201 read-only checks · 15 categories · 9 domains

201 read-only checks across Microsoft 365 and Entra ID

ScanPosture assesses identity, privileged access, Conditional Access, collaboration, audit, device posture, non-human identity, Exchange Online, Teams, SharePoint, and configuration drift.

15 categories9 security domainsRead-only
201
Read-only checks
15
Categories
9
Security domains
6
Framework readiness views

Checks are read-only. ScanPosture observes configuration and generates findings. It does not modify the tenant during scans.

15 coverage categories

Checks are organised into categories so remediation and reporting can be scoped to the areas most relevant to each stakeholder.

Authentication & MFA
Privileged Access
Account Hygiene
Conditional Access
Apps & Non-Human Identity
Tenant Configuration
Monitoring & Risk
Segregation of Duties
AI Agent Identity
Device Security
SharePoint Online
Microsoft Teams
Exchange Online
Logging & Audit
Apps & Permissions

9 security domains, weighted into one posture score

Findings roll up into nine weighted domains. Domain weights reflect posture impact, so a gap in a high-weight area moves the overall score more than a gap in a low-weight area.

D1

Identity & Authentication

User identity, MFA methods, authentication strength, and sign-in protections.

D2

Privileged Access

Admin role assignments, PIM activation, and scoped privilege.

D3

Conditional Access & Policy Enforcement

Who can access what, from where, under which conditions.

D4

Account Lifecycle & Governance

Joiner, mover, leaver flows; dormant and guest accounts; access reviews.

D5

Application & Non-Human Identity Security

Service principals, application permissions, credential hygiene.

D6

Data Access & Collaboration Security

SharePoint, Teams, Exchange sharing posture and external access.

D7

Monitoring, Drift & Posture

Security monitoring configuration and configuration drift detection.

D8

Logging & Audit

Unified audit log coverage, retention, and diagnostic-settings.

D9

Device Security

Device compliance, enrolment, and CA enforcement where observable.

A sample of what ScanPosture surfaces

Curated examples — not a raw export. Real scans typically surface dozens of findings, grouped by domain and sorted by priority.

CRITICAL

Users without MFA enabled

Identifies accounts lacking any MFA method. Each unprotected account is a credential-theft risk.

HIGH

Privileged users relying on weak MFA methods

Admins using SMS or Voice as their only MFA. Weak against phishing-resistant bypass.

HIGH

Excessive Global Administrator accounts

Too many standing GA assignments increases blast radius if any are compromised.

HIGH

New Global Administrator added

Drift signal — GA assignment changes since last scan.

HIGH

Guest users with elevated privileges

External accounts with admin or privileged roles bypass normal governance.

HIGH

Legacy authentication not blocked

Basic auth / legacy protocols bypass MFA and modern policy.

HIGH

SharePoint anonymous sharing enabled

"Anyone with the link" level sharing exposes tenant data to the open internet.

MEDIUM

DMARC not configured

Unprotected domain — vulnerable to spoofing and BEC.

MEDIUM

Admin accounts with active mailboxes

Admin identities being used as daily drivers increase credential-theft blast radius.

HIGH

PIM activation without MFA required

Just-in-time role activation should require step-up authentication.

MEDIUM

Service principals with expiring credentials

Non-human identities with secrets about to lapse — operational and security signal.

CRITICAL

Audit logging not configured

Without unified audit log, post-incident investigation is severely limited.

Licence-aware assessment

Some Microsoft controls require specific Entra ID or Microsoft 365 licensing. ScanPosture distinguishes between failed controls, skipped checks, insufficient evidence, and areas outside the current assessment scope.

Passed

The control is configured appropriately for the assessed scope.

Finding raised

ScanPosture observed a posture gap with severity and remediation guidance.

Skipped

Check could not run because a required permission or licence was not present.

Advisory

Informational signal. No score impact but recorded for context.

Insufficient evidence

Signals available do not support a reliable pass/fail conclusion.

Out of current assessment scope

The area is not assessed by the currently connected scope.

Read-only permission model

ScanPosture uses read-only access to observe configuration. It does not make tenant changes as part of scanning.

Future coverage

ScanPosture is Microsoft-first today, with future expansion planned for AWS and selected SaaS platforms where customers need a broader assurance picture.

Want to see what your tenant surfaces?

Book a 30-minute walkthrough against a working ScanPosture tenant.

201 read-only checks9 security domainsNo sales script