What happens next

A short setup flow, then your first security baseline.

You'll sign in with Microsoft, approve a one-time read-only consent flow, and land in a completed assessment — not another empty setup screen.

The goal is simple: get you from first click to a usable Microsoft 365 risk picture in under five minutes.

Estimated time
Under 5 minutes
Access model
Microsoft Graph, read-only
Who approves
A Global Administrator
Setup preview
Onboarding flowStep 1 of 3
You authenticate first. Consent and the assessment follow inside the product.
01

Sign in with Microsoft

Use your Microsoft 365 work account so we can identify the tenant and put you into the correct onboarding flow.

Usually 10–15 seconds
02

Approve read-only admin consent

A Global Administrator reviews the requested Microsoft Graph permissions and approves one-time read access.

Required once per tenant
03

Run the first assessment

TenantVigil reads configuration across Entra ID, Exchange, SharePoint, Teams, Defender, and Intune to build the initial posture baseline.

Typically 30–60 seconds
04

Open the dashboard

You arrive with prioritized findings, framework mappings, remediation guidance, and change history ready to review.

Available immediately
Generic product view

This uses mocked product data only. No customer names, tenant identifiers, or live findings are shown here.

app.tenantvigil.com

Overview

Acme Corp · 38 controls · Assessed just now

Security posture

Core Microsoft 365 baseline

84Posture / 100
Strong5 pts

Strong identity posture with a few high-impact collaboration gaps to fix next.

Fix next

Highest-impact issues first

Passing28
Failing6
Warnings4
Accepted risk2

Protection by area

Tap any area to see what's working and what isn't

Compliance

Framework mapping for audits and questionnaires

Frameworks
8
Accepted risk
2
Unavailable
3

Recent changes

Settings that changed since the previous scan

Conditional Access emergency-access policy changed
Anonymous sharing became more permissive
Safe Links preset is no longer enforced
Security and privacy expectations
Read-only onboarding. TenantVigil does not change settings during setup.
No agents, scripts, or mailbox-side installs required.
Requested access is visible in Microsoft before consent is granted.
Results are mapped to CIS, CISA SCuBA, SOC 2, and ISO 27001-oriented workflows.
Best way to prepare

Have a Global Administrator available for the Microsoft consent step.

If you want continuous monitoring later, start with the same onboarding path — you can upgrade after the initial assessment.

Once the scan finishes, you'll go directly into the dashboard with findings already populated.