The whole Microsoft 365 control posture, on one page
ScanPosture connects read-only to Microsoft 365 and Entra ID, assesses security posture across key control areas, and turns technical findings into prioritised remediation, evidence, and trend visibility.
28-day trial · No credit card · Read-only scanning
The live dashboard, at a glance
Posture score, open findings, scan coverage, priority actions, and what changed between scans, on one page, refreshed with every completed scan.
Actual ScanPosture dashboard
More than a dashboard
ScanPosture is designed to help teams understand what their Microsoft controls look like, where posture is weakening, what needs attention first, and what evidence can be shown to stakeholders.
Assess posture
Map Microsoft 365 and Entra ID signals into controls and domains so the picture holds together.
Prioritise remediation
Surface the actions with the greatest posture impact and make them easy to hand off.
Evidence improvement
Show recurring scans, trend history, and framework readiness to stakeholders that ask.
From connection to evidence, in four steps
Connect Microsoft 365
Read-only OAuth consent. No agents, no passwords, no tenant write actions.
OAuth · Read-only
Run a scan
ScanPosture assesses Microsoft 365 and Entra ID configuration against 201 read-only checks.
201 checks
Review posture
Findings are grouped into domains, controls, priority actions, and framework readiness views.
9 domains
Track improvement
Recurring scans show what changed, what improved, and what needs renewed attention.
Drift · Trend
Posture score, open findings, and what changed this scan
The dashboard refreshes with every completed scan. Score, open findings, priority actions, scan coverage, and what changed since the previous scan, in one place.
Posture score
A weighted score across 9 control domains, with movement against the previous scan.
Open findings
Grouped by severity, with trend per domain.
Priority actions
Ranked by estimated score impact.
Scan coverage
Areas not observable do not count as passes.
Drift since last scan
Every finding compared against the previous completed scan.
Access reviews
Risks assigned in-line, reviewer activity tracked.
Framework readiness
Observable readiness across the evidenced frameworks, scored separately.
The ScanPosture score reflects connected and assessed scope. Areas not connected or not observable are not silently treated as passed or failed.
Control strength, across four dimensions
A control that exists but only covers a small number of users should not score the same as a control that is consistently enforced across the tenant. ScanPosture scoring is designed to reflect that difference.
Presence
Does the control exist in the tenant?
Coverage
What share of users, roles, apps, or data is in scope?
Quality
Are the settings configured with appropriate strength?
Strength
How resilient is the control against bypass or weak configuration?
Framework readiness scores are separate from the overall posture score.
Every priority action
Priority actions with real remediation detail
Findings become prioritised steps. Each one shows what to change, why it matters, and exactly where in the Microsoft admin experience to do it.
Ranked impact
Estimated score gain per action.
Step-by-step guides
The exact portal path to do it.
Deep-links
Straight into the right admin centre.
Prerequisites
Licence and role notes where they apply.
Verification
Confirm the fix actually applied.
Hand-off ready
Exports cleanly for analysts or MSPs.
What changed since the last completed scan
Every scan is compared against the previous completed scan. You see new findings, returned findings, resolved findings, and which areas have worsened.
First detected in the latest scan compared with the previous completed scan.
Previously seen historically, absent in the previous completed scan, and present again now.
Present in the previous scan, not present in the latest scan.
What ScanPosture produces
Evidence that refreshes itself
Every output reflects the latest scan, so stakeholders see current evidence without manual compilation, screenshots, or stitched-together spreadsheets.
PDF posture reports
Board-ready score, actions and movement.
Executive summaries
Single-page narrative for leadership.
Scheduled digests
Weekly, monthly or per-scan emails.
CSV exports
For tickets, systems and MSP hand-off.
Always current
Never a stale snapshot.
Framework readiness
Packs across the eight evidenced frameworks.
Read-only by design
Read-only access. No agents. No tenant changes.
