Continuous control assurance for Microsoft-first organisations

ScanPosture gives Microsoft-first organisations a clear view of control posture, prioritised remediation, and evidence that stays current. Built for ongoing governance, not one-off reviews.

Start a Trial

Read-only access · No agents to install · Microsoft 365 · UK company

138
Live checks
continuously monitored
9
Security domains
control-model scoring
6
Frameworks
CE, ISO, GDPR, NIST, CIS, SOC 2
£2.50
Per user / month
per M365 user

The Platform

A live view of control posture

Posture score, domain breakdown, priority actions, and drift detection. Everything you need to understand your control state and act on it.

app.scanposture.com/dashboard
Dashboard
Security posture overview · Last scan 2h ago
Run Scan
62
Developing Posture
Stable · 136 scored
Open Findings
49
5 critical · 22 high · 20 medium
Scan Coverage
112
of 138 checks applied
Avg 1.8d to resolve
Critical
5
Immediate attention required
Resolved
3
this month
Top Actions to Improve Your ScoreAll Findings →
1CRITICAL
Noncompliant Device Blocking
Device Security
+15
2CRITICAL
Entra ID Log Retention Depth
Logging & Audit
+15
3CRITICAL
No MFA for Admin Portal Access
Conditional Access
+15
Fix all 5 to improve your score40 → ~100/100
What Changed This ScanView All →
10 changes·10 new
NEW · 10
Custom Banned Password List Not ConfiguredMEDIUM
No Emergency Access (Break-Glass) AccountsHIGH
Self-Service Password Reset DisabledHIGH
Weak Password PoliciesHIGH
Users Without MFA EnabledCRITICAL
Security Domains9 scored · weakest first
D919
Device Security
D330
Conditional Access
D845
Logging & Audit
D450
Account Lifecycle
D161
Identity & Auth
D671
Monitoring & Posture

The Problem

Security posture managed through scattered tools and manual effort

Most Microsoft-first businesses rely on fragmented native tooling, infrequent manual checks, and screenshots as evidence. That creates real security risk and unreliable governance.

No unified view

Security configuration is spread across Entra ID, Exchange, SharePoint, Intune, and Teams admin centres. Nobody has the complete picture in one place.

Weak prioritisation

When all findings look the same, nothing gets fixed in the right order. Critical gaps sit alongside low-severity observations without clear direction.

Evidence that goes stale

Screenshots and export files lose credibility quickly. Clients, insurers, and auditors need current, structured proof, not last quarter's artefacts.

Why ScanPosture Is Different

Control strength, not checkbox compliance

Most tools give you raw findings or misrepresent what your controls actually cover. ScanPosture is designed around giving you a defensible view of what your controls achieve.

01

Not just pass/fail

Findings are grouped into controls. The result reflects genuine control posture across your tenant, not isolated configuration observations.

02

Four-dimension scoring

Each control is assessed across presence, coverage, quality, and strength. A policy covering 30% of users scores differently to one covering 95%.

03

Defensible evidence

Framework mapping language is bounded and precise. ScanPosture shows what can be evidenced. It does not make claims that cannot be supported.

What Gets Scanned

138 checks, structured around the controls that matter most

Coverage spans identity, access, applications, collaboration, logging, and device posture across Microsoft 365 and Entra ID.

Identity & authentication
Privileged access
Conditional Access policies
Account lifecycle & governance
Application & NHI permissions
Email security (SPF, DMARC, DKIM)
SharePoint & OneDrive sharing
Microsoft Teams collaboration
Logging & audit configuration
Device compliance (Intune)
Segregation of duties
AI & Copilot identity risk
Configuration drift detection
Guest & external access
Credential & secret management
Privileged account behaviour
Dormant & shadow IT
Monitoring & risk detection
Tenant configuration

What You Get After Every Scan

More than a findings list

Every scan produces structured outputs you can act on, share with stakeholders, and use as evidence.

Posture score

A 0-100 score across 9 weighted domains, with trend tracking over time.

Priority controls

A ranked view of which controls need the most attention, and what addressing them is worth.

Framework evidence

Readiness evidence mapped to CE, ISO 27001, GDPR, NIST, CIS, and SOC 2.

Remediation guidance

Step-by-step instructions with exact portal navigation paths for every finding.

Drift detection

See exactly what changed between scans, including what improved and what got worse.

PDF reports

Executive summary and evidence outputs, ready for client or stakeholder delivery.

Scheduled reporting

Posture summaries on your schedule, delivered by email, Slack, or Teams webhook.

Owner assignment

Assign findings to responsible owners. Track remediation accountability across your team.

The operating layer

Beyond the scan result

ScanPosture is not just a findings viewer. It gives you the tools to manage risk, record accountability, and maintain a defensible governance record over time.

Risk acceptance

Mark findings as accepted exceptions with supporting rationale. Keep your exception record auditable and available for review.

Compensating controls

Document where existing controls partially or fully offset identified gaps. Build a governance record that reflects operational reality, not just raw findings.

What got worse

Every scan surfaces controls that degraded since the last check. Identify and respond to deterioration, not just to the overall findings count.

Operational cadence

Recurring posture reviews on your timeline. Governance evidence stays current without manual extraction or scheduling effort.

