Product

How M365Assessments works, from consent to report

A plain look under the hood: how tenants are connected, what the assessment engine does, what ends up in the report, and what's live today versus on the roadmap.

1 · Tenant onboarding

Connect a tenant with a guided onboarding wizard

Onboarding uses Microsoft's standard admin consent flow, one module at a time. There's nothing to install and no credentials to hand over.

  1. Sign in and get a workspace

    Sign in with your Microsoft Entra ID work account. Your first sign-in creates your workspace. MSP plans hold many customer tenants in one workspace.

  2. Add the tenant by domain

    Enter the customer's domain (for example contoso.com). We look up the Microsoft 365 tenant behind it.

  3. Pick modules and send the onboarding link

    Choose what to assess: Core (always), Exchange & Security, SharePoint & OneDrive, Teams, and the opt-in Power Platform and SharePoint Advanced modules. Send the link to the customer's Global Administrator, or open it yourself if it's your own tenant.

  4. Admin approves each module

    The admin reviews each module's permissions on Microsoft's consent screen and accepts, then signs in once more so the wizard can assign Microsoft's view-only Global Reader role where a module needs it, from the admin's own browser. The tenant shows as connected and is ready to assess.

Simplified illustration. See the complete permission list.

Revocable any time. The customer can remove the M365Assessments enterprise app in Microsoft Entra and access ends immediately. How to revoke.

2 · The assessment engine

What happens when you press Run

Each assessment runs in its own short-lived container on Microsoft Azure, talks to the tenant only through Microsoft Graph, and reads without writing.

Authenticate

The engine signs in to the tenant as each approved module app using workload identity federation: its Azure managed identity is the credential. There's no password, client secret or certificate.

Check permissions

Before collecting anything, it checks which permissions the tenant granted. If an area's key permission is missing, that area is skipped instead of being reported as a false "not configured".

Collect

Tenant core first (organization, Secure Score, subscriptions), then identity, devices and licensing. Every call is a read.

Analyze & report

Findings are evaluated against best practice, ranked by severity and written into the report, which is stored in that tenant's isolated storage.

What's covered today

Live

Identity & access (Entra ID)

  • Conditional Access policies
  • MFA registration & authentication methods
  • Admin roles & Privileged Identity Management
  • Risky users & risky sign-ins
  • Legacy authentication usage
  • Guest & external access
  • App registrations, enterprise apps & consent grants
  • Domains
Live

Devices (Intune)

  • Compliance policies
  • Configuration profiles
  • Endpoint security
  • Windows Autopilot
  • App protection policies
  • Windows Update rings
Live

Licensing & usage

  • Subscriptions
  • License utilization
  • Microsoft 365 usage & adoption
  • Microsoft 365 Copilot usage & adoption

Tenant core, every run: organization profile, Microsoft Secure Score, subscriptions.

How long does it take?

Small tenants finish in minutes. A four-user tenant takes about five minutes from start to finished report. Tenants with thousands of users, devices and applications take longer, because there's simply more to read. Runs happen in the background, so you can close the browser.

When something's blocked

If a tenant's policies block our app (for example, Conditional Access for workload identities), the run stops with a plain explanation of what happened and how to fix it. You won't get a half-empty report.

3 · The report

A report written to be read, not filed

Every assessment produces a polished report you can open in the browser and share with the people who need to act on it.

Summary up front

Tenant profile, Microsoft Secure Score and a count of findings by severity, readable in a minute.

Prioritized findings

What we found, why it matters and the recommended fix, ranked so the riskiest items come first.

Technical detail by area

Identity, devices and licensing sections with the specifics your engineers need to do the work.

Executive deliverables

Every assessment also ships a Word executive summary and a PowerPoint briefing, ready for board packs and QBR decks.

White-label for MSPs

Your logo, colours, contact details and footer on the report and both deliverables, with an option to hide "Powered by M365Assessments". Included in MSP 50, MSP 100 and Enterprise.

Illustrative sample with a fictitious company.

4 · Run history

Every run, kept on file

Each assessment is saved with its date, status and report, so you have a dated record of each tenant over time.

  • See when each tenant was last assessed
  • Open any previous report
  • Compare quarter to quarter in reviews
  • Run status in real time: queued, running, completed or failed, with the reason

Illustrative example.

5 · Workspace & roles

One workspace for your team, with four roles

Everyone signs in with their own Microsoft work account. No shared logins, and nobody's password is stored with us.

Owner

Full control

Manages the workspace, its plan and team membership.

Admin

Manage

Manages tenants, consent, assessments and team members.

Member

Operate

Adds tenants, runs assessments and works with reports.

Viewer

Read

Read-only access to tenants and reports.

Owners and admins invite teammates themselves with a one-time link, change roles and remove access. The last owner is always protected.

Enterprise SSO & role mapping (Enterprise plan): assign your Entra ID groups to Owner, Admin, Member or Viewer on the M365Assessments app and access follows them on every sign-in, including removing it for leavers.

6 · Live & roadmap

What's live today, and what's coming

We'd rather ship fewer areas done properly than many done shallowly. Here's exactly where things stand.

Live Available now

  • Microsoft Entra ID sign-in, multi-tenant workspaces Platform
  • Guided onboarding wizard with per-module consent Platform
  • Power Platform (opt-in module, not read-only) Assessment
  • Identity & access (Entra ID) Assessment
  • Devices (Intune) Assessment
  • Licensing & usage, including Copilot Assessment
  • Tenant core & Microsoft Secure Score Assessment
  • Shareable report Reporting
  • Run history Reporting
  • Word & PowerPoint executive deliverables Reporting
  • White-label reports (MSP 50, MSP 100, Enterprise) Reporting
  • Sales Guide & project pipeline: priced projects and proposals (MSP 50, MSP 100, Enterprise) Reporting
  • Team roles & self-serve invitations Workspace
  • Enterprise SSO & role mapping with Entra ID app roles (Enterprise) Workspace
  • Per-plan tenant and run quotas Workspace
  • Scheduled recurring assessments Automation
  • Self-serve billing & plan changes Workspace

New Early access modules

  • Exchange Online Assessment
  • Microsoft Teams Assessment
  • SharePoint & OneDrive Assessment
  • Microsoft Defender Assessment
  • Microsoft Purview Assessment

Why some areas take longer: Exchange, Teams, SharePoint, Defender, Purview and Power Platform rely on different Microsoft APIs, and some need a directory role or broader access than read-only Graph permissions. Each one ships as its own module that the customer approves separately, and we publish exactly what it requests on the security page. The Power Platform and SharePoint Advanced modules aren't read-only (Microsoft offers nothing narrower), so they're opt-in and clearly labelled.

Tell us what to build next. Customers suggest features and vote on each other's ideas on the feature board in the portal (Feedback in the sidebar). Suggestions are anonymous to other customers. See what's planned, in progress and recently shipped on the live roadmap.

See it on your own tenant

The fastest way to understand M365Assessments is to run it. Sign in, connect a tenant and read your first report.