What it finds
Eighty-nine Microsoft best practices. None of them quietly skipped.
Cloud Tenant Advisor grades your tenant against a fixed, published list of Microsoft security best practices — then tells you plainly which ones it measured, and which ones no API can measure at all.
Read-only · 58 Microsoft Graph endpoints · nothing altered without your confirmation
Coverage
Eight areas, eighty-nine checks
Every check carries a best-practice ID, so a finding reads “this is Microsoft best practice #37” rather than “our tool thinks you should.”
Identity, authentication & access
MFA coverage, legacy auth, Conditional Access device trust, PIM and privileged-role sprawl, phishing-resistant methods, admin-portal lockdown.
Endpoint management & compliance
Compliance policy per platform, non-compliant device blocking, app protection for BYOD, BitLocker and TPM, local admin removal, ASR rules.
Extended endpoint & identity coverage
The long tail — the individual hardening controls that make up the bulk of a real assessment.
Email, collaboration & data protection
Defender for Office 365 policies, mailbox auditing, risky auto-forward rules, sensitivity labels, DLP.
Monitoring, detection & incident response
Audit logging, alert policies, and whether anything is actually watching when a control fails.
Patch, update & configuration
Update rings and deferral sanity, feature-update profiles, minimum OS versions, security baselines and version drift.
Intune admin controls & governance
Scope tags, role-based access, and the administrative hygiene that decides who can change what.
Architecture, Zero Trust & hygiene
The structural checks — whether the tenant is arranged the way Microsoft's guidance assumes.
The part most tools skip
Coverage, stated honestly
A number like “89 checks” is worthless if you can’t tell which ones actually ran.
Ten of the eighty-nine cannot be measured by any API
They’re governance and process items — the sort of thing that lives in a policy document or a person’s head, not in Microsoft Graph. Most assessment tools handle this by quietly dropping them and reporting a smaller total that looks like full marks.
We surface them as explicit attestations instead. You’re asked to confirm them, they appear in the report marked as attested rather than measured, and the coverage figure stays honest. Nothing is silently skipped.
The same applies when a check can’t run because a capability isn’t licensed. It doesn’t report a vague “access denied” — it names the exact licence required and states plainly that this is what’s blocking the check.
Beyond the checklist
Four things the portals won’t show you
Microsoft’s consoles reward you for switching features on. They don’t tell you whether the feature is actually reaching anything.
Configured is not protected
A policy assigned to an empty group looks identical to a working one in Intune — and Secure Score still awards the points. We resolve every assignment and flag the policies that reach zero devices.
You’re already paying for it
Capabilities the tenant licenses but never switched on, and seats assigned to nobody. Recoverable without buying a thing.
Expiry radar
Certificates, Apple MDM push certificates and app secrets, ranked by how soon they lapse. These are the silent failures that take a tenant down on a weekend.
What breaks if this group goes
Before you delete a group or retire a device, see what actually depends on it — which policies, which apps, which people.
The obvious question
Isn’t this what Secure Score already does?
Fair question, and worth a straight answer. Microsoft’s built-in tooling is genuinely good at what it does. Here is precisely where it stops.
It scores intent, not outcome
A compliance policy assigned to an empty group earns the same points as one protecting five thousand devices. Secure Score reads the policy; it does not resolve the assignment. We do — and flag every policy that reaches nothing.
It goes quiet on what you can’t license
When a control needs a tier you don’t own, vendor tooling tends to omit the check rather than explain it. We name the exact licence required and state plainly that this is what’s blocking the check — so a gap never looks like a pass.
A dashboard isn’t something you can hand a client
There is no export an MSP can put in front of a customer, no branded evidence, no record of what was found and when. That artifact is the whole job for anyone assessing tenants on someone else’s behalf.
It’s the platform grading its own homework
Useful, but it is not an independent read. In front of a client, an auditor or a board, a separate assessment carries weight that a vendor’s own score simply doesn’t.
See it against your own tenant
Read-only, a few minutes to run, and nothing changes until you say so. Send a note and we’ll walk you through a live assessment.
Email [email protected]