Microsoft Secure Score
Microsoft's tenant posture measurement
Evidence-backed priorities for identity, applications, email domains, and external exposure.
Microsoft's tenant posture measurement
Deterministic analytics from current evidence
Open findings by severity and control family
Publicly observable domain protection
Searchable evidence, business context, remediation steps, ownership, and target SLA.
Sequenced by containment value, operational effort, and implementation dependency.
Resolve the identity baseline first, then validate application ownership in batches. Record accepted risks and verify closure on the next daily scan.
Security capabilities available with the tenant's assigned identity licences
Detect risky users and sign-ins, then require MFA, secure password reset, or block access according to risk.
Replace permanent administrator access with time-limited activation, approval, MFA, justification, and audit history.
Apply stronger controls when Microsoft detects elevated user or sign-in risk instead of treating every session the same.
What good looks like after the first improvement cycle
Security Defaults on Free tenants, or Conditional Access policies on P1/P2, protect administrators and users.
Every high-impact OAuth grant has a documented owner and purpose.
Initial improvement target using low-disruption controls.
Daily scan validates closure and detects regression.
A concise view of the identities, roles, applications, grants, and domains in scope.
Click any role to view its current users and directory objects
| Directory role | Members | Review |
|---|
Authentication and tenant-default status
| Domain | Auth | Status |
|---|
Microsoft product names, seat totals, and product assignments by licensed user. Graph SKU codes are shown in smaller text for reference.
Assigned identity licence coverage
Entitlement is not the same as assignment
Purchased, assigned, and available seats reported by Graph subscribedSkUs
| Product | Entra entitlement | Status | Purchased | Assigned | Available |
|---|
Product assignments returned by Microsoft Graph
| User | Account | Licences |
|---|
Monitors only DNS records that connect this tenant to Microsoft 365 services. Website hosting, nameservers, and other third-party DNS are outside Surface Guard's responsibility.
Change detection and resolver agreement for Exchange Online, Entra ID, Intune, and Teams records
Green OK means the Microsoft endpoint matches the protected baseline and agrees across public resolvers
Connection status, evidence sources, and current monitoring boundaries.
Important context when interpreting this assessment
No account, email, application, or policy changes can be executed by this connector.
Posture data is collected daily; public DNS and web observations represent scan time.
Application findings require an owner and usage check before consent or credentials are removed.