Marketing pages
Standard web requests plus optional analytics after your choice. Contact details are processed only when you submit an inquiry.
TenantShield uses different data flows for the public site, free tools, and paid services. This page explains those differences before you use them.
Standard web requests plus optional analytics after your choice. Contact details are processed only when you submit an inquiry.
The domain you enter is sent to the scan service to evaluate public DNS and email-security records.
Microsoft Graph queries and result processing run in your browser after Microsoft sign-in and consent.
Evidence, access, retention, contacts, and deliverables are defined for the engagement before work begins.
The current Browser Checker requests delegated permissions. Microsoft presents the consent request, and a Microsoft Entra administrator controls whether the delegated permissions are granted.
| Permission | Why the checker requests it |
|---|---|
Directory.Read.All | Read directory objects relevant to tenant posture. |
Policy.Read.All | Read identity and access policy configuration. |
Reports.Read.All | Read supported Microsoft 365 usage and security reports. |
UserAuthenticationMethod.Read.All | Evaluate authentication-method registration coverage. |
Organization.Read.All | Read organization and licensing context. |
SecurityAlert.Read.All | Read supported Microsoft Defender XDR alert signals. |
IdentityRiskyUser.Read.All | Read supported Microsoft Entra ID Protection risky-user signals. |
AuditLog.Read.All | Read directory audit and sign-in signals used by checks. |
DeviceManagementManagedDevices.Read.All | Read managed-device posture where Microsoft Intune is in use. |
DeviceManagementConfiguration.Read.All | Read applicable Microsoft Intune configuration. |
Application.Read.All | Review enterprise applications, service principals, and consent posture. |
When optional analytics are enabled, TenantShield reports only generic product-use milestones—such as whether a check completed—not tenant ID, entered domain, score, finding name, raw evidence, user identity, or access token.
Microsoft Clarity is limited to marketing pages and is excluded from both public tools. The tool pages can use Google Analytics only after the visitor allows optional analytics.
Microsoft Entra admin center experiences and role requirements can change. Follow your organization’s administration process and current Microsoft documentation.
To report a suspected vulnerability or ask about data handling, email jason@tenantshield.io. Do not include access tokens, passwords, private keys, or sensitive tenant exports in the first message.
Automated security-contact details are also published at /.well-known/security.txt.
Ask for the proposed evidence and access plan before deciding whether to proceed.