassigned seats
  • Microsoft 365 usage & adoption
  • Microsoft 365 Copilot usage

Plus tenant core in every run: organization profile, Secure Score and subscriptions.

Add-on modules

Exchange Online Microsoft Teams SharePoint & OneDrive Microsoft Defender Microsoft Purview

Power Platform is available as an opt-in module (environments, DLP, apps, flows and connectors). It isn't read-only: Microsoft only offers Power Platform admin access to registered management applications. What it requests.

For MSPs

One login. Every customer tenant. A repeatable service you can sell.

Put every customer in one portfolio, run the same assessment for each, and walk into every QBR with a report that starts the conversation about the next project.

  • Per-customer consent: each customer approves their own tenant, and can revoke it
  • Plans sized for 10, 50 or 100 tenants, with monthly assessment quotas
  • Team roles for owners, admins, technicians and read-only viewers
  • Findings you can scope and quote as remediation projects
Explore MSP features

Illustrative example with fictitious customers.

For in-house IT teams

Your own tenant, assessed honestly, with a clear list of what to fix first.

You know your environment better than anyone. You don't have a spare week to audit it. Get an objective, repeatable review and a prioritized to-do list.

  • Grant consent to your own tenant in a couple of minutes
  • Findings ranked by severity so the riskiest gaps come first
  • Run again after changes and keep every report in your run history
  • Evidence you can hand to leadership, auditors or your cyber insurer
See how IT teams use it

Illustrative example.

Inside the report

Findings written for the person who has to approve the fix

Every finding says what we saw, why it matters in business terms, and what to do about it. Technical detail is there when your engineers need it. The summary works for the business owner.

  • Severity-ranked so the riskiest items come first
  • Grouped by area: identity, devices, licensing
  • Specific counts and objects, not generic advice
  • A recommended fix for every finding
What's in every report

Illustrative sample with a fictitious company. Real reports reflect your tenant's configuration.

Security & trust

We ask for the least access we can, and we're specific about it

An assessment tool that needs write access to your customers' tenants is a liability. Our standard modules can look but never touch, and we list every permission each module uses.

Read our security approach

Read-only modules, approved one by one

Each area is a separate app the customer approves. The Core module uses 23 Graph permissions, every one .Read; read-only modules never get ReadWrite access. Two opt-in modules that Microsoft only offers with broader access are clearly marked and off by default.

No secrets, no certificates

Our engine authenticates with workload identity federation: its Azure managed identity is the only credential our apps trust.

Isolated per tenant

Each tenant's results live in their own storage container. Database row-level security separates every organization.

Revocable in one click

Customers can remove our enterprise apps in Microsoft Entra at any time. Access ends immediately.

Pricing

Simple plans that grow with your customer list

Priced per plan, not per seat. Early-access pricing, available now.

IT Admin

For an internal IT team assessing its own tenant.

$79/mo

1 tenant · 2 assessments a month

See details
Most popular

MSP 50

For growing MSPs running assessments across the book.

$1,199/mo

50 tenants · 100 assessments a month

Get started

MSP 100

For established MSPs with a large customer base.

$1,999/mo

100 tenants · 200 assessments a month

See details

Compare all plans, including MSP 10 and Enterprise

Questions

The questions customers ask first

Can M365Assessments change anything in a tenant?

Not with the standard modules: their permissions are read-only, so they can read configuration but can't create, change or delete anything. The two opt-in modules (Power Platform and SharePoint Advanced) need access Microsoft doesn't offer as read-only; they're off by default and we only ever read with them. The full list is on our security page.

Who has to approve access to a customer's tenant?

A Global Administrator in that tenant approves the consent request once, on Microsoft's own consent screen. You never need their credentials, and they can revoke access at any time by removing our enterprise app in Microsoft Entra.

How long does an assessment take?

Minutes for small tenants. A four-user tenant takes about five minutes end to end. Larger tenants with thousands of users, devices and apps take longer, and you can close the browser while it runs.

Do I need a Microsoft work account to sign in?

Yes. Sign-in uses Microsoft Entra ID (a work or school account). Your first sign-in creates your workspace. Personal Microsoft accounts aren't supported.

Read all FAQs

Run your first Microsoft 365 assessment today

Sign in with your Microsoft work account to create a workspace, then connect a tenant with the guided onboarding wizard.

Requires a Microsoft Entra ID (work or school) account.