Know your M365 tenant
health — automatically
116 health rules across the same 8 M365 categories on every scan. License-aware scoring combines Microsoft evidence with focused administrator context, safely reuses unchanged answers, freezes the decision history, and offers optional AI recommendations. Runs through your own relay without stored Microsoft credentials.
The problem
M365 audits are a spreadsheet and a prayer
Most tenants are audited once — usually after an incident. The checklist is long, the findings go into a report that nobody reads, and the configuration drifts the moment the auditor leaves. Six months later, DKIM is still off.
The solution
Automated. Scored. Actionable.
Calibrant runs the audit for you against a curated set of 116 rules aligned with industry benchmarks and M365 best practices. It reads Microsoft first, then asks only for context the configuration cannot prove or a saved answer can no longer support. Unchanged evidence reuses the saved context. Every final finding is severity-ranked. Eligible final scans can also receive an AI summary and prioritized action list. Run it weekly.
Protocol
How it works
Three steps from zero to scored.
Deploy Relay
A small Windows service in your Azure subscription uses Managed Identity, so Calibrant never stores Microsoft passwords, client secrets, or tenant tokens.
Run Full Scan
Calibrant collects the same complete tenant scope every time, automatically accounting for the Microsoft products you license.
Review & Act
Review only the focused context requests that are new or no longer match current evidence, then get one severity-ranked verdict per control. Eligible final scans can also receive an AI-generated executive summary.
Everything an audit should be
Full technical scope. Explicit evidence gaps. Results in minutes.
Context-Aware Scoring
Calibrant asks for scope, intent, exclusions, policy quality, or an allowed outside safeguard only when Microsoft evidence cannot prove it. Answers are saved and reused while the relevant evidence and Calibrant evaluation rules remain unchanged; changed items are asked again. One control is scored once, and no partial score is published while required context is missing.
116 Health Rules
Covers identity, email security, endpoint management, external sharing, license utilization, Defender policies, and more across 8 M365 categories.
No Stored Microsoft Credentials
The relay uses its Azure Managed Identity for M365 access. It stores a rotatable Calibrant API key, but no Microsoft service-account password, client secret, or tenant OAuth token.
AI Executive Summary
For eligible final scans, Claude can produce a 2–3 paragraph executive summary plus top 5 prioritized remediation recommendations.
Severity-Weighted Scoring
Critical findings carry 20× more weight than low-severity issues. Your score reflects real risk, not a simple pass/fail count.
Category-Level Breakdown
Scores per M365 workload — Entra ID, Exchange, Teams, SharePoint, OneDrive, Power Platform, and Intune/Endpoint. Drill into exactly where the gaps are.
Override & Accept Risk
Document findings handled elsewhere or accepted as risk. A change applies to future scans only; every completed scan keeps the exact exception policy used for its score.
PDF, CSV + Raw Log Export
Download an audit-ready PDF report of any verified scan — every finding with its evidence message, plus the frozen override policy and questionnaire answers behind the score. CSV export covers stakeholder reporting, and raw PowerShell output supports deep-dive troubleshooting.
What gets checked
Every check runs via PowerShell against your live tenant configuration.
Global admin count, conditional access, guest settings, inactive accounts, license utilization, OAuth scope audit, app credential expiry
DKIM/DMARC/SPF, IMAP/POP, TLS connectors, mailbox auditing, transport rules, malware filter, anti-spam, auto-expanding archive
External sharing level, anonymous link expiry, unmanaged device sync, resharing restrictions, idle session sign-out
Consumer access, external federation, app policies, anonymous meeting join, lobby bypass, messaging policies
Orphaned account retention, sync restrictions, storage quota alignment, sharing alignment confirmed from Microsoft evidence plus focused administrator context
DLP policies, environment inventory, Power Automate flow failures
Device enrollment, compliance policies, Defender AV status, BitLocker encryption, Windows Autopilot, update rings
Safe Attachments, Safe Links, anti-phishing policies, malware filter, outbound spam, quarantine policies
No stored Microsoft credentials
The relay uses its Azure Managed Identity for M365 connections. No Microsoft passwords, client secrets, service accounts, or tenant OAuth tokens are stored. The VM does hold a rotatable Calibrant API key and the local administrator password you set during deployment. It makes outbound-only HTTPS calls and needs no inbound ports. Its Graph permissions and Global Reader role are read-only. The optional Power Platform management registration is broader than read-only; skip it if that access is not acceptable, and Power Platform checks will be reported as not evaluated.
Ready to audit your tenant?
Deploy the relay once, then run full-scope scans whenever you want. They generally complete in minutes; tenant size and Microsoft API response times vary.