Tenant /
Security operations overview

Microsoft 365 security posture

Evidence-backed priorities for identity, applications, email domains, and external exposure.

Microsoft Secure Score

Microsoft's tenant posture measurement

Secure Score

CurrentInitial target 60%Strong 80%

Executive analysis

Deterministic analytics from current evidence

Action focused

Risk concentration

Open findings by severity and control family

Email & web controls

Publicly observable domain protection

Risk register

Prioritized findings

Searchable evidence, business context, remediation steps, ownership, and target SLA.

Control improvement plan

30-day remediation roadmap

Sequenced by containment value, operational effort, and implementation dependency.

Manual scans are limited to once every 10 minutes.
Recommended operating rhythm

Resolve the identity baseline first, then validate application ownership in batches. Record accepted risks and verify closure on the next daily scan.

Suggested success measures

What good looks like after the first improvement cycle

Identity

Identity baseline enforced

Security Defaults on Free tenants, or Conditional Access policies on P1/P2, protect administrators and users.

Applications

100% ownership assigned

Every high-impact OAuth grant has a documented owner and purpose.

Posture

Secure Score ≥ 60%

Initial improvement target using low-disruption controls.

Operations

Zero overdue critical risks

Daily scan validates closure and detects regression.

Tenant inventory

Protected environment

A concise view of the identities, roles, applications, grants, and domains in scope.

Active privileged roles

Click any role to view its current users and directory objects

Directory roleMembersReview

Verified domains

Authentication and tenant-default status

DomainAuthStatus
Microsoft Graph license query

Tenant subscriptions and user assignments

Microsoft product names, seat totals, and product assignments by licensed user. Graph SKU codes are shown in smaller text for reference.

Tenant entitlement

  • Subscription inventory is tenant-wide
  • Product names use Microsoft's licensing reference

User assignments

Assigned identity licence coverage

How to read this

Entitlement is not the same as assignment

  • A purchased product may have unassigned seats
  • User rows show the products actually assigned
  • Disabled service plans are excluded

Subscribed products

Purchased, assigned, and available seats reported by Graph subscribedSkUs

ProductEntra entitlementStatusPurchasedAssignedAvailable

Licensed users

Product assignments returned by Microsoft Graph

UserAccountLicences
Microsoft service DNS only

DNS health dashboard

Monitors only DNS records that connect this tenant to Microsoft 365 services. Website hosting, nameservers, and other third-party DNS are outside Surface Guard's responsibility.

Manual scans are limited to once every 10 minutes.

Microsoft DNS service health

Change detection and resolver agreement for Exchange Online, Entra ID, Intune, and Teams records

Microsoft service records

Green OK means the Microsoft endpoint matches the protected baseline and agrees across public resolvers

Monitoring assurance

Collection health

Connection status, evidence sources, and current monitoring boundaries.

Current boundaries

Important context when interpreting this assessment

Read-only by design

No account, email, application, or policy changes can be executed by this connector.

License-aware scope

Evidence timing

Posture data is collected daily; public DNS and web observations represent scan time.

Human validation

Application findings require an owner and usage check before consent or credentials are removed.