ScanPosture gives Microsoft-first SMBs a clearer, more defensible view of control posture, priority gaps, and what changed since the last scan.
The Problem
Most SMBs rely heavily on Microsoft 365, but the security configuration is fragmented, manually reviewed, and poorly evidenced. That creates real risk.
Security settings are scattered across multiple admin centres. Nobody has the full picture in one place.
When everything is a finding, nothing is a priority. Teams waste time on low-impact issues while critical gaps remain.
Screenshots and spreadsheets are weak evidence. Clients, insurers, and auditors want current, structured proof.
Why ScanPosture Is Different
Most tools give you raw findings or overstate compliance. ScanPosture is designed to give you a defensible view of what your controls actually look like.
Findings are grouped into controls. The result reflects real control posture across your tenant, not isolated technical checks.
Every control is scored across presence, coverage, quality, and strength. A setting that exists but covers 30% of users doesn't score the same as one covering 95%.
Framework support language is bounded and defensible. We say what we can evidence. We never overclaim compliance.
What Gets Scanned
Structured around the controls that matter most across identity, access, applications, collaboration, logging, and device posture.
What You Get After Every Scan
Every scan gives you a structured view of posture, what matters most, and what changed since the last scan.
0–100 score across 9 weighted domains with trend tracking
Know which controls are weakest and what to fix first
CE, ISO 27001, GDPR, NIST support levels with approved language
Detailed remediation with exact portal navigation paths
See what changed between scans — roles, policies, permissions
Executive summary and compliance readiness, client-ready
Daily, weekly, monthly summaries via email, Slack, Teams
See where existing controls mitigate gaps elsewhere
Real Findings
These are 8 examples from 133 checks. A full scan covers identity, access, email, collaboration, devices, AI risk, drift, and more — every finding includes severity, compliance mapping, and step-by-step remediation.
Compliance Readiness
ScanPosture maps observable controls to framework requirements and tells you how strongly the evidence supports alignment. We never say “compliant” — we show what we can defend.
Secure Configuration and User Access Control evidence within M365 scope
Selected A.5 and A.8 technical control evidence
Technical safeguard assessment within identity and access scope
Protect and Detect function evidence
Pricing
per user / month · from £250/month for 100 users
Free during beta · No credit card required
Continuous assurance, not a one-off check. Evidence that stays current. Priority actions that stay relevant. That is what justifies a subscription, not a snapshot.
How It Works
Read-only OAuth consent. No agents, no passwords, no complex setup.
133 checks execute automatically against your Entra ID and M365 configuration.
Posture score, domain breakdown, priority controls, and framework evidence — all in minutes.
Recurring scans detect drift, refresh evidence, and track improvement over time.
Why This Isn’t a One-Off Assessment
Users change, guest access expands, new apps appear, roles drift, and evidence quickly becomes stale. ScanPosture is built to help you maintain control assurance over time, not just identify issues once.
Roles, policies, apps, and permissions change constantly. Even well-run tenants drift between scans.
Old reports and screenshots quickly lose value. Clients and insurers want to know what posture looks like now, not three months ago.
New users join. Apps gain permissions. AI agents are provisioned. Service principals accumulate scope. Risk is dynamic.
Clients, insurers, and auditors care about current posture. Recurring scans keep evidence fresh and priorities accurate.
For Managed Service Providers
MSPs are expected to do more than manage licences. Customers want evidence that their environment is being monitored and improved. ScanPosture makes that scalable.
Manage all customer tenants from a single MSP dashboard with role-based access control.
Generate posture reports for every client on a schedule. Show improvement over time.
One invoice for all clients. Auto-adjusting quantities as client user counts change.
Identify changes in customer environments before clients do. Proactive, not reactive.
Brand reports with your logo and colours. Option to remove ScanPosture branding entirely.
See where clients need licence upgrades or hardening work. Built-in commercial opportunity.
Already managing Microsoft 365 environments for clients? Let’s talk.
Platform Status
Live today
Coming next
Longer-term
What Happens After You Join
From connection to posture in under five minutes. No agents, no passwords, no complex setup.
Read-only OAuth consent
Runs automatically
Posture in minutes
Ongoing monitoring
Built By Practitioners
I built ScanPosture because I saw the same problem at every Microsoft-first business I worked with: fragmented security evidence, weak prioritisation, and no ongoing assurance. The tools that existed were either too basic or too expensive. This product fills that gap.
Andy Lawson
Founder, Lawsons Enterprises Ltd
Start your free beta
Clear posture. Priority gaps. Fresh evidence. Updated with every scan.
Free during beta · No credit card required · Read-only access