Before you start
A Global Administrator of your Microsoft 365, the first time only. After that, anyone with the Global Reader role can run it again.
A computer with a current browser: Edge, Chrome, Safari or Firefox. A phone works, but saving the PDF is easier on a computer.
Microsoft's sign-in opens in a small pop-up window. If your browser blocks it, allow pop-ups for this site.
About two minutes: one to sign in and approve, one for the scan.
Start the check
Open the security check page and click Sign in with Microsoft & scan. A Microsoft sign-in window opens on top of the page.
Want to see what you'll get first? Click See a sample report. It uses a made-up company and needs no sign-in.
Sign in with your work account
Use your normal Microsoft 365 work account, the one you'd use for Outlook or Teams. Complete MFA as usual. Personal Microsoft accounts (Outlook.com, Hotmail) won't work.
The sign-in happens on Microsoft's own page (the address starts with login.microsoftonline.com). Your password never touches this site.
Approve read-only access
The first time, Microsoft asks you to approve the app. Check that the app name is Security Scan, review the list, tick Consent on behalf of your organization and click Accept.
Permissions requested
Security Scan
unverified until publisher verification is complete
This app would like to:
- Read directory data
- Read your organization's policies
- Read audit log data
- Read your organization's security events
- Read all identity risky user information
- Read directory RBAC settings
- Read Microsoft Intune devices
- Read Microsoft Intune device configuration and policies
- Read SharePoint and OneDrive tenant settings
- Sign you in and read your profile
Don't see the checkbox? Your account isn't a Global Administrator. See If you're not an admin.
Wait for the scan
The pop-up closes and a checklist of about 20 items ticks off, usually in under a minute. Leave the tab open until it finishes.
- Green: read successfully.
- Amber, "no access": that area needs a licence you don't have, or a role your account doesn't hold. The scan carries on and the report says what was skipped.
Read and save your report
The report appears on screen. To keep a copy:
- Decide whether to keep Include names on. It adds an appendix listing the people and devices behind each finding. Turn it off if you'll share the report widely.
- Click Download PDF.
- In the print window, set Destination to Save as PDF (on a Mac: PDF → Save as PDF), then click Save.
The report isn't stored anywhere unless you share it. If you close or reload the tab before saving, you'll need to run the scan again. That's quick, and it won't ask for approval a second time.
Want us to review it? Click Send to , add your contact details and tick the consent box. You choose whether staff and device names are included; untick it to send counts only. Shared reports are encrypted and deleted after 12 months, or sooner on request.
Remove access (optional)
The app can't do anything unless an administrator is signed in, but you can remove it whenever you like:
- Go to entra.microsoft.com and sign in as an administrator.
- Open Identity → Applications → Enterprise applications.
- Search for Security Scan and open it.
- Click Properties → Delete, then confirm.
If you want to run the check again later, you'll simply be asked to approve it again.
If you're not an admin
If you see "Need admin approval", your account can't approve apps for the organisation. Send your Global Administrator this approval link. They open it, review the same read-only list, and click Accept:
After they approve, you can run the scan yourself if you have the Global Reader role. After approving, your admin may land on a blank or "can't connect" page. That's normal: the approval is already saved.
Troubleshooting
"Need admin approval"
The app hasn't been approved in your organisation yet. Send the approval link above to a Global Administrator.
Nothing happens when I click sign in
The pop-up was blocked. Look for a blocked-pop-up icon in the address bar, allow pop-ups for this site, and try again.
"The sign-in window was closed"
The pop-up was closed before sign-in finished. Click the button again.
"You can't access this application" or "AADSTS" errors
Your organisation may block third-party apps or require approval workflows. Ask your Global Administrator to use the approval link, or send us the error code.
Some sections say "couldn't be read"
Usually a missing licence (for example Intune or Entra ID P2), or an account without the Global Reader role. Everything else in the report is still accurate. The last page lists what was skipped.
The PDF has no colours or backgrounds
In the print window, open More settings and turn on Background graphics.
I reloaded the page and the report is gone
That's by design: nothing is stored. Run the scan again; it takes about a minute.
Permissions, in plain English
All permissions are read-only and delegated: the app acts as the signed-in person, only while they're signed in. There is no background access, no password or secret stored, and nothing can be changed.
| Microsoft's name | What we use it for |
|---|---|
| Read directory data | Counting users, guests, admins, domains, licences and devices |
| Read your organization's policies | Checking Conditional Access, MFA settings and user permissions |
| Read audit log data | Seeing who has registered MFA and when accounts last signed in |
| Read your organization's security events | Your Microsoft Secure Score and its recommendations |
| Read all identity risky user information | Accounts Microsoft has flagged as possibly compromised |
| Read directory RBAC settings | Who holds admin roles |
| Read Microsoft Intune devices | Device encryption, compliance and last check-in |
| Read Microsoft Intune device configuration and policies | Whether device compliance policies exist |
| Read SharePoint and OneDrive tenant settings | How widely files can be shared |
| Sign you in and read your profile | Signing you in, and naming who ran the scan in the report |
It never reads email, files, chats, calendars or contacts. Email security records (SPF, DKIM, DMARC) are checked with public DNS lookups, the same information anyone on the internet can see.
Questions
Can this change anything in our Microsoft 365?
No. Every permission is read-only, and Microsoft enforces that, not us.
Where does our data go?
From Microsoft straight to your browser tab. The scan itself never sends your data to us. Only if you click Send to and tick the consent box is the finished report sent, encrypted, and kept for up to 12 months so we can follow up. Otherwise the only copy is the PDF you choose to save.
Does it work with any Microsoft 365 plan?
Yes. Business Premium, E3 and E5 give the fullest report. On smaller plans, sections that need a licence you don't have are marked as skipped.
Can we run it again later?
Yes, as often as you like. After the first approval, a Global Reader can run it without asking an admin again.
Is this a penetration test?
No. It's a configuration review of your Microsoft 365 settings. It doesn't test your network, on-premises systems, backups, or how staff respond to phishing.