Tenant Healthcheck

Know your M365 tenant
health — automatically

116 health rules across the same 8 M365 categories on every scan. License-aware scoring combines Microsoft evidence with focused administrator context, safely reuses unchanged answers, freezes the decision history, and offers optional AI recommendations. Runs through your own relay without stored Microsoft credentials.

The problem

M365 audits are a spreadsheet and a prayer

Most tenants are audited once — usually after an incident. The checklist is long, the findings go into a report that nobody reads, and the configuration drifts the moment the auditor leaves. Six months later, DKIM is still off.

The solution

Automated. Scored. Actionable.

Calibrant runs the audit for you against a curated set of 116 rules aligned with industry benchmarks and M365 best practices. It reads Microsoft first, then asks only for context the configuration cannot prove or a saved answer can no longer support. Unchanged evidence reuses the saved context. Every final finding is severity-ranked. Eligible final scans can also receive an AI summary and prioritized action list. Run it weekly.

Protocol

How it works

Three steps from zero to scored.

1

Deploy Relay

A small Windows service in your Azure subscription uses Managed Identity, so Calibrant never stores Microsoft passwords, client secrets, or tenant tokens.

2

Run Full Scan

Calibrant collects the same complete tenant scope every time, automatically accounting for the Microsoft products you license.

3

Review & Act

Review only the focused context requests that are new or no longer match current evidence, then get one severity-ranked verdict per control. Eligible final scans can also receive an AI-generated executive summary.

116 health rules8 categories$8 per month, unlimited scans

Everything an audit should be

Full technical scope. Explicit evidence gaps. Results in minutes.

Context-Aware Scoring

Calibrant asks for scope, intent, exclusions, policy quality, or an allowed outside safeguard only when Microsoft evidence cannot prove it. Answers are saved and reused while the relevant evidence and Calibrant evaluation rules remain unchanged; changed items are asked again. One control is scored once, and no partial score is published while required context is missing.

116 Health Rules

Covers identity, email security, endpoint management, external sharing, license utilization, Defender policies, and more across 8 M365 categories.

No Stored Microsoft Credentials

The relay uses its Azure Managed Identity for M365 access. It stores a rotatable Calibrant API key, but no Microsoft service-account password, client secret, or tenant OAuth token.

AI Executive Summary

For eligible final scans, Claude can produce a 2–3 paragraph executive summary plus top 5 prioritized remediation recommendations.

Severity-Weighted Scoring

Critical findings carry 20× more weight than low-severity issues. Your score reflects real risk, not a simple pass/fail count.

Category-Level Breakdown

Scores per M365 workload — Entra ID, Exchange, Teams, SharePoint, OneDrive, Power Platform, and Intune/Endpoint. Drill into exactly where the gaps are.

Override & Accept Risk

Document findings handled elsewhere or accepted as risk. A change applies to future scans only; every completed scan keeps the exact exception policy used for its score.

PDF, CSV + Raw Log Export

Download an audit-ready PDF report of any verified scan — every finding with its evidence message, plus the frozen override policy and questionnaire answers behind the score. CSV export covers stakeholder reporting, and raw PowerShell output supports deep-dive troubleshooting.

What gets checked

Every check runs via PowerShell against your live tenant configuration.

Tenant / Entra ID

Global admin count, conditional access, guest settings, inactive accounts, license utilization, OAuth scope audit, app credential expiry

Exchange Online

DKIM/DMARC/SPF, IMAP/POP, TLS connectors, mailbox auditing, transport rules, malware filter, anti-spam, auto-expanding archive

SharePoint Online

External sharing level, anonymous link expiry, unmanaged device sync, resharing restrictions, idle session sign-out

Microsoft Teams

Consumer access, external federation, app policies, anonymous meeting join, lobby bypass, messaging policies

OneDrive for Business

Orphaned account retention, sync restrictions, storage quota alignment, sharing alignment confirmed from Microsoft evidence plus focused administrator context

Power Platform

DLP policies, environment inventory, Power Automate flow failures

Intune / Endpoint

Device enrollment, compliance policies, Defender AV status, BitLocker encryption, Windows Autopilot, update rings

EOP / Defender

Safe Attachments, Safe Links, anti-phishing policies, malware filter, outbound spam, quarantine policies

No stored Microsoft credentials

The relay uses its Azure Managed Identity for M365 connections. No Microsoft passwords, client secrets, service accounts, or tenant OAuth tokens are stored. The VM does hold a rotatable Calibrant API key and the local administrator password you set during deployment. It makes outbound-only HTTPS calls and needs no inbound ports. Its Graph permissions and Global Reader role are read-only. The optional Power Platform management registration is broader than read-only; skip it if that access is not acceptable, and Power Platform checks will be reported as not evaluated.

Managed Identity auth Outbound-only connections Auto-updating relay No inbound ports

Ready to audit your tenant?

Deploy the relay once, then run full-scope scans whenever you want. They generally complete in minutes; tenant size and Microsoft API response times vary.