Your tenant's security at a glance. Each card below summarizes one area — identity, threats, licensing, governance — using a simple green / amber / red signal. Skim the page in 30 seconds: green means healthy, amber means worth a look, red means someone should be working on it this week.
Cyber-insurance policies and basic compliance now expect a handful of specific security controls to be in place — MFA everywhere, old sign-in methods blocked, admin accounts protected, devices managed. This page turns your tenant into that yes/no checklist, so you can see at a glance whether you'd pass, and exactly what to fix (or hand to IT) before a renewal or audit.
Auditors don't ask "is your tenant secure?" — they ask whether you meet specific, named controls from a framework like CIS Controls v8, NIST CSF 2.0, or ISO/IEC 27001. This page takes the security posture already measured across the other sections and cross-references it to those catalogues, so you can see which named controls you already satisfy and which are gaps — a running head-start on any audit or questionnaire. It's an indicative map to focus effort, not a formal certification.
CyberSecure Canada (CyberSécuritaire Canada) is a voluntary federal certification program for small and medium organizations, built around 13 baseline controls. This page cross-references what your Microsoft 365 tenant can measure directly against those controls — the same posture already tracked elsewhere in this dashboard — and lets you record the rest as your own declaration. It is a self-assessment to help you prepare, never a substitute for the certification itself, and never a percentage: every count below is either measured from your tenant or declared by your organization, shown plainly as what it is.
Microsoft scores your tenant against a checklist of security best practices — think of it like a credit score for your Microsoft 365 setup. Higher means fewer easy openings for attackers. The list below shows what's still open, grouped by area (Identity, Apps, Data…), with the biggest opportunities first. A score climbing over time means the team is closing real risks.
Everyone who can sign in, on one row each: whether they have multi-factor sign-in, how strong that method is, whether they hold admin powers, and when they last signed in. The tiles above the table double as filters — click No MFA or Phishable MFA to jump straight to the people who need attention. This replaces the three separate identity tables with a single view.
People leave, but Microsoft 365 access doesn't always leave with them. This page cross-references the People data already collected to surface accounts that look like a departure: disabled but still licensed (a seat you're still paying for), an account with no sign-in in 90+ days while still licensed, or a guest who hasn't signed in in 90+ days. Each one comes with a short offboarding checklist — reclaim the licence, disable the account, revoke guest access — to hand to whoever manages your tenant. Read-only: the checklist is text you act on in your own admin tools, never a button here.
Who can sign in to your company, how they prove it's really them, and who holds admin powers. People without multi-factor authentication are the single biggest risk in any tenant — one stolen password and the attacker is in. The admin lists below also matter: the more administrators you have, the larger the damage if one account is compromised.
The rules that decide who can sign in, from where, and under what conditions — for example "require MFA when signing in from a new device" or "block sign-ins from countries we don't do business in." This section highlights gaps: common attack patterns that aren't yet blocked. Each gap is a door we know how to close.
What Microsoft Defender has actually seen attempting to attack your tenant — suspicious sign-ins, leaked passwords found on the dark web, malware on company devices. A clean list is the goal. Anything red or recent should be reviewed by whoever owns security incident response.
How your people prove it's really them when they sign in. Passwords alone are phishable; so are SMS and voice codes. The goal is phishing-resistant methods — passkeys, Windows Hello, FIDO2 keys — which an attacker can't intercept. This page shows how many users are MFA-capable, how many can go passwordless, and who is still relying on SMS/voice so you know exactly who to move first.
How your email is protected against phishing, spoofing, and malicious attachments — and what's been caught recently. Email is the #1 way attackers get into companies, so this section answers two questions: are the standard protections turned on, and are they working?
Who you're paying Microsoft for, what they're actually using, and where you might be over- or under-licensed. Each user is a recurring cost; this section helps you spot licences that aren't being used (recoverable spend) and users whose role would justify a security upgrade (e.g. moving a high-risk admin from E3 to Entra ID P2).
Every app — both your internal tools and third-party services like DocuSign, Slack, or Salesforce — that has permission to read or write data in your tenant. A forgotten app with broad permissions is a quiet backdoor: nobody uses it, nobody is watching it, but an attacker who compromises that app gets access too. This section helps you spot what to retire.
