securityMicrosoft 365 security ops

See every risk. Fix it in one click.

Alif gives security teams and MSPs the fastest way to assess Microsoft 365 posture, manage identities at scale, and fix what the audit caught — from a single pane of glass.

F.01Tenant inventory

All your tenants in one dashboard.

Sign in and see every customer tenant's secure score side-by-side. Add new ones with a domain or tenant ID. Consent verifies in real time before the first sync runs.

  • task_altAdd tenant by domain or tenant ID
  • task_altConsent verified before sync starts
  • task_altStatus chips — Secure / Review / At risk
  • task_altSync all tenants in one click
assess.yourdomain.com / AssessmentHome
home
corporate_fare
bar_chart
rocket_launch
settings
Total Tenants
28
Avg Secure Score
67%
Need Attention
9
Last Sync
4h ago
add_circleAdd new tenant
Tenant Inventory 5
C
Contoso Ltd
contoso.onmicrosoft.com
8fe2a1c4-4d3e-4a2b-9f1e-8a7b6c5d4e3f
82
Secure
sync
open_in_new
NW
Northwind Trading
northwind-trading.com
b43c2d1e-9f8a-4d5c-b6e7-a1b2c3d4e5f6
67
Review
sync
open_in_new
F
Fabrikam Inc
fabrikam.net
72a91c3b-5d8e-4f2a-ab19-3c4d5e6f7a8b
54
At risk
sync
open_in_new
WB
Woodgrove Bank
woodgrove.finance
1e9d8c7b-6a5f-4e3d-92c1-b4a3c2d1e0f9
91
Secure
sync
open_in_new
AW
Adventure Works
adventureworks.io
6d5c4b3a-2e1f-4a9b-8c7d-5e4f3a2b1c0d
73
Review
sync
open_in_new
F.02Posture dashboard

One tenant, nine focused views.

Switch between Dashboard, Users, Devices, Email, Data, Policies, Apps, Licenses and Baselines — each tab a different angle on the same assessment. No re-fetching, no waiting.

  • task_altMicrosoft Secure Score + Alif posture score
  • task_altAI findings prioritised by impact
  • task_altTile grids drill into detailed tables
  • task_altClick a tab below — it actually switches
assess.yourdomain.com / AssessmentOverview?t=contoso
dashboard
person
devices
mail
cloud_done
policy
apps
verified
shield
Dashboard
Users
Policies
Licenses
0%
Secure Score
Microsoft M365

Contoso Ltd

4 findings need attention. 2 improvements ready to apply.

Users
1,240
trending_up+18
Global Admins
3
optimal
Dormant >45d
112
trending_up+6
No MFA
24
review
Key Security Findings
Privileged role lacks phishing-resistant MFA

Global Administrator role is protected by a Conditional Access policy requiring any MFA — not yet hardened to FIDO2 / Windows Hello.

24 members without registered MFA method

Users are covered by CA but have never completed initial MFA setup. First sign-in after policy activation will fail.

Display Name
Email / UPN
MFA
Role
Status
chevron_rightFardeen K.
fardeen.k@contoso.com
Enabled
GLOBAL ADMIN
Active
FK
Fardeen K.
fardeen.k@contoso.com
Security Engineer · IT Security
MFA registered Enabled No risk
shield_personRole & Access
RoleGlobal Admin
Account typeUser
Break-glassNo
lockIdentity Signals
MFAFIDO2
Risk levelNone
Last sign-in2h ago
verifiedLicences
Assigned3
M365 E5 · EMS E5 · Defender for Cloud Apps
chevron_rightAarti M.
aarti.m@contoso.com
Enabled
Member
Active
chevron_rightMarcus O.
marcus.o@contoso.com
Missing
Member
Dormant
Conditional Access Policy
State
Users
Apps
Grant
Require MFA for all users
On
All
All
MFA
Block legacy authentication
On
All
All
Block
Require compliant device for admins
Report
Admins
All
Device
High-risk sign-in requires reset
On
All
All
MFA
Phishing-resistant MFA for GA
Off
GA
Portal
FIDO2
SKUs
12
Purchased
1,540
Assigned
1,218
Unused
322
Licence
Purchased
Assigned
Available
Usage
Microsoft 365 E5
400
348
52
87%
Microsoft 365 E3
820
740
80
90%
EMS E5
180
98
82
54%
Defender for Cloud Apps
140
32
108
23%
F.03Framework radar

Compare against 9 compliance frameworks.