ScanPosture observes configuration and generates findings. Policies, users, roles, and tenant settings are not changed during scans.
No passwords collected
OAuth-only. ScanPosture never stores or processes Microsoft account passwords.
No agent deployment
Cloud-side only. Nothing to install on endpoints, servers, or domain controllers.
Read-only OAuth
Every Microsoft Graph permission ScanPosture asks for is read-scoped. Verifiable in the consent screen.
Visible at consent
Your Global Administrator sees the full permission list before granting access.
No silent remediation
Findings are surfaced. Nothing is changed automatically. Future write actions need explicit authorisation.
Removable connection
Revoke ScanPosture’s tenant access at any time from the Microsoft admin centre.
Run posture across multiple Microsoft tenants under one account
Holding companies, M&A consolidation periods, in-house IT teams managing sister-company tenants, one ScanPosture account can hold and switch between every tenant a team is responsible for, with role-scoped access per tenant.
One sign-in, many tenants
A single Microsoft work account holds membership of every tenant you have access to. The dashboard sidebar carries a tenant picker; switching is one click.
Role-scoped per tenant
Owner / admin / analyst / billing / viewer is set per (user, tenant) pair. A user can be an owner on one tenant and an analyst on another. Row-level security keeps every read scoped to the active tenant.
Built for real situations
Holding companies with multiple operating subsidiaries. Acquired businesses inside their own Entra tenant during integration. Internal IT teams supporting sister companies. The same product, scoped cleanly.
MSP partners use the same multi-tenant model with extra fleet-level views, branded reporting and per-client billing. See the MSP page →
Platform questions
Everything an IT lead or Global Administrator typically asks before granting consent.
Yes, and it is worth being precise about how. Every Microsoft Graph permission ScanPosture requests is read-scoped, and no agents or passwords ever enter your tenant. Microsoft offers no read-only application permission for Exchange Online, so the single Exchange permission, Exchange.ManageAsApp, is pinned to read-only by the Global Reader role your administrator assigns, and the scan engine only ever issues read (Get-) commands against it. Nothing in your tenant is changed during a scan: policies, users, roles and settings stay exactly as they were. The only tenant change happens at setup, when your administrator approves that read-only access.
You will see the standard Microsoft admin consent screen listing the read-scoped Microsoft Graph permissions ScanPosture uses to assess posture, alongside the single Exchange Online application permission Microsoft provides, Exchange.ManageAsApp, which grants nothing on its own and is bounded to read-only by the Global Reader role you assign separately. Two optional Azure-resource checks also benefit from a read-only Reader role at your tenant root, granted separately if you want them included. The full request set is shown to your Global Administrator at the moment of consent, nothing is hidden behind it.
Once a day by default, at 02:00 in your tenant timezone. You can raise that to up to four scans a day in settings, and any tenant owner or admin can trigger an unscheduled scan from the dashboard at any time.
Typically one to three minutes for a connected Entra ID tenant. Larger tenants with a high number of apps, guests and roles sit at the longer end of that range. Progress is shown live in the dashboard while the scan runs.
ScanPosture reads your Secure Score as a signal and links you to it inside the Microsoft Defender portal, it does not replace it. ScanPosture’s own score is a control-model rollup across nine weighted security domains, drift-aware between scans, framework-mapped, and licence-aware: missing licence coverage is reported as "out of assessment scope" rather than silently treated as a failure.
All customer data is stored in the United Kingdom, in our Supabase region in London. Application hosting and email delivery are routed through UK / EU infrastructure end-to-end.
Eight readiness views, Cyber Essentials, ISO 27001:2022, GDPR Article 32, NIST CSF 2.0, NIST SP 800-53 Rev 5, CIS Controls v8.1, SOC 2, and NCSC CAF 4.0. ScanPosture provides readiness evidence, not certification, it does not submit, approve or certify any framework assessment.
See your Microsoft posture clearly
Start your 28-day trial and see your own posture inside a few minutes.