Establish applicability
Confirm licenses, enabled services, tenant relationships, business requirements, known exceptions, and assessment boundaries.
TenantShield combines a structured Microsoft 365 control library, collected evidence, analyst validation, and business context to produce priorities—not just check results.
Confirm licenses, enabled services, tenant relationships, business requirements, known exceptions, and assessment boundaries.
Collect and review the configuration and operational evidence available for each applicable control.
Check material observations against compensating controls, dependencies, stakeholder intent, and evidence quality.
Consider likely impact, exposure, exploitability, breadth, business dependency, change risk, and effort.
Connect each priority to evidence, an accountable owner, recommended action, dependency, and validation step.
The library contains more than 400 controls, but a larger raw count is not the objective. Applicability and evidence quality are recorded so excluded controls do not distort the result.
Microsoft Entra authentication, Conditional Access, privileged roles, guest users, and user and sign-in risk.
Exchange Online, built-in security features for cloud mailboxes, Microsoft Defender for Office 365 where licensed, mail flow, auditing, forwarding, and email authentication.
Microsoft Teams, SharePoint Online, OneDrive, sharing, guest users, and governance settings.
Consent, permissions, enterprise applications, and service principals.
Microsoft Intune device management, configuration, and compliance signals where applicable.
Relevant Microsoft Purview retention, sensitivity labeling, and data loss prevention controls where licensed.
Microsoft Defender XDR alerts where licensed, audit availability, logging, and investigation readiness.
Ownership, exception handling, access lifecycle, change control, and evidence of review.
Maester can turn Microsoft security guidance and customer policy into repeatable PowerShell/Pester tests using Microsoft Graph and supported service modules. TenantShield can use that output alongside direct configuration review, operational records, stakeholder evidence, and other approved sources.
Confirm the services, permissions, identities, test packages, execution location, output handling, and exclusions before connection.
Record the Maester and test versions, selected suites, timestamps, skipped tests, errors, and exported evidence needed for repeatability.
Check applicability, licensing, configuration state, policy intent, exceptions, compensating controls, duplicates, and evidence confidence.
Use analyst judgment to determine severity, business impact, recommendation, ownership, sequence, and validation—not the raw test status alone.
Read Maester's installation and execution documentation or inspect the MIT-licensed source repository.
A recommendation is prioritized using the evidence available at the time of review and the organization’s context.
| Factor | Question |
|---|---|
| Impact | What could happen to identities, data, operations, customers, or regulatory obligations? |
| Exposure | How broadly is the condition exposed, and which users, administrators, data, or workloads are affected? |
| Likelihood | How plausible is misuse or failure given current controls and common attack paths? |
| Compensation | Do other technical or operational controls materially reduce the risk? |
| Change risk | What user impact, dependency, or service disruption could remediation create? |
| Evidence confidence | Is the conclusion supported directly, partially, or dependent on stakeholder confirmation? |
TenantShield uses Microsoft’s current names for the services and signals being evaluated. Microsoft Secure Score is referenced as a Microsoft posture measurement; it is not relabeled as a TenantShield grade.
The sample report shows how evidence, context, priority, and action are connected.