What it finds

Eighty-nine Microsoft best practices. None of them quietly skipped.

Cloud Tenant Advisor grades your tenant against a fixed, published list of Microsoft security best practices — then tells you plainly which ones it measured, and which ones no API can measure at all.

Read-only · 58 Microsoft Graph endpoints · nothing altered without your confirmation

Coverage

Eight areas, eighty-nine checks

Every check carries a best-practice ID, so a finding reads “this is Microsoft best practice #37” rather than “our tool thinks you should.”

10

Identity, authentication & access

MFA coverage, legacy auth, Conditional Access device trust, PIM and privileged-role sprawl, phishing-resistant methods, admin-portal lockdown.

10

Endpoint management & compliance

Compliance policy per platform, non-compliant device blocking, app protection for BYOD, BitLocker and TPM, local admin removal, ASR rules.

39

Extended endpoint & identity coverage

The long tail — the individual hardening controls that make up the bulk of a real assessment.

10

Email, collaboration & data protection

Defender for Office 365 policies, mailbox auditing, risky auto-forward rules, sensitivity labels, DLP.

6

Monitoring, detection & incident response

Audit logging, alert policies, and whether anything is actually watching when a control fails.

5

Patch, update & configuration

Update rings and deferral sanity, feature-update profiles, minimum OS versions, security baselines and version drift.

5

Intune admin controls & governance

Scope tags, role-based access, and the administrative hygiene that decides who can change what.

4

Architecture, Zero Trust & hygiene

The structural checks — whether the tenant is arranged the way Microsoft's guidance assumes.

The part most tools skip

Coverage, stated honestly

A number like “89 checks” is worthless if you can’t tell which ones actually ran.

Ten of the eighty-nine cannot be measured by any API

They’re governance and process items — the sort of thing that lives in a policy document or a person’s head, not in Microsoft Graph. Most assessment tools handle this by quietly dropping them and reporting a smaller total that looks like full marks.

We surface them as explicit attestations instead. You’re asked to confirm them, they appear in the report marked as attested rather than measured, and the coverage figure stays honest. Nothing is silently skipped.

The same applies when a check can’t run because a capability isn’t licensed. It doesn’t report a vague “access denied” — it names the exact licence required and states plainly that this is what’s blocking the check.

89
best practices, all accounted for
8
assessment areas
10
surfaced as attestations, not hidden
0
changes without your consent

Beyond the checklist

Four things the portals won’t show you

Microsoft’s consoles reward you for switching features on. They don’t tell you whether the feature is actually reaching anything.

The scary one

Configured is not protected

A policy assigned to an empty group looks identical to a working one in Intune — and Secure Score still awards the points. We resolve every assignment and flag the policies that reach zero devices.

Recover spend

You’re already paying for it

Capabilities the tenant licenses but never switched on, and seats assigned to nobody. Recoverable without buying a thing.

No surprises

Expiry radar

Certificates, Apple MDM push certificates and app secrets, ranked by how soon they lapse. These are the silent failures that take a tenant down on a weekend.

Blast radius

What breaks if this group goes

Before you delete a group or retire a device, see what actually depends on it — which policies, which apps, which people.

The obvious question

Isn’t this what Secure Score already does?

Fair question, and worth a straight answer. Microsoft’s built-in tooling is genuinely good at what it does. Here is precisely where it stops.

Configuration vs effect

It scores intent, not outcome

A compliance policy assigned to an empty group earns the same points as one protecting five thousand devices. Secure Score reads the policy; it does not resolve the assignment. We do — and flag every policy that reaches nothing.

Licensing

It goes quiet on what you can’t license

When a control needs a tier you don’t own, vendor tooling tends to omit the check rather than explain it. We name the exact licence required and state plainly that this is what’s blocking the check — so a gap never looks like a pass.

Deliverable

A dashboard isn’t something you can hand a client

There is no export an MSP can put in front of a customer, no branded evidence, no record of what was found and when. That artifact is the whole job for anyone assessing tenants on someone else’s behalf.

Independence

It’s the platform grading its own homework

Useful, but it is not an independent read. In front of a client, an auditor or a board, a separate assessment carries weight that a vendor’s own score simply doesn’t.

See it against your own tenant

Read-only, a few minutes to run, and nothing changes until you say so. Send a note and we’ll walk you through a live assessment.

Email [email protected]