Calibrant Docs
Learn how to deploy the relay, optionally label and cross-check your Microsoft 365 tenant, and run full-scope Healthcheck and Security Baseline scans against your environment.
The Relay
Relay Setup
Deploy the Calibrant Relay VM in your own Azure subscription for M365 configuration and security checks.
Relay Reference
For a relay that is already running: the exact permissions it holds and why, logs, environment variables, and who can reach your tenant through it.
Updating the Relay
How new versions are approved and installed, and how to rotate the relay API key.
Removing the Relay
Offboard cleanly: delete the Azure resources, clear the settings Azure can't reach, and verify nothing is left.
Connect Microsoft 365 (optional)
Not required to scan. Records your tenant's name and directory ID so Calibrant can confirm your relay is reporting on the tenant you expect.
Tenant Healthcheck
Healthcheck Overview
Scan your M365 tenant configuration against best practices across Entra ID, Exchange, Teams, SharePoint, and more.
Tenant Context & Follow-Ups
See what is asked before a scan, what is asked only after Microsoft evidence arrives, and how one final verdict is scored.
Scanning
Run scans, understand severity-weighted scores, read results, and export findings.
Relay Permissions for Healthcheck
Grant your relay's Managed Identity the Graph and Exchange app roles plus Global Reader needed to run healthcheck scans.
Security Baseline
Security Baseline Overview
Run framework-driven M365 security assessments and understand which scan results can update the living assessment.
Prerequisite Questionnaire
Set optional Fabric/Power BI and Power Platform intent, then understand result-driven context, safe answer reuse, and complete, provisional, and incomplete results.
Why Some Checks Are Manual
Understand the permission tradeoffs behind manual controls and optional Microsoft admin APIs.
Trust & Security
How the Relay VM Is Secured
Catalog-only execution, no inbound access, Managed Identity, least privilege, and updates only you approve.
Data Handling
What scans collect and never collect, where findings live, and how long each kind of data is retained.
Application Security
SSO-only sign-in, database-enforced workspace isolation, and how to report a vulnerability.
Why Some Checks Are Manual
Calibrant could automate more checks by asking for administrative permissions. It deliberately does not — here is the trade and what it costs.