FAQ

Frequently asked questions

Straight answers about permissions, data, assessments and plans. Can't find what you need? Ask us.

Getting started

What is M365Assessments?

A web app that assesses the security and configuration of Microsoft 365 tenants. You connect a tenant through a guided onboarding wizard (read-only modules by default), run an assessment, and get a prioritized, plain-English report covering identity (Entra ID), devices (Intune) and licensing and usage. It's built for MSPs who assess many customer tenants and for IT teams assessing their own.

How do I sign in? Do I need to create an account?

There's no separate account or password. You sign in with Microsoft using your Microsoft Entra ID work or school account, and your first sign-in creates your workspace. Personal Microsoft accounts (such as Outlook.com) aren't supported.

How do I connect a customer's tenant?

Add the customer's domain in your workspace, choose the modules to assess (Core is always included) and generate an onboarding link. The customer's Global Administrator opens it, approves each module on Microsoft's consent screen, and signs in once more so the wizard can assign Microsoft's read-only Global Reader role where a module needs it. The tenant is then connected and ready to assess.

Do I need GDAP, delegated admin or my customer's credentials?

No. Each customer grants consent directly to our module applications. You never handle their credentials, and you don't need a GDAP relationship to run an assessment.

Is there anything to install?

No. There are no agents, PowerShell modules or scripts to run. Everything happens in the browser: even the Global Reader role is assigned by the onboarding page with the admin's own sign-in. (A PowerShell alternative is shown only if a tenant's policies block the in-browser step.)

Permissions & security

What permissions does M365Assessments need?

It depends on the modules you pick, and each module is approved separately. The Core module (always required) uses 23 read-only Microsoft Graph application permissions, such as Directory.Read.All, Policy.Read.All and DeviceManagementConfiguration.Read.All. The Exchange & Security, SharePoint & OneDrive and Teams modules add their own read-only permissions, and Exchange & Security and Teams also need Microsoft's view-only Global Reader role. Two opt-in modules, Power Platform and SharePoint Advanced, need access that isn't read-only. See the full list with the reason for each.

Can it change anything in my tenant?

Not with the standard modules. They have no write permissions or write roles, so they can't create, modify or delete users, policies, devices, apps or data. Two opt-in modules are different: SharePoint Advanced uses SharePoint Sites.FullControl.All (the only permission Microsoft accepts for the full SharePoint tenant-settings audit), and Power Platform registers our app as a Power Platform management application, which Microsoft treats like a Power Platform administrator. Both are off by default, labelled "not read-only" everywhere, need an explicit acknowledgement, and we only ever read with them.

Why does consent require a Global Administrator?

Microsoft requires an administrator to approve application permissions that apply across an organization, like reading directory and policy configuration, and to assign directory roles such as Global Reader. It's a one-time wizard of a few minutes; the admin doesn't need to stay involved afterwards.

Can a customer revoke access?

Yes, at any time and without contacting us. An administrator deletes the "M365 Assessment" enterprise applications (one per module) in the Microsoft Entra admin center, and access ends immediately. Step-by-step instructions.

How does M365Assessments authenticate to customer tenants?

With workload identity federation: our assessment engine's Azure managed identity is the only credential our module apps trust. There's no client secret or certificate at all, tokens are short-lived and never logged. (Tenants connected before modules were introduced still use our original read-only Collector app with a certificate held in Azure Key Vault until their admin re-onboards.)

What if the tenant blocks your app with Conditional Access?

If Conditional Access for workload identities (or a similar control) blocks our app from signing in, the assessment stops and tells you why. You won't get a misleading, half-empty report. Allow the app in the policy and run it again.

Are you SOC 2 or ISO 27001 certified?

Not yet. We're in early access and working toward independent third-party assessment. We're happy to complete your security questionnaire and explain our architecture in detail. Start with our security page.

Data & privacy

What data do you store?

We store three kinds of data:

  • Your workspace: organization name, team members and roles.
  • Connected tenants: tenant ID, domain, consent status and run history.
  • Assessment results: the configuration data collected and the generated report, kept in that tenant's own isolated storage container.