Click a framework — CIS, NIST, ISO 27001, Essential 8, and more — to see your tenant scored against it instantly. The dashed ring is the 70% target. Anything outside it needs work.

  • task_altTry it — click a framework pill
  • task_altHover a point to see its score
  • task_altOverall score animates too
  • task_altTarget: 70% (dashed grey ring)
assess.yourdomain.com / Baselines
Microsoft Baseline
CIS v6
CMMC L1
NIST CSF
ISO 27001
Zero Trust
Coverage by domain
Overall 72%
Identity Email Devices Data Policies Apps Target 70%
F.04Admin deep-dive

Audit every privileged admin.

Click any admin to see job title, department, MFA method, risk score, last sign-in, and full licence list — pulled live from Microsoft Graph. The fastest way to answer "is this admin still safe?"

  • task_altIdentity signals — MFA, risk level, account status
  • task_altProfile context — title, department, UPN
  • task_altFull licence list — not just a count
  • task_altBreak-glass detection + last sign-in age
assess.yourdomain.com / Users / Global-Admins
Display Name
Email / UPN
MFA
Role
Status
chevron_rightAisha Bashir
aisha.bashir@contoso.com
Enabled
GLOBAL ADMIN
Active
AB
Aisha Bashir
aisha.bashir@contoso.com
Director of IT Security · IT Security & Compliance
MFA · FIDO2 Enabled No risk Break-glass: No
shield_personRole & Access
RoleGlobal Administrator
Account typeUser
Account statusEnabled
Break-glassNo
lockIdentity Signals
MFA registeredYes
MethodFIDO2 + WHfB
Risk levelNone
Last sign-in2h ago
badgeProfile
Display nameAisha Bashir
Job titleDirector of IT Security
DepartmentIT Security & Compliance
Days since login0 (today)
verifiedAssigned Licences · 3
verifiedMicrosoft 365 E5 verifiedEMS E5 verifiedDefender for Cloud Apps
F.05AI-drafted findings

Every finding explains itself.

We don't just flag the issue — AI writes a plain-English paragraph explaining the risk, who it affects, and how to fix it. All grounded in your real tenant state. Edit before you export.

  • task_altSeverity mapped to CVSS-style bands
  • task_altCross-references multiple frameworks
  • task_altCopy to clipboard or rewrite with AI
  • task_altExecutive-summary generator included
assess.yourdomain.com / AI-Findings

AI Security Analysis

Live · GPT-4o
Critical CIS 1.3.1 · NIST AC-2(7) · ISO A.5.18
Break-glass accounts missing MFA exclusion

Two emergency-access accounts inherit the tenant-wide MFA Conditional Access policy. During a mass MFA outage — a documented Entra failure mode — these accounts would be locked out. This defeats the purpose of break-glass entirely.

High CIS 3.1 · NIST CSF PR.DS-5 · ISO A.5.14
Guest sharing permits anonymous links

External sharing at the SharePoint tenant level allows "anyone" links. 14 sites have been shared externally in the last 90 days. Recommend downgrading to "Existing guests" and reviewing each exception.

Medium NIST CSF PR.AC-7 · ZT Identity 2.1
Conditional Access gap in admin role bundle

Only 3 of 9 privileged Entra roles are covered by the admin-bundle CA policy requiring phishing-resistant MFA. Roles like Exchange Admin and SharePoint Admin can still use SMS-based MFA

F.06Reports & exports

Two reports, one click.

A branded PDF for the boardroom and a full Excel workbook for the engineer. Same assessment, two formats — exported in seconds.

  • task_altBranded PDF with your logo and colour
  • task_altExcel export — one sheet per data view (users, devices, mailboxes, policies, licences)
  • task_altGenerated in under 30 seconds
  • task_altEvery chart embedded, not linked
assess.yourdomain.com / Export
CIS Foundations V6
Baseline Coverage — Contoso Ltd
82%
Coverage
Passed 96 / 117
Identity
Email
Devices
Policies
Executive Summary
Assessment Report
This assessment evaluates Contoso Ltd's Microsoft 365 tenant against nine security frameworks…
• 4 critical findings identified
• 12 high-priority recommendations
• 87% overall coverage
Detail Sheet
Per-control Findings
picture_as_pdfDownload PDF
table_chartExport Excel
F.07White-label

White-label everything as yours.

Your customers never need to know you use Alif. Swap the name, logo, tagline and accent colour — every report, email, and URL shows your brand. Try the controls below to see it live.

