Free tool
How secure is your Microsoft 365?
A read-only audit of your tenant in under a minute: Secure Score benchmarked against similar organisations, MFA coverage, legacy authentication, conditional access and admin sprawl, in plain English.
How secure is your Microsoft 365, really?
Sign in as a Microsoft 365 administrator and we'll run a read-only audit: your Secure Score against similar organisations, MFA coverage, legacy authentication, conditional access, admin sprawl and guests, in plain English. It takes under a minute.
- Read-only permissions, so nothing can be changed
- Runs once and keeps nothing on our servers
- We never see your password, sign-in stays with Microsoft
- Revoke access any time in Entra under Enterprise applications
You'll need to be an admin: the audit reads tenant-wide security settings, which Microsoft only releases with admin-approved permissions. Your contact details are only shared with us if you choose to at the end. Privacy policy
What the audit checks
- Your Microsoft Secure Score, benchmarked against organisations of a similar size, with Microsoft's own top improvement actions ranked by the points on the table.
- MFA coverage: how many of your users could actually complete a multi-factor challenge if asked. Microsoft's data says MFA stops over 99% of account-compromise attacks.
- Legacy authentication: whether the old protocols that skip MFA entirely (IMAP, POP, basic auth) are blocked, because password-spray attacks try them first.
- Baseline enforcement: security defaults or conditional access, including policies sitting in report-only mode that protect nobody.
- Admin sprawl and guests: how many global administrator accounts exist (Microsoft recommends two to four) and how many external guests are in your directory.
Why it matters
Most breaches aren't clever. They're a missing setting.
The attacks that actually hit UK businesses walk through doors that were already there to close: an account without MFA, a legacy protocol left open, an admin login that was never locked down.
The score is the shortlist
Secure Score's real value isn't the number, it's the ranked to-do list underneath it, generated by Microsoft from your actual configuration. The audit surfaces your top actions with the points each is worth, so instead of a vague sense that "we should do more about security" you get five specific changes in priority order. Insurers and auditors are starting to ask for the number too, which makes now a good time to know it.
Fixing it without breaking Monday morning
Every finding in this audit is fixable with configuration, but sequencing matters: enforce MFA before blocking legacy authentication, exempt the copier's mailbox before it stops scanning, and keep a break-glass account outside every policy. We make these changes for clients routinely with zero lockouts, as part of Cyber Essentials preparation and our wider modern workplace management.
Questions
About this tool
A Microsoft 365 administrator for your organisation. The audit reads tenant-wide security configuration, and Microsoft only releases that to an admin who approves the read-only permissions. If you're not an admin you'll see a 'needs admin approval' message; forward this page to whoever looks after your Microsoft 365.
The connection is read-only and goes through Microsoft's own sign-in, so we never see your password and the tool has no permission to change anything. It reads your Secure Score, security defaults and conditional access state, the MFA registration report, admin role membership counts and the guest count. An admin can revoke the access at any time in Microsoft Entra under Enterprise applications.
It's processed on the fly and discarded. Nothing is stored on our servers, and there are no logs of your configuration. Your contact details are only sent to us if you choose to share them to unlock the full report, and the summary we receive contains your score and check results only, never user or admin names.
Microsoft's own measurement of your security posture, calculated inside your tenant from the controls you have and haven't enabled. Each recommended action is worth points. It's genuinely useful because it's specific to your setup and comes with Microsoft's prioritised to-do list, and cyber insurers increasingly ask for it. Its limit is scope: it measures Microsoft 365 configuration, not your endpoints, backups or people.
No, but do act. The average organisation scores well under half the available points, so a mediocre score puts you in plentiful company. What matters is the handful of high-value items: MFA enforced for everyone, admins protected, legacy authentication blocked. Those three shut down the attacks that actually happen to UK SMEs, and they're usually a day's careful work.
Yes, and carefully. Most of these fixes are settings changes, but the order matters: enforce MFA before you block legacy auth, warn users before you change their sign-in experience, and keep a break-glass account outside every policy. We do this routinely, roll it out without locking anyone out, and it dovetails with Cyber Essentials certification if you want the badge too.
Red flags in your audit?
We'll close the gaps in the right order, with no lockouts and no drama, and keep them closed with 24×7 monitoring.