SeQontrol and Microsoft's native tooling
Secure Score, Purview and SharePoint Advanced Management already ship with your licence. Here is what they cover, and the specific gaps that made this worth building.
When native is enough
One tenant, one administrator, no external reporting obligation and no Copilot rollout pending: Secure Score plus the native reports will tell you most of what you need, and they cost nothing extra. Start there. A tool you already own and will actually check beats one you buy and ignore.
The four gaps
- One number, not a control. Secure Score gives a figure per tenant. It does not tell an auditor which control held, or produce evidence that it held over a period.
- Per workload, per tenant. Sharing sits in one report, identity in another, mail flow in a third — and none of them span the clients a provider manages.
- No outside-in view. Nothing native scans your public web and domain surface, which is where a good deal of exposure actually lives — that is WebScan, and running it costs nothing.
- Reporting, not remediation, and no memory. Native reports show a state. They do not stage a fix with a grace window and an undo, and they do not keep a tamper-evident record of what changed and who approved it.
The honest overlap
Microsoft improves this surface constantly, and some of what SeQontrol does today will be native eventually. The parts we expect to keep mattering are the ones native tooling is structurally unlikely to build: cross-tenant fleet economics, and turning a security finding into portable compliance evidence.
We license per estate, so if Microsoft ships something that replaces a piece of this, you are free to stop paying for that piece.