Microsoft 365 security assessment
Microsoft 365 security posture, made clear.
Understand your Microsoft 365 security posture through structured assessments, prioritized findings, measurable coverage and reporting you can act on.
Secure Microsoft Entra sign in. ScopePoint assesses configuration, not your emails, Teams conversations or files.
Why ScopePoint
From tenant configuration to a posture you can act on
Microsoft 365 already holds the settings that decide your security posture. ScopePoint reads them, scores what it finds, and shows how much it was able to assess.
Visibility
See your Microsoft 365 security posture in one view: the score, the coverage behind it, and the findings that produced it.
Prioritization
Know what to fix first. Findings are organized by severity and security category, each with the evidence behind it.
Evidence
Turn every assessment into a clear record you can review, track over time and share.
Features
From assessment to actionable security insight.
Run the assessment, understand the result, and take the evidence with you.
Security assessments
Run structured checks across supported Microsoft 365 security areas, from a versioned assessment catalog.
Posture scoring
One score out of 100, from a published formula weighted by severity. The same findings always produce the same score.
Coverage
See how much of the supported scope was actually evaluated, reported separately from the score. A check that could not run is never counted as a pass.
Findings and recommendations
Understand what needs attention, why it matters, and what to do about it.
Assessment history
Every run is kept, so posture and findings can be compared over time.
Professional reporting
Turn an assessment into PDF, CSV or JSON output for review, tracking and sharing.
How it works
Five steps from sign in to a shareable report
No agent to deploy and nothing to install in your tenant.
- 1
Sign in
Authenticate with your Microsoft work account.
- 2
Connect Microsoft 365
An administrator approves the read only access ScopePoint needs.
- 3
Run an assessment
ScopePoint evaluates your tenant configuration against its check catalog.
- 4
Review posture and findings
Read the score with its coverage, then work through findings by severity.
- 5
Export or share
Generate a PDF, CSV or JSON report.
Security and privacy
Know exactly what ScopePoint can access, and what it cannot access.
ScopePoint reads configuration in order to assess it. Here is what that means.
Microsoft Entra authentication
Sign in is handled by Microsoft. ScopePoint never sees or stores your password.
Read only access
ScopePoint requests Microsoft Graph permissions that can only read, covering organization details, users, application registrations and directory role assignments. None of them can write to your tenant.
Configuration, not content
Assessments read tenant configuration and security metadata. ScopePoint does not collect mailbox content, Teams messages, or files in SharePoint or OneDrive.
No automatic remediation
ScopePoint assesses and reports. It does not make configuration changes in your Microsoft 365 tenant.
Tenant isolation
Results are scoped to your organization and its connected tenants, and every request is authorized against it.
Evidence kept minimal
Findings record only what is needed to explain them. Raw Microsoft Graph responses are never stored, and access tokens never reach a log or a report.
Reporting
Turn assessment results into evidence you can share.
Every report is a snapshot of one assessment, recording the score and the coverage it was measured at.
What a report contains
- Security posture score
- Coverage of the assessed scope
- Summary for management
- Findings by severity
- Breakdown per category
- Recommended actions
- Assessment context and timestamps
Three formats
- For review and sharing.
- CSV
- For spreadsheet analysis and tracking.
- JSON
- For use by another system.
Who it is for
Built for teams responsible for Microsoft 365 security.
Anyone accountable for a Microsoft 365 environment, whether that is one tenant or several.
Internal IT teams
A clear view of the environment you already run, without assembling it by hand.
Microsoft 365 administrators
What is configured, what it scores, and how much was assessed.
Security teams and consultants
A repeatable assessment to take into a review, with evidence attached.
Managed service providers
Consistent reporting across every tenant you look after.
Small and medium sized organizations
Understand your security posture without running a security programme.
FAQ
Questions people ask before connecting a tenant
Mostly about access. Fair questions to ask of a security product.
What is ScopePoint?
A Microsoft 365 security assessment platform. It reads the configuration of a connected tenant, evaluates it against a versioned catalog of security checks, and reports a posture score, the coverage that score was measured at, and the findings behind it.
What does ScopePoint assess?
Three areas today: identity, such as guest and disabled accounts; privileged access, such as directory role assignments; and application registrations, including applications without an owner and credentials that have expired or are about to expire. The catalog is versioned, and every finding records the check that produced it.
Does ScopePoint change settings in my Microsoft 365 tenant?
No. ScopePoint holds permissions that can only read, and it has no remediation feature. It reports what it finds; acting on a finding is something you do in Microsoft 365 yourself.
What Microsoft permissions does ScopePoint require?
Four Microsoft Graph application permissions, all of which can only read:
Organization.Read.AllUser.Read.AllApplication.Read.AllRoleManagement.Read.Directory
Each one is the least privileged option for the data the assessment needs, and an administrator grants them explicitly through Microsoft's consent screen. None of them permits writing to your tenant.
Does ScopePoint read my emails?
No. ScopePoint holds no mail permission and collects no mailbox content.
Does ScopePoint read Teams conversations?
No. ScopePoint holds no Teams permission and collects no message content.
Does ScopePoint read files in SharePoint or OneDrive?
No. ScopePoint holds no file permission and does not inspect file contents.
What is the difference between the posture score and coverage?
The score describes the checks that completed. Coverage says how many that was. They are reported separately on purpose: if part of an assessment could not run, the score is not a statement about your whole tenant, and a category nobody assessed is shown as not assessed rather than as a pass.
Can I disconnect my tenant?
Yes, at any time. Disconnecting stops ScopePoint using the connection, while your assessment history and reports remain available. You can connect the same tenant again later. Removing the enterprise application from Microsoft 365 is a separate step you perform in Microsoft's portal, and ScopePoint tells you where.
Which report formats are supported?
PDF for review and sharing, CSV for spreadsheets and tracking, and JSON for another system to consume. A report can also be generated again when you need a fresh copy; the score and coverage it records stay exactly as they were assessed.
Does ScopePoint support multiple Microsoft 365 tenants?
Yes. An organization in ScopePoint can connect more than one Microsoft 365 tenant, and each is assessed and reported separately. A given Microsoft 365 tenant can be connected to one ScopePoint organization at a time; connecting it elsewhere requires disconnecting it first.
See your Microsoft 365 security posture clearly.
Connect your environment, run an assessment, and turn security findings into a clear posture overview.
Sign in with your Microsoft work account. Connecting a tenant requires administrator consent.