Microsoft-first · Entra ID · Read-only scanning

The whole Microsoft 365 control posture, on one page

ScanPosture connects read-only to Microsoft 365 and Entra ID, assesses security posture across key control areas, and turns technical findings into prioritised remediation, evidence, and trend visibility.

28-day trial · No credit card · Read-only scanning

Multi-tenant readyDrift between scans8 framework views

The live dashboard, at a glance

Posture score, open findings, scan coverage, priority actions, and what changed between scans, on one page, refreshed with every completed scan.

Good afternoon, Rachel Whitfield
Posture, attention, and remediation across your tenant, on one page.
Tenant posture·Last 30 days
AI SummaryRun Scan
Latest scan·12h ago Improving(observed)
71/100C
+3
Improving posture
Posture has improved 3 points this month. One critical finding remains in Identity & Authentication, clearing it would lift the score towards the B band. Two access-review responses are overdue.
6078952 Jun9 Jun17 Jun24 Jun2 Jul
Open critical findings
1
Highest-severity open findings
Open high findings
7
High-severity open findings
Resolved this week
6
In the last 7 days
Latest scan age
12h
Last completed 12h ago
Users protected
138
Observed Microsoft 365 users in this tenant
Recent scan movement
Posture improved. 6 findings resolved this scan.
Closures outpaced new exposure since the last completed scan.
New
2
Resolved
6
Net movement
−4

Actual ScanPosture dashboard

More than a dashboard

ScanPosture is designed to help teams understand what their Microsoft controls look like, where posture is weakening, what needs attention first, and what evidence can be shown to stakeholders.

01

Assess posture

Map Microsoft 365 and Entra ID signals into controls and domains so the picture holds together.

02

Prioritise remediation

Surface the actions with the greatest posture impact and make them easy to hand off.

03

Evidence improvement

Show recurring scans, trend history, and framework readiness to stakeholders that ask.

From connection to evidence, in four steps

1

Connect Microsoft 365

Read-only OAuth consent. No agents, no passwords, no tenant write actions.

OAuth · Read-only

2

Run a scan

ScanPosture assesses Microsoft 365 and Entra ID configuration against 201 read-only checks.

201 checks

3

Review posture

Findings are grouped into domains, controls, priority actions, and framework readiness views.

9 domains

4

Track improvement

Recurring scans show what changed, what improved, and what needs renewed attention.

Drift · Trend

Every completed scan

Posture score, open findings, and what changed this scan

The dashboard refreshes with every completed scan. Score, open findings, priority actions, scan coverage, and what changed since the previous scan, in one place.

Posture score

A weighted score across 9 control domains, with movement against the previous scan.

Open findings

Grouped by severity, with trend per domain.

Priority actions

Ranked by estimated score impact.

Scan coverage

Areas not observable do not count as passes.

Drift since last scan

Every finding compared against the previous completed scan.

Access reviews

Risks assigned in-line, reviewer activity tracked.

Framework readiness

Observable readiness across the evidenced frameworks, scored separately.

The ScanPosture score reflects connected and assessed scope. Areas not connected or not observable are not silently treated as passed or failed.

Control strength, across four dimensions

A control that exists but only covers a small number of users should not score the same as a control that is consistently enforced across the tenant. ScanPosture scoring is designed to reflect that difference.

Presence

Does the control exist in the tenant?

Coverage

What share of users, roles, apps, or data is in scope?

Quality

Are the settings configured with appropriate strength?

Strength

How resilient is the control against bypass or weak configuration?

Framework readiness scores are separate from the overall posture score.

Every priority action

Priority actions with real remediation detail

Findings become prioritised steps. Each one shows what to change, why it matters, and exactly where in the Microsoft admin experience to do it.

Ranked impact

Estimated score gain per action.

Step-by-step guides

The exact portal path to do it.

Deep-links

Straight into the right admin centre.

Prerequisites

Licence and role notes where they apply.

Verification

Confirm the fix actually applied.

Hand-off ready

Exports cleanly for analysts or MSPs.

What changed since the last completed scan

Every scan is compared against the previous completed scan. You see new findings, returned findings, resolved findings, and which areas have worsened.

New

First detected in the latest scan compared with the previous completed scan.

Returned

Previously seen historically, absent in the previous completed scan, and present again now.

Resolved

Present in the previous scan, not present in the latest scan.

What ScanPosture produces

Evidence that refreshes itself

Every output reflects the latest scan, so stakeholders see current evidence without manual compilation, screenshots, or stitched-together spreadsheets.

