MFA Coverage & method ranking
% of users with MFA registered and enforced, with a per-user ranking of the strongest method (fido2 > Windows Hello > Authenticator > SMS > password).
Pillar 4 Β· SaaS and cloud posture
Continuous monitoring for Microsoft 365, Google Workspace and AWS. Identities, mail, data leakage, third-party apps and cloud posture with scoring, remediation and auditable evidence.
% of users with MFA registered and enforced, with a per-user ranking of the strongest method (fido2 > Windows Hello > Authenticator > SMS > password).
Conditional access policy coverage per app against Microsoft's baseline, with real license gating and no false not-applicable.
Privileged roles with just-in-time activation vs. permanent assignment. Requires Entra ID P2, auto-detected.
Visibility into your periodic access recertification process (SOC2 CC6.1 / ISO 27001 A.9.2.5), not just the point-in-time risk.
Assigned SKUs vs. actual usage, orphaned accounts and licensing waste in one panel.
Rules that auto-forward to external addresses or delete messages without user intervention β a classic silent post-compromise vector.
Anti-spam/phishing/bulk actions, real quarantine, zero-hour ZAP and bulk mail threshold.
Safe Attachments/Links, Spoof & Mailbox Intelligence and Safe Documents measured against your real license.
Calendar sharing policy, third-party storage providers in OWA and add-in auto-install.
Organizational configuration and mail flow connectors with direct impact on Secure Score.
At least one DLP policy enforced, and confirming enforcement reaches Teams chat/channels, not only Exchange/SharePoint/OneDrive.
Resources shared with anyone with the link or external domains, with visibility that native suites don't surface in a simple way.
Labels created and actually published to users/groups.
Apps with consent, scopes ranked by risk, dormant apps flagged for revoke, and the admin consent policy.
Unsanctioned SaaS and governance of AI agents connected to your tenant.
~44 new controls measured with no additional permissions, audited control-by-control against Microsoft's real documentation.
Identities, apps, mail, data leakage and compliance with 0-100 score and A-F grade.
Revoke an OAuth app, disable a suspicious inbox rule, or remove an external share β all audited and pushed to your SIEM.
Score evolution over time to show real posture improvement, not just today's snapshot.
Mailbox auditing to investigate access and interaction with sensitive content after the fact.
Each AWS account connects via AssumeRole + external ID, with no shared users or permanent access keys.
Detects public buckets and unencrypted EBS/RDS resources before they become an exposure or compliance gap.
Identifies sensitive ports open to the Internet and prioritizes findings by severity.
Users without MFA, stale keys and wildcard policies visible in one actionable inventory.
Confirms audit logging and managed detection are active on every connected account.