Posture scanning · one of three

Inside the tenant, scored continuously

SecurityPortal checks the identity and configuration posture of the Microsoft 365 and Entra estate — then tags every finding so it becomes control evidence downstream instead of another dashboard nobody exports. For the public side of the same organisation, see WebScan.

In one line: continuous posture across your whole client book, arriving as evidence rather than as a chart.

Why it matters

A native secure score is one number per tenant. It is not mapped to the frameworks your clients and auditors cite, it is partly licensing-gated, and it has no concept of a provider managing forty tenants. It also stops at the boundary of the tenant, which is not where your risk stops — WebScan covers the public side, and both file their findings in the same place.

Regulatory regimes increasingly expect demonstrable, continuous controls. An annual penetration test and a bare score no longer satisfy a client questionnaire, let alone an auditor.

What it does

  • Identity and configuration posture — Conditional Access coverage, MFA enforcement including report-only and exclusion gaps, secure-configuration signals, and genuine over-permissioned-application detection.
  • Log analytics checks — where the tenant exports activity logs, SecurityPortal runs query-based checks that a native score cannot produce: high-privilege application permissions that are genuinely unused, and per-user MFA usage as actually observed.
  • Control-tagged findings — each finding carries control references and a structured evidence table, so it flows into CompliancePortal as first-party evidence rather than being re-collected by hand.
  • Fleet-wide and scan-only — no agents, no write path, built to run across every tenant you manage.

Scan-only, on purpose

SecurityPortal assesses and evidences; it does not remediate. Fixing lives in the products built to write safely — ShareCare for sharing and permissions, MailTrust for DNS, and Dredd for approved configuration once it lands. Guided remediation for the highest-value posture gaps is roadmap, not a shipped claim.

When the data is not there, we say so

The log-analytics checks depend on the customer actually exporting activity logs. Where that export does not exist, the check degrades honestly to "not assessed" — it never quietly reports a pass it could not verify.

Inside SecurityPortal

What’s in the product

The screens you will actually work in.

Posture you can argue with

Not a single score. A ladder you climb by fixing things, checks tagged to the controls they satisfy, and an explicit count of what could not be assessed at all.

The posture ladder: Blind and Assessed both ticked, Critical clear current with no
                    Critical failing, High clear still greyed out, and coverage at 56 per cent.
Four tiers, and you can only be on one of them. A percentage lets everyone pick the reading they prefer. A tier does not.
  1. Where the whole estate stands — one domain of five has reached the top tier, so that is what the tenant is, whatever the average says.
  2. The tier you are on, and why. Not “good”: no Critical failing. The condition is written next to the claim.
  3. The one above it, and its price. Greyed until nothing High is failing — a target with a definition, not a nudge.
Tiers are earned by scan evidence only: waiving a finding moves nothing here. That is security above compliance, enforced rather than asserted.
Three checks in a row: app registrations holding excessive application permissions
                    marked Fail and High, apps retaining high-risk permissions marked Not assessed and
                    Medium, and Global Administrator count within limit marked Pass — each tagged with
                    its control reference.
Three states, and the middle one is the honest one. Every check carries the control reference that lets the same finding become compliance evidence without anyone re-collecting it.
  1. Fail, with how many objects are affected — so you know whether this is an afternoon or a project before you open it.
  2. Not assessed. We could not read what this check needs. It is not a pass, it is not a fail, and it is counted separately so it can never quietly become either.
  3. Pass, still carrying its references. The evidence for a control is the check that proved it, not a screenshot someone took in March.
Category rows for authentication and identity, devices, data protection, apps and
                    collaboration, and email and messaging — each with a pass, warning and fail split
                    and a separate count of critical or high failures and unassessed checks.
Grouped the way you would fix it — by area, worst first, with the unassessed count kept next to the failures rather than buried under them.
  1. Two numbers, not one. What is failing at Critical or High, and what was never assessed. A row can be quiet because it is clean or because nobody could look.
  2. A row that is entirely unassessed says so. Nothing failing, nothing passing, ten checks unread — which is a licensing conversation, not a security win.

The outside half lives next door

Everything on this page is inside the tenant. The public side — asset discovery, TLS, headers, cookies, DNS, exposed services and infrastructure — is WebScan, which is free to run and files its findings in the same store, with the same control tags.

Capability and what you get from it

CapabilityWhat it means for you
Conditional Access, MFA and application-permission postureThe controls auditors and clients actually ask about
Log-analytics query checksEvidence a native score cannot produce — truly unused permissions, real MFA source
Not-assessed counted separately from pass and failA check that could not run never becomes a quiet pass
Control-reference tags on every findingPosture becomes compliance evidence with no second integration
Fleet-wide, agentlessRun it across the whole book without touching an endpoint

Objections, answered straight

"We already track our secure score."

That is one number, for one tenant. Can you show a control-level gap, the tier it is blocking, and the evidence an auditor would accept, across thirty clients, from one screen?

"Isn't posture just a checklist?"

Ours carries control mappings and structured evidence, and it feeds a real evidence workflow rather than producing a static PDF that ages badly.

"Does it remediate?"

No. It assesses and evidences. Remediation lives in the products designed to write safely, and we are explicit about which plane can do what.

"Why not a general cloud posture tool?"

Most do not combine Microsoft 365 identity posture, fleet economics and compliance evidence output in one place — nor sit beside a scanner for the public surface that files into the same store.

Get the gap report first

The usual opener: a posture assessment across your worst tenants, every finding mapped to a control — and a free WebScan of your public sites while we are there.