Run 40+ automated checks across Microsoft Entra ID, Conditional Access, Microsoft Entra roles, authentication methods, Microsoft Intune, enterprise applications, and Microsoft Secure Score. Sign in with a work or school account that has the required administrator roles. Tenant results are processed in your browser and are not sent to TenantShield.
40+ security checks
7 control categories
0 tenant results sent to TenantShield
Delegated, read-only Microsoft Graph permissions
Identity
Security defaults, Microsoft Entra MFA registration, legacy authentication, guest users, self-service password reset (SSPR), and user consent settings
Conditional Access
Policies, multifactor authentication, user and sign-in risk, compliant devices, and named locations
Privileged access
Global Administrator assignments, privileged roles, and active versus eligible assignments
Authentication methods
Passkeys (FIDO2), Microsoft Authenticator, Temporary Access Pass, and SMS or voice methods
Devices & Microsoft Intune
Compliance policies, configuration profiles, enrollment, device compliance, encryption, and stale devices
Microsoft Secure Score, risky users, risky sign-ins, Microsoft Defender XDR alerts, and licensing
Requires a Global Administrator (or Privileged Role Administrator) to approve the read-only permissions the first time. Not an admin? Try the no-sign-in external scan or view a sample assessment. Tenant results are not sent to TenantShield. Standard technical request data and optional privacy-safe analytics are described in the Privacy Notice.
Running security checks…
Querying Microsoft Graph API in real time
0 / 0 checks0%
Microsoft 365 security checker results
—
Directional check result
Need an analyst-reviewed next step?
This self-service checker reviews 40+ signals in your browser. The paid Microsoft 365 Security Assessment adds analyst validation, executive and technical reporting, a prioritized action register, and a stakeholder readout. Implementation is scoped separately.