Days of clicking through portals
Entra admin center, Intune, the Microsoft 365 admin center, PowerShell exports, screenshots into a slide deck. It's the same checklist every time, done by hand.
Early access Entra, Intune, Exchange, SharePoint, Teams & more are live
M365Assessments connects to a tenant through a guided onboarding wizard with read-only modules, checks identity, device and licensing configuration against best practice, and turns it into a prioritized, plain-English report. It's ready for the QBR, the onboarding, or the board.
contosodental.com · Last run Sep 18, 2026
Everyone agrees a tenant review is valuable. Almost nobody has the hours to do one properly, consistently, for every customer.
Entra admin center, Intune, the Microsoft 365 admin center, PowerShell exports, screenshots into a slide deck. It's the same checklist every time, done by hand.
What gets checked depends on who ran it and how busy the week was. Next quarter there's nothing reliable to compare against, and nobody can prove things improved.
Raw findings don't sell a Conditional Access project or justify a budget. Customers skim a wall of data, nod, and nothing changes.
No agents to install, no scripts to run, no credentials to collect.
Enter the customer's primary domain. We look up the Microsoft 365 tenant behind it.
Send the onboarding link. Their Global Admin approves each module on Microsoft's own consent screen, and the wizard assigns the view-only Global Reader role where needed.
Press Run. We collect configuration through Microsoft Graph and analyze it against best practice.
Prioritized findings, explained in plain English, each with a recommended fix. Ready to present.
Every assessment includes your tenant's core profile and Microsoft Secure Score, plus in-depth identity, device and licensing checks. Add modules for email, collaboration and compliance.
Microsoft Entra ID, where attackers start.
Microsoft Intune, whether endpoints are actually managed.
Where the money goes, and whether it's used.
Plus tenant core in every run: organization profile, Secure Score and subscriptions.
Power Platform is available as an opt-in module (environments, DLP, apps, flows and connectors). It isn't read-only: Microsoft only offers Power Platform admin access to registered management applications. What it requests.
Put every customer in one portfolio, run the same assessment for each, and walk into every QBR with a report that starts the conversation about the next project.
42 tenants · MSP 50 plan
| Customer | Consent | Findings |
|---|---|---|
| Contoso Dental Groupcontosodental.com | Granted | 3712 |
| Fabrikam Manufacturingfabrikam.com | Running | In progress |
| Northwind Legalnorthwindlegal.com | Granted | 149 |
| Tailspin Logisticstailspin.co | Awaiting | Consent link sent |
| Woodgrove Credit Unionwoodgrovecu.org | Granted | 026 |
Illustrative example with fictitious customers.
You know your environment better than anyone. You don't have a spare week to audit it. Get an objective, repeatable review and a prioritized to-do list.
High + medium findings per assessment
Illustrative example.
Every finding says what we saw, why it matters in business terms, and what to do about it. Technical detail is there when your engineers need it. The summary works for the business owner.
fabrikam.com · 212 users · Prepared by your IT partner
Including 2 users in the Finance group. A single phished password is enough to get into these accounts.
Users can grant apps access to their mailbox and files without an admin reviewing the request.
Most are missing BitLocker or haven't checked in for more than 30 days.
Illustrative sample with a fictitious company. Real reports reflect your tenant's configuration.
An assessment tool that needs write access to your customers' tenants is a liability. Our standard modules can look but never touch, and we list every permission each module uses.
Read our security approachEach area is a separate app the customer approves. The Core module uses 23 Graph permissions, every one .Read; read-only modules never get ReadWrite access. Two opt-in modules that Microsoft only offers with broader access are clearly marked and off by default.
Our engine authenticates with workload identity federation: its Azure managed identity is the only credential our apps trust.
Each tenant's results live in their own storage container. Database row-level security separates every organization.
Customers can remove our enterprise apps in Microsoft Entra at any time. Access ends immediately.
Priced per plan, not per seat. Early-access pricing, available now.
Not with the standard modules: their permissions are read-only, so they can read configuration but can't create, change or delete anything. The two opt-in modules (Power Platform and SharePoint Advanced) need access Microsoft doesn't offer as read-only; they're off by default and we only ever read with them. The full list is on our security page.
A Global Administrator in that tenant approves the consent request once, on Microsoft's own consent screen. You never need their credentials, and they can revoke access at any time by removing our enterprise app in Microsoft Entra.
Minutes for small tenants. A four-user tenant takes about five minutes end to end. Larger tenants with thousands of users, devices and apps take longer, and you can close the browser while it runs.
Yes. Sign-in uses Microsoft Entra ID (a work or school account). Your first sign-in creates your workspace. Personal Microsoft accounts aren't supported.
Sign in with your Microsoft work account to create a workspace, then connect a tenant with the guided onboarding wizard.
Requires a Microsoft Entra ID (work or school) account.