Guide  ·  About five minutes to read

How to run your security check

Everything you'll see, step by step: who should sign in, what Microsoft will ask you to approve, and how to save your report. No software to install.

Before you start

Who

A Global Administrator of your Microsoft 365, the first time only. After that, anyone with the Global Reader role can run it again.

Device

A computer with a current browser: Edge, Chrome, Safari or Firefox. A phone works, but saving the PDF is easier on a computer.

Pop-ups

Microsoft's sign-in opens in a small pop-up window. If your browser blocks it, allow pop-ups for this site.

Time

About two minutes: one to sign in and approve, one for the scan.

01

Start the check

Open the security check page and click Sign in with Microsoft & scan. A Microsoft sign-in window opens on top of the page.

Want to see what you'll get first? Click See a sample report. It uses a made-up company and needs no sign-in.

02

Sign in with your work account

Use your normal Microsoft 365 work account, the one you'd use for Outlook or Teams. Complete MFA as usual. Personal Microsoft accounts (Outlook.com, Hotmail) won't work.

The sign-in happens on Microsoft's own page (the address starts with login.microsoftonline.com). Your password never touches this site.

03

Approve read-only access

The first time, Microsoft asks you to approve the app. Check that the app name is Security Scan, review the list, tick Consent on behalf of your organization and click Accept.

Don't see the checkbox? Your account isn't a Global Administrator. See If you're not an admin.

04

Wait for the scan

The pop-up closes and a checklist of about 20 items ticks off, usually in under a minute. Leave the tab open until it finishes.

  • Green: read successfully.
  • Amber, "no access": that area needs a licence you don't have, or a role your account doesn't hold. The scan carries on and the report says what was skipped.
05

Read and save your report

The report appears on screen. To keep a copy:

  1. Decide whether to keep Include names on. It adds an appendix listing the people and devices behind each finding. Turn it off if you'll share the report widely.
  2. Click Download PDF.
  3. In the print window, set Destination to Save as PDF (on a Mac: PDF → Save as PDF), then click Save.

The report isn't stored anywhere unless you share it. If you close or reload the tab before saving, you'll need to run the scan again. That's quick, and it won't ask for approval a second time.

Want us to review it? Click Send to , add your contact details and tick the consent box. You choose whether staff and device names are included; untick it to send counts only. Shared reports are encrypted and deleted after 12 months, or sooner on request.

06

Remove access (optional)

The app can't do anything unless an administrator is signed in, but you can remove it whenever you like:

  1. Go to entra.microsoft.com and sign in as an administrator.
  2. Open Identity → Applications → Enterprise applications.
  3. Search for Security Scan and open it.
  4. Click Properties → Delete, then confirm.

If you want to run the check again later, you'll simply be asked to approve it again.

If you're not an admin

If you see "Need admin approval", your account can't approve apps for the organisation. Send your Global Administrator this approval link. They open it, review the same read-only list, and click Accept:

After they approve, you can run the scan yourself if you have the Global Reader role. After approving, your admin may land on a blank or "can't connect" page. That's normal: the approval is already saved.

Troubleshooting

"Need admin approval"

The app hasn't been approved in your organisation yet. Send the approval link above to a Global Administrator.

Nothing happens when I click sign in

The pop-up was blocked. Look for a blocked-pop-up icon in the address bar, allow pop-ups for this site, and try again.

"The sign-in window was closed"

The pop-up was closed before sign-in finished. Click the button again.

"You can't access this application" or "AADSTS" errors

Your organisation may block third-party apps or require approval workflows. Ask your Global Administrator to use the approval link, or send us the error code.

Some sections say "couldn't be read"

Usually a missing licence (for example Intune or Entra ID P2), or an account without the Global Reader role. Everything else in the report is still accurate. The last page lists what was skipped.

The PDF has no colours or backgrounds

In the print window, open More settings and turn on Background graphics.

I reloaded the page and the report is gone

That's by design: nothing is stored. Run the scan again; it takes about a minute.

Permissions, in plain English

All permissions are read-only and delegated: the app acts as the signed-in person, only while they're signed in. There is no background access, no password or secret stored, and nothing can be changed.

Microsoft's nameWhat we use it for
Read directory dataCounting users, guests, admins, domains, licences and devices
Read your organization's policiesChecking Conditional Access, MFA settings and user permissions
Read audit log dataSeeing who has registered MFA and when accounts last signed in
Read your organization's security eventsYour Microsoft Secure Score and its recommendations
Read all identity risky user informationAccounts Microsoft has flagged as possibly compromised
Read directory RBAC settingsWho holds admin roles
Read Microsoft Intune devicesDevice encryption, compliance and last check-in
Read Microsoft Intune device configuration and policiesWhether device compliance policies exist
Read SharePoint and OneDrive tenant settingsHow widely files can be shared
Sign you in and read your profileSigning you in, and naming who ran the scan in the report

It never reads email, files, chats, calendars or contacts. Email security records (SPF, DKIM, DMARC) are checked with public DNS lookups, the same information anyone on the internet can see.

Questions

Can this change anything in our Microsoft 365?

No. Every permission is read-only, and Microsoft enforces that, not us.

Where does our data go?

From Microsoft straight to your browser tab. The scan itself never sends your data to us. Only if you click Send to and tick the consent box is the finished report sent, encrypted, and kept for up to 12 months so we can follow up. Otherwise the only copy is the PDF you choose to save.

Does it work with any Microsoft 365 plan?

Yes. Business Premium, E3 and E5 give the fullest report. On smaller plans, sections that need a licence you don't have are marked as skipped.

Can we run it again later?

Yes, as often as you like. After the first approval, a Global Reader can run it without asking an admin again.

Is this a penetration test?

No. It's a configuration review of your Microsoft 365 settings. It doesn't test your network, on-premises systems, backups, or how staff respond to phishing.

Ready when you are.

Start the check