Every way company data can leave your tenant to outsiders: files shared through SharePoint and OneDrive links — especially anonymous "Anyone" links that need no sign-in — who's allowed to invite external guests, and the guest accounts that already have access. Anonymous links and forgotten guests are two of the most common findings in a security audit or a cyber-insurance questionnaire, so this page shows exactly where you stand and what to tighten.
Admin power is what an attacker is really after — one compromised administrator can undo everything else. This page shows who holds admin roles, and whether that power is standing (always live, always a target) or just-in-time (granted only when needed, via Privileged Identity Management). The goals are simple: as few permanent Global Administrators as possible, everyone on least-privilege, and admin access granted on demand rather than left switched on.
Every sign-in and every admin change is logged by Entra ID — but the raw logs are overwhelming. This page summarises the most recent activity: how many sign-ins succeed vs fail, how many satisfy MFA, whether any legacy (pre-MFA) sign-ins are still happening, where sign-ins come from, and what administrators changed recently. Use it to spot patterns — a spike in failures, an unexpected country, a burst of admin changes — then drill into the full logs for the details. Sign-in logs need an Entra ID P1 licence.
Email is the most common way data leaks out and fraud gets in. This page covers two risks visible to a read-only sign-in: apps that have been granted permission to read or send your users' mail (a favourite for invoice fraud and quiet data theft), and email domains that aren't verified (which weakens spoofing protection). Deeper checks like per-mailbox auto-forwarding rules need higher permissions — the page explains what's covered and what isn't.
Data protection is about classifying sensitive information (with sensitivity labels like Confidential) and then controlling it (encryption, and DLP rules that stop it leaving). This page shows the labels your tenant has published — the foundation everything else builds on — plus a primer on Microsoft Purview's DLP and its newer AI governance for Copilot. For most small businesses this is a grow-into-it area; it's here so the picture is complete when you need it.
The single most misunderstood thing about Microsoft 365: Microsoft does not back up your data. They keep the service running and replicate your data across datacentres, but if a user deletes a mailbox, ransomware encrypts your files, or a retention window lapses, recovering it is your responsibility. This page explains that shared-responsibility gap in plain English, gives a retention-and-recovery checklist to verify, and makes the case for a dedicated third-party backup.
The big-picture hygiene settings: who is allowed to create groups, invite external guests, register new apps, or run automation. Loose defaults here mean any employee can quietly expand the company's attack surface without anyone noticing. Tight defaults keep change deliberate and auditable.
Who's actually using Microsoft 365 day-to-day — last sign-in, mailbox activity, file usage. Two uses: licensing decisions (a paid account nobody logs into is waste), and risk (a long-dormant account, especially an admin one, is a door left unlocked).
The plan and live status for managing your company’s Windows computers with Microsoft Intune — Entra-joined, Autopatch for updates, BitLocker and Defender. The Monitor tab shows each enrolled device’s compliance and encryption in real time; the Rollout Plan tab is the step-by-step build guide. Devices appear here automatically as you enrol them.
How AI is actually being used and trusted in the tenant. Two angles: are the Microsoft 365 Copilot seats you pay for being used (idle seats are the most expensive waste you own), and which third-party AI tools — ChatGPT, Claude, Gemini and the like — your users have granted access to your data. The first is a cost question, the second is a data-governance risk.
Before you switch on Microsoft 365 Copilot, this checks whether your tenant is ready to use it safely — Copilot can surface anything a person is already allowed to open, so data safety comes before licences. It reads the sharing, labelling, access, shadow-AI and licensing posture you already collect and shows what to set up first. Read-only: it reports readiness and the setup steps, it changes nothing itself.
Every app that has been granted permission — by a user or an admin — to read or write data in this tenant, plus what that permission actually lets it do. A forgotten or over-permissioned app is a quiet backdoor: nobody uses it, nobody is watching it, but an attacker who compromises that app inherits its access. Microsoft's own first-party apps are expected and deprioritized; the apps worth reviewing are surfaced first.