Now in beta · Identity Security for UK SMBs

Know exactly who can access what —
and fix it before it costs you

ScanPosture continuously scans your Microsoft 365 environment for identity security misconfigurations. No security team needed. Results in minutes.

Read-only scanning103+ security checksResults in under 5 minutes
app.scanposture.com

Security Score

72/ 100
B+↑ 8 pts

Findings by Severity

2
Critical
5
High
7
Medium
3
Low

17 findings across your tenant

Compliance

Cyber Ess.85%
GDPR78%
ISO 2700172%
NIST68%
Recent FindingsView all →
CRITICALGlobal Admin without MFA
HIGHLegacy auth protocols enabled
HIGHConditional Access gaps
MEDIUMExcessive OAuth app permissions
MEDIUMGuest account sprawl

The Problem

Most UK SMBs don’t know their Microsoft 365 is misconfigured

Your insurer wants proof

Cyber insurers are tightening requirements. If you can't evidence MFA enforcement and access controls, your claim could be voided — even if you're paying the premium.

Your clients are asking questions

Enterprise clients and public sector contracts increasingly require Cyber Essentials certification. Without visibility into your identity posture, you can't answer their security questionnaires.

You have no visibility

Most SMBs have no idea who has admin access, which accounts lack MFA, or what OAuth apps have been granted permissions. You can't fix what you can't see.

What We Scan

103+ checks across your Microsoft 365 environment

Azure AD

Identity & Access

MFA gaps, privileged role sprawl, inactive admin accounts, PIM configuration, conditional access policy gaps.

Azure AD

Account Hygiene

Stale accounts, dormant users, guest access without review, legacy authentication, self-service password reset gaps.

Azure AD

App Permissions

OAuth apps with excessive permissions, service principals with owner-level access, AI agent OAuth grants, managed identity risks.

M365

Microsoft 365 Apps

SharePoint anonymous links, Exchange mail forwarding rules, Teams external access, DMARC and DKIM configuration.

All checks

Drift Detection

Compares every scan against the last. Flags new Global Admins, removed MFA registrations, changed conditional access policies.

Compliance

Compliance Mapping

Every finding mapped to Cyber Essentials, ISO 27001, UK GDPR, and cyber insurance requirements. Evidence pack on demand.

Platform Coverage

Built for where your identities live

ScanPosture starts with Microsoft 365 and Azure AD — the identity layer for most UK SMBs. More platforms coming as we grow.

Live

Microsoft Azure / Entra IDLive
Microsoft 365Live

Coming Soon

AWS IAMSoon
Google WorkspaceSoon
OktaSoon

Roadmap

SlackPlanned
AtlassianPlanned
SalesforcePlanned
GitHubPlanned
Active DirectoryPlanned

Security Checks

What ScanPosture Finds

103+ security checks across authentication, access control, apps, and compliance. Every finding includes severity, compliance mapping, and fix instructions.

CRITICALGlobal admin accounts without MFA

3 of your 5 Global Administrator accounts have no MFA registered. A compromised admin account gives an attacker full control of your Microsoft 365 environment.

CRITICALExternal mail forwarding rules active

2 mailboxes have active forwarding rules sending copies of all email to external addresses. This is a common indicator of account compromise.

HIGHLegacy authentication not blocked

Legacy authentication protocols are enabled, allowing sign-ins that bypass MFA. This is how most Microsoft 365 accounts are compromised.

HIGHSharePoint anonymous links enabled

Your SharePoint tenant allows 'Anyone' links — files shared this way are accessible to anyone on the internet without authentication.

HIGHGuest users without access review

14 guest accounts have had access for over 90 days with no review. Former contractors and partners may still have access to your data.

MEDIUMConditional access gaps

Sign-in risk policies are not enforced. High-risk sign-ins from unusual locations are not being blocked or challenged.

Plus 97 more checks covering MFA quality, conditional access gaps, stale accounts, app credentials, tenant configuration, and identity risk detection.

Compliance

Pass Cyber Essentials. Satisfy your insurer. Evidence controls to your clients.

ScanPosture maps every finding to the frameworks your business actually needs to comply with.

Cyber Essentials

UK Government Scheme

Cyber Insurance

Insurer Requirements

ISO 27001

Information Security

UK GDPR

Data Protection

NIST CSF

Cybersecurity Framework

SRA

Solicitors Regulation

Cyber insurance is changing

Insurers are tightening identity security requirements. Claims are being challenged when organisations can’t evidence MFA enforcement, privileged access controls, and conditional access policies. ScanPosture gives you continuous proof that your controls are in place.

Simple Pricing

See how ScanPosture compares

Enterprise security scanning at a fraction of the cost.

Manual Consultant

One-off assessment

£2,000–5,000/assessment
  • Point-in-time assessment
  • No ongoing monitoring
  • No compliance mapping
  • No remediation tracking
  • Stale within weeks
Beta — Join free

ScanPosture

Continuous scanning

£2.50/user/month

From £250/month for 100 users

  • 103+ automated checks
  • Continuous daily monitoring
  • Drift detection between scans
  • Plain English remediation
  • Compliance evidence pack
  • Cyber insurance alignment
  • Results in minutes

£2.00/user at 101+ · £1.50/user at 501+

Save 10% with annual billing

Enterprise Tools

Full IAM platform

£6–12/user/month
  • Deep identity scanning
  • Provisioning & lifecycle
  • Access request workflows
  • PAM & governance
  • 6-month implementation
  • Requires dedicated IT team

How It Works

From signup to your first scan in under 5 minutes

1

Connect

Connect your Microsoft 365 tenant in under 2 minutes. Read-only permissions. No agents to install.

2

Scan

ScanPosture runs 103+ security checks across your Azure AD, users, apps, and configurations.

3

Fix

Every finding comes with plain English remediation steps and direct links to the Azure portal — no security expertise required.

4

Monitor

Daily scans detect drift. Get alerted when something changes. Track your security score improving over time.

Built by Practitioners

Enterprise experience. SMB focus.

Built by enterprise infrastructure practitioners with 30+ years of experience securing identity environments for organisations including NHS trusts, insurers, and financial services firms. We built ScanPosture because we saw the same Azure AD misconfigurations at every SMB we worked with — and no tool existed at a price they could afford.

Roadmap

Where we are

Beta live

Scanning Microsoft 365 and Azure AD

103+ security checks

Identity, access, apps, compliance

Compliance mapping

Cyber Essentials, ISO 27001, GDPR

Access reviews & MSP portal

Coming soon

AWS IAM & Google Workspace

On the roadmap

Secure your Microsoft 365. Join the beta.

Be among the first UK businesses to know exactly who can access what.

Free during beta · No credit card required