Getting started

What M365Assessments is and how it works

M365Assessments runs read-only security and configuration assessments of Microsoft 365 tenants and turns them into a prioritized report, a Word summary and a PowerPoint briefing.

Who can do this
Everyone
Plan
All plans
Time
3-minute read

What it is

M365Assessments is a web app at app.m365assessments.com for two kinds of teams:

  • MSPs who assess many customer tenants from one workspace, with per-customer consent, history and reports.
  • IT teams who assess their own Microsoft 365 tenant.

There's nothing to install: no agents, scripts or PowerShell modules. Standard modules are read-only, so an assessment never changes settings, users or data in the tenant.

How it works

Onboarding flowYou add the customer and send an onboarding link. The customer's Global Administrator approves each module at Microsoft, then assigns the read-only roles in the wizard. The first assessment verifies everything. 1. You (portal)Add customer,choose modules,send the link 2. Customer adminOpens the link andselects Grant consentfor each module 3. MicrosoftAdmin reviews thepermissions andselects Accept 4. ReadyRoles assigned inthe wizard; first runverifies everything back to the wizard, next module
  1. Sign in with your Microsoft work or school account. Your first sign-in creates your workspace. Signing in for the first time.

  2. Add a customer: the Microsoft 365 tenant you want to assess, by domain or tenant ID. Adding a customer.

  3. Onboard it: choose the modules to assess and send the onboarding link to the tenant's Global Administrator, who approves each module at Microsoft. The wizard also assigns Microsoft's read-only Global Reader role where a module needs it. Onboarding a customer.

  4. Run an assessment on demand or on a schedule. The engine reads the tenant's configuration and builds the report. Running an assessment.

  5. Share the results: open the HTML report in the browser, save it as PDF, or download the Word executive summary and PowerPoint briefing. Reading the report.

What gets assessed

Each assessment area is a module: a separate Microsoft app that the tenant's administrator approves on its own. You pick the modules per customer.

Modules at a glance
ModuleCoversAccess
Core (always)Entra ID, Conditional Access, apps, Intune, licensing and usage, Secure ScoreRead-only
Exchange & SecurityExchange Online, Defender for Office 365 / EOP, Defender for Identity sensors, PurviewRead-only + Global Reader
SharePoint & OneDriveSharing settings, sites, storage, ownership, OneDrive usageRead-only
Microsoft TeamsTeams policies, external and guest access, voice, team inventory, devicesRead-only + Global Reader
Power Platform (opt-in)Environments, DLP, tenant isolation, apps, flows, connectorsNot read-only
SharePoint Advanced (opt-in)The complete SharePoint tenant-settings auditNot read-only

Details, including every permission: Modules explained.

Words you will see

  • Organization (or workspace): your account in M365Assessments. Its people, plan and customers live here.
  • Customer: one Microsoft 365 tenant your organization assesses. IT teams add their own tenant as their customer.
  • Module: one assessment area, backed by one Microsoft app in the customer's tenant.
  • Assessment (or run): one collection of a tenant's configuration at a point in time, plus the report built from it.

Good to know

M365Assessments supports Microsoft 365 commercial (worldwide) tenants. US Government clouds (GCC, GCC High, DoD) and other national clouds are not supported today.

What happens next

Ready to try it? Follow the quick start to connect a tenant and run your first assessment.

Last updated

Can't find what you need?

Our team is happy to help. Missing an article? Suggest it on the Feedback board in the app and vote for the ones you want.