Real Findings

What ScanPosture actually surfaces

Every finding includes severity, control mapping, framework alignment, and step-by-step remediation.

CRITICALUsers without MFA enabled
CRITICALLegacy authentication not blocked
HIGHAdmin accounts without dedicated identities
HIGHDMARC not configured for primary domain
HIGHGuest users with elevated privileges
HIGHAI agents with high-privilege permissions
MEDIUMSharePoint anonymous sharing enabled
MEDIUMNo device compliance policies configured

8 examples from 138 checks. A full scan covers identity, access, email, collaboration, devices, AI permissions, drift, and more.

Framework Readiness

Framework support, not compliance claims

ScanPosture maps observable controls to framework requirements and shows how strongly the evidence supports alignment. We do not claim certification or formal sign-off. We show what we can evidence.

Cyber Essentialsv3.3

Secure Configuration and User Access Control evidence within Microsoft 365 scope

ISO 270012022

Selected A.5 and A.8 technical control evidence across identity and access management

GDPRArticle 32

Technical safeguard assessment within identity, access, and data-handling scope

NIST SP 800-53Rev 5

Access Control, Identification and Authentication, and Audit and Accountability evidence

CIS Controlsv8.1

Account Management, Access Control, and Audit Log Management safeguard evidence

SOC 2Type II

Logical and Physical Access, Change Management, and Risk Monitoring criteria evidence

Pricing

Simple, transparent pricing

Priced per licensed user in the monitored Microsoft 365 tenant. Contact us for MSP and multi-tenant pricing.

£2.50

per licensed Microsoft 365 user / month

Pricing is per user in your monitored tenant, not per ScanPosture administrator. From £250/month for 100 users.

  • 138 security checks across 9 domains
  • Control-model posture scoring
  • Framework readiness (CE, ISO, GDPR, NIST, CIS, SOC 2)
  • Drift detection between scans
  • Step-by-step remediation guidance
  • PDF reports and CSV exports
  • Scheduled posture reporting
  • Email, Slack, and Teams webhook alerts
  • Continuous monitoring, not one-off

What organisations are replacing

One-off consultant review£3,000 to £8,000 each
Microsoft Secure Score only (fragmented view)Free but incomplete
Manual evidence via screenshots and spreadsheetsSignificant staff time
Generic compliance automation platform£6,000 to £15,000/year
ScanPosture (100 users)£250/month

Microsoft has useful native tooling, but posture visibility is fragmented across admin centres. ScanPosture brings control scoring, drift detection, and readiness evidence into a single operational layer, updated continuously.

For Managed Service Providers

A complete operating layer for MSP customer estates

The MSP portal and client portal are live. ScanPosture gives managed service providers a structured way to deliver continuous control assurance across their customer estate, with the reporting and visibility to make it a repeatable service.

MSP management portal

Manage all client tenants from one interface. Switch between clients, view consolidated posture, and run scans across your estate without separate logins.

Client-facing portal

Each client has their own scoped portal view. You control what they see, how much context they receive, and what actions they can take.

Branded reporting

Deliver posture and evidence reports under your brand. Configure content, frequency, and visual identity per client.

Portfolio drift visibility

See what changed across all client tenants between scans. Identify deterioration early, before clients raise it.

Recurring review workflows

Structured review cadence for every client. Posture evidence generated on your schedule, ready for service delivery without manual effort.

Commercial visibility

See where clients need hardening work, licence changes, or expanded scope. Operational insight that supports structured account development.

Platform Status

What’s live, what’s next, what’s planned

Control assurance is live and operational. Here is where each capability currently sits.

Live

  • 138 checks across 9 security domains
  • Control-model posture scoring
  • Customer portal and reporting
  • MSP portal and client portal
  • Drift detection and scheduled scans
  • Framework readiness (CE, ISO, GDPR, NIST, CIS, SOC 2)
  • Remediation guidance and PDF reports
  • Risk acceptance and exception tracking
  • Demo environment

Next

  • Deeper Microsoft 365 coverage
  • Stronger governance and exception workflows
  • Richer MSP review and client reporting
  • Broader executive evidence outputs
  • Direct customer billing portal

Planned

  • AWS IAM assurance expansion
  • Selected SaaS posture coverage
  • Authorised remediation
  • Cross-platform assurance layer
  • Public launch (Autumn 2026)

Getting Started

From connection to continuous assurance

Read-only OAuth consent. No agents, no passwords, no complex setup. Posture in minutes.

Connect Microsoft 365

Read-only OAuth consent

First scan starts

Runs automatically

Review your posture

Results in minutes

Stay assured

Ongoing monitoring

Read-only accessNo agents to installMicrosoft 365UK company (Lawsons Enterprises Ltd)

Built By Practitioners

I built ScanPosture because I saw the same problem at every Microsoft-first business I worked with: fragmented security evidence, weak prioritisation, and no ongoing assurance. The tools that existed were either too basic or too expensive. This product fills that gap.

Andy Lawson, Founder, ScanPosture

Know what your controls look like. Fix the right gaps first.

Clear posture. Prioritised remediation. Evidence that stays current.

Start a Trial