SaaS Posture Β· M365 Policies

M365 Policies

Connectors, organizational configuration, sharing, DLP and Defender for Office 365 evaluated with 0-100 scoring and specific remediation per finding β€” without having to review every policy by hand in the Admin Center.

Capabilities

Connectors Policy

Detects inbound connectors that allow spoofing your own internal domain, and verifies partner connections enforce TLS β€” a misconfigured mail connector is a backdoor for BEC.

Org Config Policy

Modern Auth (OAuth2) enabled, MailTips for externals, and Customer Lockbox β€” organizational configuration affecting the whole tenant from a single misconfigured setting.

Sharing Policy (SharePoint/OneDrive)

6 checks: non-permissive sharing capability, legacy auth disabled, external resharing blocked, idle session sign-out, sync restricted to managed devices, and allowed external domains.

DLP Policy

Verifies at least one active data loss prevention policy exists (not just test mode) and that enforcement also reaches Teams, not only Exchange/SharePoint/OneDrive.

Defender for Office 365 UNIQUE

11 checks on Anti-Phish, Safe Links and Safe Attachments β€” spoof intelligence, protected domains/users, phishing threshold level, and real malicious attachment blocking (not just a warning).