ScanPosture gives Microsoft-first organisations a clear, defensible view of identity, access, collaboration, audit, and device posture, with prioritised remediation and evidence that stays current.
Read-only access · No agents to install · Microsoft 365 · UK company
The Platform
See posture score, priority actions, domain strength, scan coverage, and what changed since the last completed scan.
The Problem
Most Microsoft-first businesses rely on fragmented native tooling, infrequent manual checks, and screenshots as evidence. That creates real security risk and unreliable governance.
Security configuration is spread across Entra ID, Exchange, SharePoint, Intune, and Teams admin centres. Nobody has the complete picture in one place.
When all findings look the same, nothing gets fixed in the right order. Critical gaps sit alongside low-severity observations without clear direction.
Screenshots and export files lose credibility quickly. Clients, insurers, and auditors need current, structured proof, not last quarter's artefacts.
Why ScanPosture Is Different
Most tools give you raw findings or misrepresent what your controls actually cover. ScanPosture is built around a defensible view of what your controls achieve across your Microsoft 365 tenant.
Checks are grouped into controls. The result reflects genuine control posture across your tenant, not isolated configuration observations.
Each control is assessed across presence, coverage, quality, and strength. A policy covering 30% of users scores differently to one covering 95%.
Framework readiness views show observable technical alignment. ScanPosture does not certify compliance or make claims that cannot be evidenced.
What Gets Scanned
Coverage spans identity, access, applications, collaboration, devices, logging, and drift detection across Microsoft 365 and Entra ID.
What You Get After Every Scan
Every scan produces structured outputs you can act on, share with stakeholders, and use as evidence.
A 0-100 score across 9 weighted security domains, with trend tracking over time.
A ranked view of which controls need the most attention, and what resolving them is worth to your score.
Observable readiness mapped to CE, ISO 27001, GDPR, NIST, CIS, and SOC 2. Not a certification claim.
Step-by-step instructions with exact portal navigation paths for every finding.
See exactly what changed between scans, including what improved and what deteriorated.
Executive summary and evidence outputs, ready for client or stakeholder delivery.
Posture summaries on your schedule, delivered by email, Slack, or Teams webhook.
Assign findings to responsible owners and track remediation accountability across your team.
The operating layer
ScanPosture is not just a findings viewer. It gives you the tools to manage risk, record accountability, and maintain a defensible posture record over time.
Mark findings as accepted exceptions with supporting rationale. Keep your exception record auditable and available for review.
Document where existing controls partially or fully offset identified gaps. Build a governance record that reflects operational reality, not just raw findings.
Every scan surfaces controls that degraded since the last check. Identify and respond to deterioration, not just to the overall findings count.
Recurring posture reviews on your timeline. Evidence stays current without manual extraction or scheduling effort.
Real Findings
Every finding includes severity, control mapping, framework alignment, and step-by-step remediation guidance.
8 examples from 201 checks across identity, access, email, collaboration, devices, AI permissions, and drift.
Framework Readiness
ScanPosture maps observable Microsoft 365 and Entra ID controls to framework themes. These views support readiness conversations and evidence gathering. They do not certify compliance or replace legal, audit, or certification advice.
Secure Configuration and User Access Control readiness evidence within Microsoft 365 scope.
Selected A.5 and A.8 technical control evidence across identity and access management.
Technical safeguard assessment within identity, access, and data-handling scope.
Identity, Protect, and Detect function evidence across Microsoft 365 and Entra ID controls.
Account Management, Access Control, and Audit Log Management safeguard readiness evidence.
Logical and Physical Access, Change Management, and Risk Monitoring criteria evidence.
Pricing
Priced per Entra user in the monitored tenant. Contact us for MSP and multi-tenant pricing.
per Entra user / month
Billed per licensed user in your monitored tenant, not per ScanPosture administrator. From £250/month for 100 users.
Price ranges are indicative and vary by scope and vendor.
Microsoft has useful native tooling, but posture visibility is fragmented across admin centres. ScanPosture brings control scoring, drift detection, and readiness evidence into a single operational layer, updated continuously.
For Managed Service Providers
ScanPosture helps MSPs monitor customer posture, evidence improvement, prioritise remediation, and support recurring service reviews across Microsoft-first tenants.
Review posture across all customer tenants from one interface. No separate logins, no context switching.
Produce customer-ready reports with MSP branding where enabled. Structured outputs for service delivery and stakeholder review.
See what changed across client tenants between scans. Identify what worsened and what needs attention before clients raise it.
Track actions, exceptions, and follow-up across customer estates. Evidence that work is being done and decisions are recorded.
Use posture evidence and trend history to support structured service reviews and quarterly business reviews.
Control what MSP users and customer stakeholders can see. Scoped views per client, configurable at the MSP level.
Platform Status
Control assurance is live and operational. Here is where each capability currently sits.
Live
Next
Planned
Getting Started
Read-only OAuth consent. No agents, no passwords, no complex setup. Posture results in minutes.
Read-only OAuth consent
Runs automatically
Results in minutes
Ongoing monitoring
Built By Practitioners
I built ScanPosture because I saw the same problem at every Microsoft-first business I worked with: fragmented security evidence, weak prioritisation, and no ongoing assurance. The tools that existed were either too basic or too expensive. This product fills that gap.
Andy Lawson, Founder, ScanPosture
Clear posture. Prioritised remediation. Evidence that stays current.