PDF posture reports

Board-ready score, actions and movement.

Executive summaries

Single-page narrative for leadership.

Scheduled digests

Weekly, monthly or per-scan emails.

CSV exports

For tickets, systems and MSP hand-off.

Always current

Never a stale snapshot.

Framework readiness

Packs across the eight evidenced frameworks.

Read-only by design

Read-only access. No agents. No tenant changes.

ScanPosture observes configuration and generates findings. Policies, users, roles, and tenant settings are not changed during scans.

No passwords collected

OAuth-only. ScanPosture never stores or processes Microsoft account passwords.

No agent deployment

Cloud-side only. Nothing to install on endpoints, servers, or domain controllers.

Read-only OAuth

Every Microsoft Graph permission ScanPosture asks for is read-scoped. Verifiable in the consent screen.

Visible at consent

Your Global Administrator sees the full permission list before granting access.

No silent remediation

Findings are surfaced. Nothing is changed automatically. Future write actions need explicit authorisation.

Removable connection

Revoke ScanPosture’s tenant access at any time from the Microsoft admin centre.

Multi-tenant Direct

Run posture across multiple Microsoft tenants under one account

Holding companies, M&A consolidation periods, in-house IT teams managing sister-company tenants, one ScanPosture account can hold and switch between every tenant a team is responsible for, with role-scoped access per tenant.

One sign-in, many tenants

A single Microsoft work account holds membership of every tenant you have access to. The dashboard sidebar carries a tenant picker; switching is one click.

Role-scoped per tenant

Owner / admin / analyst / billing / viewer is set per (user, tenant) pair. A user can be an owner on one tenant and an analyst on another. Row-level security keeps every read scoped to the active tenant.

Built for real situations

Holding companies with multiple operating subsidiaries. Acquired businesses inside their own Entra tenant during integration. Internal IT teams supporting sister companies. The same product, scoped cleanly.

MSP partners use the same multi-tenant model with extra fleet-level views, branded reporting and per-client billing. See the MSP page →

Frequently asked

Platform questions

Everything an IT lead or Global Administrator typically asks before granting consent.

Yes, and it is worth being precise about how. Every Microsoft Graph permission ScanPosture requests is read-scoped, and no agents or passwords ever enter your tenant. Microsoft offers no read-only application permission for Exchange Online, so the single Exchange permission, Exchange.ManageAsApp, is pinned to read-only by the Global Reader role your administrator assigns, and the scan engine only ever issues read (Get-) commands against it. Nothing in your tenant is changed during a scan: policies, users, roles and settings stay exactly as they were. The only tenant change happens at setup, when your administrator approves that read-only access.

You will see the standard Microsoft admin consent screen listing the read-scoped Microsoft Graph permissions ScanPosture uses to assess posture, alongside the single Exchange Online application permission Microsoft provides, Exchange.ManageAsApp, which grants nothing on its own and is bounded to read-only by the Global Reader role you assign separately. Two optional Azure-resource checks also benefit from a read-only Reader role at your tenant root, granted separately if you want them included. The full request set is shown to your Global Administrator at the moment of consent, nothing is hidden behind it.

Once a day by default, at 02:00 in your tenant timezone. You can raise that to up to four scans a day in settings, and any tenant owner or admin can trigger an unscheduled scan from the dashboard at any time.

Typically one to three minutes for a connected Entra ID tenant. Larger tenants with a high number of apps, guests and roles sit at the longer end of that range. Progress is shown live in the dashboard while the scan runs.

ScanPosture reads your Secure Score as a signal and links you to it inside the Microsoft Defender portal, it does not replace it. ScanPosture’s own score is a control-model rollup across nine weighted security domains, drift-aware between scans, framework-mapped, and licence-aware: missing licence coverage is reported as "out of assessment scope" rather than silently treated as a failure.

All customer data is stored in the United Kingdom, in our Supabase region in London. Application hosting and email delivery are routed through UK / EU infrastructure end-to-end.

Eight readiness views, Cyber Essentials, ISO 27001:2022, GDPR Article 32, NIST CSF 2.0, NIST SP 800-53 Rev 5, CIS Controls v8.1, SOC 2, and NCSC CAF 4.0. ScanPosture provides readiness evidence, not certification, it does not submit, approve or certify any framework assessment.

See your Microsoft posture clearly

Start your 28-day trial and see your own posture inside a few minutes.

Read-only · no agents201 checks · 9 domainsNo credit card