Authenticate
The engine signs in to the tenant as each approved module app using workload identity federation: its Azure managed identity is the credential. There's no password, client secret or certificate.
A plain look under the hood: how tenants are connected, what the assessment engine does, what ends up in the report, and what's live today versus on the roadmap.
Onboarding uses Microsoft's standard admin consent flow, one module at a time. There's nothing to install and no credentials to hand over.
Sign in with your Microsoft Entra ID work account. Your first sign-in creates your workspace. MSP plans hold many customer tenants in one workspace.
Enter the customer's domain (for example contoso.com). We look up the Microsoft 365 tenant behind it.
Choose what to assess: Core (always), Exchange & Security, SharePoint & OneDrive, Teams, and the opt-in Power Platform and SharePoint Advanced modules. Send the link to the customer's Global Administrator, or open it yourself if it's your own tenant.
The admin reviews each module's permissions on Microsoft's consent screen and accepts, then signs in once more so the wizard can assign Microsoft's view-only Global Reader role where a module needs it, from the admin's own browser. The tenant shows as connected and is ready to assess.
Simplified illustration. See the complete permission list.
Revocable any time. The customer can remove the M365Assessments enterprise app in Microsoft Entra and access ends immediately. How to revoke.
Each assessment runs in its own short-lived container on Microsoft Azure, talks to the tenant only through Microsoft Graph, and reads without writing.
The engine signs in to the tenant as each approved module app using workload identity federation: its Azure managed identity is the credential. There's no password, client secret or certificate.
Before collecting anything, it checks which permissions the tenant granted. If an area's key permission is missing, that area is skipped instead of being reported as a false "not configured".
Tenant core first (organization, Secure Score, subscriptions), then identity, devices and licensing. Every call is a read.
Findings are evaluated against best practice, ranked by severity and written into the report, which is stored in that tenant's isolated storage.
Tenant core, every run: organization profile, Microsoft Secure Score, subscriptions.
Small tenants finish in minutes. A four-user tenant takes about five minutes from start to finished report. Tenants with thousands of users, devices and applications take longer, because there's simply more to read. Runs happen in the background, so you can close the browser.
If a tenant's policies block our app (for example, Conditional Access for workload identities), the run stops with a plain explanation of what happened and how to fix it. You won't get a half-empty report.
Every assessment produces a polished report you can open in the browser and share with the people who need to act on it.
Tenant profile, Microsoft Secure Score and a count of findings by severity, readable in a minute.
What we found, why it matters and the recommended fix, ranked so the riskiest items come first.
Identity, devices and licensing sections with the specifics your engineers need to do the work.
Every assessment also ships a Word executive summary and a PowerPoint briefing, ready for board packs and QBR decks.
Your logo, colours, contact details and footer on the report and both deliverables, with an option to hide "Powered by M365Assessments". Included in MSP 50, MSP 100 and Enterprise.
litware.io · 64 users · Identity, Devices, Licensing
3 accounts signed in with legacy protocols in the last 30 days. These sign-ins bypass MFA.
Staff can open company email on personal phones with no data protection controls.
Illustrative sample with a fictitious company.
Each assessment is saved with its date, status and report, so you have a dated record of each tenant over time.
4 assessments
| Date | Status | Findings |
|---|---|---|
| Sep 18, 2026 | Completed | 3712 |
| Jun 20, 2026 | Completed | 5913 |
| Mar 14, 2026 | Completed | 71015 |
| Mar 14, 2026 | Failed | Consent missing |
Illustrative example.
Everyone signs in with their own Microsoft work account. No shared logins, and nobody's password is stored with us.
Manages the workspace, its plan and team membership.
Manages tenants, consent, assessments and team members.
Adds tenants, runs assessments and works with reports.
Read-only access to tenants and reports.
Owners and admins invite teammates themselves with a one-time link, change roles and remove access. The last owner is always protected.
Enterprise SSO & role mapping (Enterprise plan): assign your Entra ID groups to Owner, Admin, Member or Viewer on the M365Assessments app and access follows them on every sign-in, including removing it for leavers.
We'd rather ship fewer areas done properly than many done shallowly. Here's exactly where things stand.
Why some areas take longer: Exchange, Teams, SharePoint, Defender, Purview and Power Platform rely on different Microsoft APIs, and some need a directory role or broader access than read-only Graph permissions. Each one ships as its own module that the customer approves separately, and we publish exactly what it requests on the security page. The Power Platform and SharePoint Advanced modules aren't read-only (Microsoft offers nothing narrower), so they're opt-in and clearly labelled.
Tell us what to build next. Customers suggest features and vote on each other's ideas on the feature board in the portal (Feedback in the sidebar). Suggestions are anonymous to other customers. See what's planned, in progress and recently shipped on the live roadmap.
The fastest way to understand M365Assessments is to run it. Sign in, connect a tenant and read your first report.