ScopePoint

Microsoft 365 security assessment

Microsoft 365 security posture, made clear.

Understand your Microsoft 365 security posture through structured assessments, prioritized findings, measurable coverage and reporting you can act on.

Secure Microsoft Entra sign in. ScopePoint assesses configuration, not your emails, Teams conversations or files.

Why ScopePoint

From tenant configuration to a posture you can act on

Microsoft 365 already holds the settings that decide your security posture. ScopePoint reads them, scores what it finds, and shows how much it was able to assess.

Visibility

See your Microsoft 365 security posture in one view: the score, the coverage behind it, and the findings that produced it.

Prioritization

Know what to fix first. Findings are organized by severity and security category, each with the evidence behind it.

Evidence

Turn every assessment into a clear record you can review, track over time and share.

Features

From assessment to actionable security insight.

Run the assessment, understand the result, and take the evidence with you.

Security assessments

Run structured checks across supported Microsoft 365 security areas, from a versioned assessment catalog.

Posture scoring

One score out of 100, from a published formula weighted by severity. The same findings always produce the same score.

Coverage

See how much of the supported scope was actually evaluated, reported separately from the score. A check that could not run is never counted as a pass.

Findings and recommendations

Understand what needs attention, why it matters, and what to do about it.

Assessment history

Every run is kept, so posture and findings can be compared over time.

Professional reporting

Turn an assessment into PDF, CSV or JSON output for review, tracking and sharing.

How it works

Five steps from sign in to a shareable report

No agent to deploy and nothing to install in your tenant.

  1. 1

    Sign in

    Authenticate with your Microsoft work account.

  2. 2

    Connect Microsoft 365

    An administrator approves the read only access ScopePoint needs.

  3. 3

    Run an assessment

    ScopePoint evaluates your tenant configuration against its check catalog.

  4. 4

    Review posture and findings

    Read the score with its coverage, then work through findings by severity.

  5. 5

    Export or share

    Generate a PDF, CSV or JSON report.

Security and privacy

Know exactly what ScopePoint can access, and what it cannot access.

ScopePoint reads configuration in order to assess it. Here is what that means.

Microsoft Entra authentication

Sign in is handled by Microsoft. ScopePoint never sees or stores your password.

Read only access

ScopePoint requests Microsoft Graph permissions that can only read, covering organization details, users, application registrations and directory role assignments. None of them can write to your tenant.

Configuration, not content

Assessments read tenant configuration and security metadata. ScopePoint does not collect mailbox content, Teams messages, or files in SharePoint or OneDrive.

No automatic remediation

ScopePoint assesses and reports. It does not make configuration changes in your Microsoft 365 tenant.

Tenant isolation

Results are scoped to your organization and its connected tenants, and every request is authorized against it.

Evidence kept minimal

Findings record only what is needed to explain them. Raw Microsoft Graph responses are never stored, and access tokens never reach a log or a report.

Reporting

Turn assessment results into evidence you can share.

Every report is a snapshot of one assessment, recording the score and the coverage it was measured at.

What a report contains

  • Security posture score
  • Coverage of the assessed scope
  • Summary for management
  • Findings by severity
  • Breakdown per category
  • Recommended actions
  • Assessment context and timestamps

Three formats

PDF
For review and sharing.
CSV
For spreadsheet analysis and tracking.
JSON
For use by another system.

Who it is for

Built for teams responsible for Microsoft 365 security.

Anyone accountable for a Microsoft 365 environment, whether that is one tenant or several.

Internal IT teams

A clear view of the environment you already run, without assembling it by hand.

Microsoft 365 administrators

What is configured, what it scores, and how much was assessed.

Security teams and consultants

A repeatable assessment to take into a review, with evidence attached.

Managed service providers

Consistent reporting across every tenant you look after.

Small and medium sized organizations

Understand your security posture without running a security programme.

FAQ

Questions people ask before connecting a tenant

Mostly about access. Fair questions to ask of a security product.

What is ScopePoint?

A Microsoft 365 security assessment platform. It reads the configuration of a connected tenant, evaluates it against a versioned catalog of security checks, and reports a posture score, the coverage that score was measured at, and the findings behind it.

What does ScopePoint assess?

Three areas today: identity, such as guest and disabled accounts; privileged access, such as directory role assignments; and application registrations, including applications without an owner and credentials that have expired or are about to expire. The catalog is versioned, and every finding records the check that produced it.

Does ScopePoint change settings in my Microsoft 365 tenant?

No. ScopePoint holds permissions that can only read, and it has no remediation feature. It reports what it finds; acting on a finding is something you do in Microsoft 365 yourself.

What Microsoft permissions does ScopePoint require?

Four Microsoft Graph application permissions, all of which can only read:

  • Organization.Read.All
  • User.Read.All
  • Application.Read.All
  • RoleManagement.Read.Directory

Each one is the least privileged option for the data the assessment needs, and an administrator grants them explicitly through Microsoft's consent screen. None of them permits writing to your tenant.

Does ScopePoint read my emails?

No. ScopePoint holds no mail permission and collects no mailbox content.

Does ScopePoint read Teams conversations?

No. ScopePoint holds no Teams permission and collects no message content.

Does ScopePoint read files in SharePoint or OneDrive?

No. ScopePoint holds no file permission and does not inspect file contents.

What is the difference between the posture score and coverage?

The score describes the checks that completed. Coverage says how many that was. They are reported separately on purpose: if part of an assessment could not run, the score is not a statement about your whole tenant, and a category nobody assessed is shown as not assessed rather than as a pass.

Can I disconnect my tenant?

Yes, at any time. Disconnecting stops ScopePoint using the connection, while your assessment history and reports remain available. You can connect the same tenant again later. Removing the enterprise application from Microsoft 365 is a separate step you perform in Microsoft's portal, and ScopePoint tells you where.

Which report formats are supported?

PDF for review and sharing, CSV for spreadsheets and tracking, and JSON for another system to consume. A report can also be generated again when you need a fresh copy; the score and coverage it records stay exactly as they were assessed.

Does ScopePoint support multiple Microsoft 365 tenants?

Yes. An organization in ScopePoint can connect more than one Microsoft 365 tenant, and each is assessed and reported separately. A given Microsoft 365 tenant can be connected to one ScopePoint organization at a time; connecting it elsewhere requires disconnecting it first.

See your Microsoft 365 security posture clearly.

Connect your environment, run an assessment, and turn security findings into a clear posture overview.

Sign in with your Microsoft work account. Connecting a tenant requires administrator consent.