Pillar 4 Β· SaaS and cloud posture

SaaS Posture

Continuous monitoring for Microsoft 365, Google Workspace and AWS. Identities, mail, data leakage, third-party apps and cloud posture with scoring, remediation and auditable evidence.

Identities β€” identity and access governance

MFA Coverage & method ranking

% of users with MFA registered and enforced, with a per-user ranking of the strongest method (fido2 > Windows Hello > Authenticator > SMS > password).

Conditional Access benchmark

Conditional access policy coverage per app against Microsoft's baseline, with real license gating and no false not-applicable.

PIM Benchmark

Privileged roles with just-in-time activation vs. permanent assignment. Requires Entra ID P2, auto-detected.

Access Reviews

Visibility into your periodic access recertification process (SOC2 CC6.1 / ISO 27001 A.9.2.5), not just the point-in-time risk.

Licenses & Users

Assigned SKUs vs. actual usage, orphaned accounts and licensing waste in one panel.

Mail β€” Exchange Online hardening

Inbox Rules & external forwarding

Rules that auto-forward to external addresses or delete messages without user intervention β€” a classic silent post-compromise vector.

Content & Malware Filter Policy

Anti-spam/phishing/bulk actions, real quarantine, zero-hour ZAP and bulk mail threshold.

ATP Policy + Defender for O365

Safe Attachments/Links, Spoof & Mailbox Intelligence and Safe Documents measured against your real license.

Mailbox/OWA hardening

Calendar sharing policy, third-party storage providers in OWA and add-in auto-install.

Org config & Connectors policy

Organizational configuration and mail flow connectors with direct impact on Secure Score.

DLP & Apps β€” data leakage and third-party risk

DLP + Teams scope

At least one DLP policy enforced, and confirming enforcement reaches Teams chat/channels, not only Exchange/SharePoint/OneDrive.

Sharing & External Shares

Resources shared with anyone with the link or external domains, with visibility that native suites don't surface in a simple way.

Sensitivity Labels (Purview)

Labels created and actually published to users/groups.

OAuth Apps & Admin Consent

Apps with consent, scopes ranked by risk, dormant apps flagged for revoke, and the admin consent policy.

Shadow IT & AI Agents UNIQUE

Unsanctioned SaaS and governance of AI agents connected to your tenant.

Secure Score & Remediation

Microsoft Secure Score integrated UNIQUE

~44 new controls measured with no additional permissions, audited control-by-control against Microsoft's real documentation.

A-F scoring per sub-domain

Identities, apps, mail, data leakage and compliance with 0-100 score and A-F grade.

1-click remediation with SIEM audit UNIQUE

Revoke an OAuth app, disable a suspicious inbox rule, or remove an external share β€” all audited and pushed to your SIEM.

Compliance trending

Score evolution over time to show real posture improvement, not just today's snapshot.

Mailbox audit trail

Mailbox auditing to investigate access and interaction with sensitive content after the fact.

CSPM AWS β€” multi-account cloud posture

Secure cross-account connection

Each AWS account connects via AssumeRole + external ID, with no shared users or permanent access keys.

S3 and data encryption

Detects public buckets and unencrypted EBS/RDS resources before they become an exposure or compliance gap.

Exposed Security Groups

Identifies sensitive ports open to the Internet and prioritizes findings by severity.

IAM, MFA and privileges

Users without MFA, stale keys and wildcard policies visible in one actionable inventory.

CloudTrail and GuardDuty

Confirms audit logging and managed detection are active on every connected account.