Free discovery scan
A read-only configuration scan of one Microsoft tenant, run by you, in your tenant. We never touch it. You get an 8–12 page report and a 30-minute readout.
What it checks
The scan is built on CISA's Secure Cloud Business Applications (SCuBA) secure configuration baselines for Microsoft 365, plus additional identity-hygiene checks of our own. It reports where your tenant's configuration conforms to those baselines and where it does not.
How it runs
- We send you a signed PowerShell script and instructions.
- You run it in your own tenant. It reads configuration and writes a single output file.
- You send us the output file.
- We produce the report and schedule the readout.
No app registration is created for us, no consent is granted, and no credentials change hands. The only thing that leaves your environment is the output file, and you can read it before you send it.
What it is not
The scan reports configuration conformance gaps. It does not perform the full access reconciliation — who holds what, what changed, what drifted — across your tenants. That is the paid audit, and it is a different kind of work: collection into an identity graph, a diff against the prior cycle, and rule-based findings with evidence attached.
If the scan comes back clean, that tells you your configuration is in reasonable shape. It does not tell you who has access to what.
The scan covers one tenant. If you run several, pick the one you are least sure about.
Request the scan
We ask only what we need to qualify the request. No tenant IDs, no domain names, nothing resembling a credential.