Fix this week
Gaps attackers actively exploit: accounts without MFA, legacy authentication left open, standing Global Admin access, risky users nobody has reviewed.
You run a busy environment with a small team. M365Assessments gives you an objective review of identity, devices and licensing in minutes, plus a prioritized list of what to fix first.
No agents, no scripts, no service accounts. If you're a Global Administrator, you can connect your tenant yourself.
Use your work account. Your first sign-in creates your workspace.
Enter your domain, pick the modules, and approve each one's permissions on Microsoft's consent screen; the wizard then assigns the view-only Global Reader role for you. If you're not a Global Admin, send the link to someone who is.
Start the assessment. Small tenants finish in minutes; you'll get a report ranked by severity.
Simplified illustration. Microsoft shows the full list of read-only permissions when you consent.
A flat list of 200 recommendations isn't a plan. Findings are ranked by severity and explained in plain English, so you can spend your limited time where it counts.
Gaps attackers actively exploit: accounts without MFA, legacy authentication left open, standing Global Admin access, risky users nobody has reviewed.
Hardening that closes real risk but needs a change window: device compliance, app protection, guest access settings, update rings.
Hygiene and cost: stale app registrations, unassigned licenses, unused subscriptions and configuration drift.
Every assessment is saved to your run history. Re-run after a remediation sprint or each quarter, and put the reports side by side.
High + medium findings per assessment
Illustrative example.
Answer MFA, admin access and device management questions with current evidence instead of guesses.
Turn "we need more security tooling" into a ranked list of specific gaps leadership can approve.
Check licensing, usage and identity hygiene before you put AI in front of your data.
Inherited a tenant? Get a baseline on day one so you know what you're working with.
Your security team will ask. Here are the answers.
Security & permissions detailsThe standard modules request only read permissions and the view-only Global Reader role, so the assessment can't modify policies, users, devices or data. Two opt-in modules that Microsoft only offers with broader access are clearly marked and off by default.
We don't request access to mailbox contents, files, chats or documents. We read configuration.
Delete the M365 Assessment enterprise apps in Microsoft Entra whenever you want, and access ends immediately.
The IT Admin plan covers one tenant with two assessments a month. Sign in with your work account to get started.