Free · Read-only · About two minutes
How exposed is your Microsoft 365?
Sign in with Microsoft and get a boardroom-ready security report: MFA gaps, admin sprawl, risky users, unencrypted laptops and email spoofing, in plain English.
js/config.js (see docs/SETUP.md). You can still preview a sample report.
Read-only
The app can only read settings, and only while an admin is signed in. It never touches email, files or chats.
Runs in your browser
Your tenant's data travels from Microsoft straight to this page, and disappears when you close it.
Your report, yours
Download it as a PDF. Nothing is sent to us unless you choose to share it.
Who should sign in?
The first time, a Global Administrator signs in and ticks Consent on behalf of your organization. After that, a Global Reader can run the scan. Other accounts will see a "needs admin approval" message.
Exactly what this reads
- Users, groups, domains, licenses and admin roles
- MFA registration status and last sign-in dates
- Conditional Access, security defaults and tenant user settings
- Microsoft Secure Score and its recommended actions
- Risky users flagged by Microsoft Entra ID Protection
- Intune device compliance, encryption and last check-in
- SharePoint and OneDrive sharing settings
It never reads email, files, chats or calendars. Full permission list →