"We already track our secure score."
That is one number, for one tenant. Can you show a control-level gap, the tier it is blocking, and the evidence an auditor would accept, across thirty clients, from one screen?
SecurityPortal checks the identity and configuration posture of the Microsoft 365 and Entra estate — then tags every finding so it becomes control evidence downstream instead of another dashboard nobody exports. For the public side of the same organisation, see WebScan.
A native secure score is one number per tenant. It is not mapped to the frameworks your clients and auditors cite, it is partly licensing-gated, and it has no concept of a provider managing forty tenants. It also stops at the boundary of the tenant, which is not where your risk stops — WebScan covers the public side, and both file their findings in the same place.
Regulatory regimes increasingly expect demonstrable, continuous controls. An annual penetration test and a bare score no longer satisfy a client questionnaire, let alone an auditor.
SecurityPortal assesses and evidences; it does not remediate. Fixing lives in the products built to write safely — ShareCare for sharing and permissions, MailTrust for DNS, and Dredd for approved configuration once it lands. Guided remediation for the highest-value posture gaps is roadmap, not a shipped claim.
The log-analytics checks depend on the customer actually exporting activity logs. Where that export does not exist, the check degrades honestly to "not assessed" — it never quietly reports a pass it could not verify.
The screens you will actually work in.
Not a single score. A ladder you climb by fixing things, checks tagged to the controls they satisfy, and an explicit count of what could not be assessed at all.



Everything on this page is inside the tenant. The public side — asset discovery, TLS, headers, cookies, DNS, exposed services and infrastructure — is WebScan, which is free to run and files its findings in the same store, with the same control tags.
| Capability | What it means for you |
|---|---|
| Conditional Access, MFA and application-permission posture | The controls auditors and clients actually ask about |
| Log-analytics query checks | Evidence a native score cannot produce — truly unused permissions, real MFA source |
| Not-assessed counted separately from pass and fail | A check that could not run never becomes a quiet pass |
| Control-reference tags on every finding | Posture becomes compliance evidence with no second integration |
| Fleet-wide, agentless | Run it across the whole book without touching an endpoint |
That is one number, for one tenant. Can you show a control-level gap, the tier it is blocking, and the evidence an auditor would accept, across thirty clients, from one screen?
Ours carries control mappings and structured evidence, and it feeds a real evidence workflow rather than producing a static PDF that ages badly.
No. It assesses and evidences. Remediation lives in the products designed to write safely, and we are explicit about which plane can do what.
Most do not combine Microsoft 365 identity posture, fleet economics and compliance evidence output in one place — nor sit beside a scanner for the public surface that files into the same store.
The usual opener: a posture assessment across your worst tenants, every finding mapped to a control — and a free WebScan of your public sites while we are there.