See the six ways attackers break into Microsoft 365 — and prove you're protected.
See the six ways attackers break into Microsoft 365— and prove you’re protected.
90+ read-only checks in about two minutes, scored against the six most common attacks on small businesses — with the evidence a cyber-insurer or auditor will accept. No agents. No credit card.
Read-only Graph access · No agents · ~2-minute scan

Six ways in. A checklist to shut each one down.
Every finding maps to one of the six ways real businesses get breached — and every missing protection becomes a box you can tick: plain English, ranked by impact, satisfying to finish.
Account Takeover
Someone gains access to an employee or admin account.
Ransomware Readiness
Your systems get encrypted and you can't operate.
Email Fraud & Phishing
Staff receive fake emails, or criminals impersonate your business.
Data Theft & Leakage
Company or customer data leaves the organization.
Unauthorized External Access
Someone gets into your systems from outside.
Admin & Insider Risk
Someone with admin access does something harmful.
One scan, seven frameworks
Every assessment automatically maps findings to the frameworks your auditors, board, and cyber-insurance renewal ask about — each with the exportable evidence behind it.
Start free, scale as you grow
No credit card required for the free tier. Upgrade when you need continuous monitoring and compliance reporting.
TenantVigil Business adds full reporting, scheduled scans, drift detection, and on-demand individual control refreshes with control-level history. MSP Provider manages up to 10 client tenants from one console.
Free
Baseline Microsoft 365 assessment for a single tenant.
- 1 full Microsoft 365 assessment per month
- CIS & CISA SCuBA benchmark coverage
- Security score with top 5 findings
- Manual remediation guidance
- No full report or PDF export
- No scheduled scans
- Community support
Business
Continuous monitoring, full reporting, and control-level change management. Billed monthly or annually.
- Everything in Free, plus:
- Full executive & technical PDF reports
- Compliance framework mapping
- Scheduled scans with drift monitoring
- Individual control refreshes
- Control-level change history
- Drift alerts (email, Slack, Teams)
- Historical trend analysis
- Priority email support
Microsoft 365 security, answered
The most common questions about running a free Microsoft 365 security assessment, read-only permissions, and framework coverage.
How do I check my Microsoft 365 security posture?
Connect your tenant with Microsoft's consent screen and TenantVigil runs a free, read-only assessment of 90+ security controls across the six core Microsoft 365 services. In about two minutes you get prioritized findings, severity ratings, and step-by-step remediation — no agents to install.
Is the TenantVigil Microsoft 365 security assessment really free?
Yes. The assessment is free and needs no credit card. The Free plan gives you the full read-only scan and report; the Business and MSP Provider plans add continuous monitoring, configuration drift detection, scheduled reporting, and multi-tenant management.
Is TenantVigil read-only, and what Microsoft 365 permissions does it need?
It is 100% read-only. TenantVigil requests read-only Microsoft Graph scopes (such as Organization.Read.All, Policy.Read.All, and SecurityEvents.Read.All) and never modifies your tenant. Remediation stays in your hands — the platform shows you exactly what to change and how.
What is CISA SCuBA and does TenantVigil check it?
CISA SCuBA (Secure Cloud Business Applications) is the U.S. government's security baseline for Microsoft 365. TenantVigil maps assessment findings directly to SCuBA controls — including the MS.AAD identity baseline — alongside CIS, NIS2, HIPAA, ISO 27001, SOC 2, and GDPR.
Which Microsoft 365 services does TenantVigil scan?
All six core services: Entra ID (Azure AD), Exchange Online, SharePoint and OneDrive, Microsoft Defender, Teams, and Intune. The checks span identity and MFA, mail transport, external sharing, device compliance, and threat protection.
How long does a Microsoft 365 security assessment take?
About two minutes. The scan is fully automated — no agents, no installs, and no changes to your environment. You grant read-only consent and results appear as soon as the checks complete.
Which compliance frameworks does one scan map to?
A single assessment maps to seven frameworks — CIS Benchmark v6.0, CISA SCuBA, SOC 2, ISO 27001, HIPAA, NIS2, and GDPR — each with exportable, audit-grade evidence behind every control.
Can MSPs use TenantVigil across multiple client tenants?
Yes. The MSP Provider plan adds a multi-tenant console to assess, monitor for drift, and report across every managed Microsoft 365 tenant from one place, so a whole client portfolio stays covered.
Still deciding? Run a free assessment or talk to us.
Your free security assessment is 3 steps away
Connect your Microsoft 365 tenant, run your first scan, and get a full CIS benchmark report with guided remediation — all within 5 minutes. No agents, no scripts, no credit card.
No credit card required · Free tier available forever