We don't store passwords, and we don't collect email, file, chat or document contents.

Will the report include user names?

Where it's relevant to a finding, yes. For example, a report can list the users who aren't registered for MFA or the accounts holding permanent admin roles. That's what makes findings actionable. If the tenant conceals user names in Microsoft 365 usage reports, usage data reflects that setting.

Where is data stored?

On Microsoft Azure, in data centers in the United States. Each assessed tenant's results are kept in a separate storage container, and our database uses row-level security to isolate every organization.

Can I have a tenant's data deleted?

Yes. Email hello@m365assessments.com and we'll delete the stored results and reports for that tenant. See our privacy policy for details.

Assessments & reports

What does an assessment cover today?

Identity and access in Microsoft Entra ID (Conditional Access, MFA registration and authentication methods, admin roles and PIM, risky users and sign-ins, legacy authentication, guest and external access, app registrations, enterprise apps and consent grants, domains), devices in Microsoft Intune (compliance, configuration, endpoint security, Autopilot, app protection, update rings), and licensing and usage (subscriptions, license utilization, Microsoft 365 and Copilot usage). Every run also includes tenant core data and Microsoft Secure Score.

What about Exchange, Teams, SharePoint, Defender and Purview?

Each arrives as its own module that the customer approves separately, and the security page lists exactly what each one requests. Exchange & Security (Exchange Online, Defender for Office 365, Purview), SharePoint & OneDrive and Teams are read-only modules. Power Platform is available as an opt-in module; it isn't read-only because Microsoft only offers Power Platform admin access to registered management applications, so it's off unless you choose it.

How long does an assessment take?

Minutes for small tenants. A four-user tenant takes about five minutes from start to finished report. Large tenants with thousands of users, devices and applications take longer. Runs happen in the background, so you don't need to keep the page open.

What format is the report in?

A polished report you view and share in the browser, plus a Word executive summary and a PowerPoint briefing generated with every assessment for board packs and QBRs. On MSP 50, MSP 100 and Enterprise plans all three can carry your own logo, colors, contact details and footer (white-label).

Can I schedule recurring assessments?

Yes. For each tenant, choose weekly (any weekday), monthly or quarterly (any day from the 1st to the 28th), a time and a time zone. The time stays the same local time when daylight saving changes. Each scheduled run counts toward your plan's assessments; if the allowance is used up or consent is missing, that run is skipped and shown in the portal, and the schedule continues on its next date. You can still run an assessment on demand whenever you like, and every run is kept in your run history.

Do you support GCC, GCC High, DoD or other sovereign clouds?

Not yet. M365Assessments currently supports Microsoft 365 commercial (worldwide) tenants only. US Government clouds (GCC, GCC High, DoD) and other national clouds such as Microsoft 365 operated by 21Vianet aren't supported today. Let us know if you need them.

How do I request a feature?

Sign in and open Feedback in the portal sidebar (or go straight to app.m365assessments.com/feedback). Choose Suggest a feature, or vote for an existing idea if someone has already suggested it. You can comment and follow requests to see when they move to planned, in progress and shipped. Other customers see suggestions as coming from "An MSP partner" or "An IT team", never your name or company, and our team reviews new suggestions before they appear for everyone. What's planned and recently shipped is on the public roadmap.

Plans & billing

How much does it cost?

Early-access pricing starts at $150/month for the IT Admin plan (1 tenant, 2 assessments a month). MSP plans cover 10, 50 or 100 tenants, and Enterprise plans are custom. Annual billing gets you two months free. See all plans.

What happens if I run out of assessments?

Additional assessments are available. Contact us and we'll add more to your plan, or help you move to a larger plan. Reports you've already run stay available.

Can I switch plans or cancel?

Yes. Owners and admins can upgrade, downgrade, switch between monthly and annual billing, update the payment card, download invoices or cancel, all in the portal under Settings › Billing & plan. Payments are handled securely by Stripe. After cancelling, your plan stays active until the end of the paid period and your reports remain available. Enterprise plans are managed with our team: just email us.

Still have questions?

We'd be glad to walk you through a live report and answer anything your team or your customers want to know.