Evaluated controls only.
This is how GraphSec presents a Microsoft 365 tenant assessment.
All names, values and results are fictional. The generated report may change technically, in content and visually with future product versions.
This page demonstrates the intended structure and user experience.
Contoso GmbH
Tenant: contoso.onmicrosoft.com · Scan time: 4 August 2026, 18:42
8 controls require further evidence.
Privileged access is the primary technical risk.
Two administrative accounts are outside the intended strong-authentication policy. External sharing and legacy-protocol exceptions also require remediation.
Protect admin accounts: review and remove policy exclusions.
Restrict external sharing: disable anonymous links on sensitive sites.
Close coverage gaps: obtain the required Intune and risk data.
IAM-01Strong authentication for privileged accounts
Two of seven privileged accounts are outside effective policy coverage.
Show evidence and recommendation
Policy: Require-Phishing-Resistant-MFA
Excluded accounts: 2Review justified exceptions and remove unnecessary exclusions.
COL-01External sharing in SharePoint and OneDrive
Anonymous links remain available on two sensitive sites.
MAIL-02Enforced secure mail transport
The assessed partner domains use appropriate TLS transport rules.
DEV-02Device compliance in Microsoft Intune
The required Intune data source was not available.
No control matches the selected filter.
A control that was not tested is neither passed nor failed. The report records the reason and next step.
| ID | Control | Status | Reason | Next step |
|---|---|---|---|---|
DEV-02 | Intune compliance | Licence missing | Intune data source not licensed. | Review licensing and repeat. |
IAM-09 | Risky users | Permission missing | Required Graph permission unavailable. | Review admin consent. |
RES-01 | Backup and recovery | Manual evidence | Restore test is outside the tenant. | Attach test evidence. |
Status, coverage and evidence are presented separately.
This shows whether a control passed, failed or could not be evaluated due to missing data.
The defined criterion is met.
An exception or incomplete evidence requires review.
The technical criterion is not met.
A licence, permission or external document is missing.
Compare the three licence plans and usage rights.