  • task_altTry renaming it — watch the preview
  • task_altPick a brand colour — everything re-themes
  • task_altUpload logo replaces shield mark
  • task_altApplied to PDF and portal
assess.yourdomain.com / Admin / White-label
Brand controls
ASSESS BY ALIF
Your security is our responsibility
Tenant report
Contoso Ltd
Score
82%
Findings
4
Download Report
F.08Multi-tenant console

Built for MSPs managing many tenants.

Every customer in one console. Schedule automatic syncs, compare scores side-by-side, and catch security drops the week they happen.

  • task_altUnlimited tenants per workspace
  • task_altEach user keeps their own tenant shortlist
  • task_altScheduled re-syncs (weekly / monthly)Soon
  • task_altScore drift alerts — email / Slack / TeamsSoon
assess.yourdomain.com / Customers
C
Contoso Ltd
contoso.com
Synced 2h ago 82%
NW
Northwind Trading
northwind.com
Synced 2h ago 67%
F
Fabrikam Inc
fabrikam.net
Synced 2h ago 54%
WB
Woodgrove Bank
woodgrove.finance
Synced 2h ago 91%
AW
Adventure Works
adventureworks.io
Synced 2h ago 73%
TG
Tailspin Group
tailspin.co
Synced 2h ago 88%
LP
Litware Partners
litware.partners
Synced 2h ago 44%
AS
Alpine Systems
alpine-systems.ch
Synced 2h ago 79%
HT
Humongous Telecom
humongous.tel
Synced 2h ago 86%
F.09Security model

Read-only. Revocable. Stays in your region.

We request only read permissions. Your data never leaves the Azure region you signed up in. Remove a tenant from your inventory and our app is auto-removed from your directory — no extra steps.

assess.yourdomain.com / Security-Model
lock
Read-only scopes

We inspect your tenant. We can't change it.

scopes requested:
• Directory.Read.All
• SecurityEvents.Read.All
• Policy.Read.All
write scopes requested: 0
public
Your data, your region

Assessments run in the Azure region your workspace is deployed to. Nothing leaves.

workspace region: Your Azure region
processing: Your Azure region
storage: Your Azure region
data exfil: none
toggle_off
Revoke anytime — one click

Delete the tenant from your inventory and the enterprise app is removed from your Entra directory automatically. No leftovers.

action: Tenant Inventory → Delete
what happens:
• Cached assessment cleared
• Enterprise app removed from your tenant
post-revoke access: none
Part 2

Now fix what we found.

Manage by Alif turns your findings into action. Govern identities, automate offboarding, enforce policy, and close the loop on every alert — without leaving the console.

boltWorkflow automation groupIdentity lifecycle psychologyAI remediation shieldPolicy enforcement
M.01One console, every portal

9 Microsoft portals replaced by 1.

Manage every Microsoft 365 setting from Alif. Stop tab-hopping between Entra, Exchange, Teams, SharePoint, Intune, Defender, and Compliance — they're all in one place here.

  • task_altSingle sign-on with your admin identity
  • task_altNo context-switching between admin tabs
  • task_altOne search box across every surface
  • task_altOne permission model, one audit trail
manage.yourdomain.com — unified admin surface
Manage BY ALIF
person
Entra ID
identity + CA
mail
Exchange
mail + rules
chat
Teams
policies
folder_shared
SharePoint
sites + sharing
cloud
OneDrive
accounts
devices
Intune
compliance
shield
Defender
alerts + quarantine
gavel
Compliance
DLP + retention
M.02Command center

The whole tenant on one screen.

Identity counts, licence usage, compliant endpoints, active risks, and Secure Score — every key metric for the tenant you picked, all live, all on one page.

  • task_alt4 KPI tiles with live deltas
  • task_altPosture checklist — 6 critical checks
  • task_altAnimated Secure Score ring
  • task_altClick any tile to drill into the module
manage.yourdomain.com / Dashboard
dashboard
group
shield
mail
devices
bolt
policy
settings
groupIdentities
2,847
412 guests · 18 admins
verifiedLicences
1,923/2,100
91% utilisation
devicesEndpoints
1,456
82% compliant
warningRisks
12
8 failing · 4 warn
0%
Secure Score
Excellent
315 / 400 points
trending_up+12 this month
Security Posture
check
Conditional Access enforced
8 / 11
check
No disabled users with licences
0 found
warning
Guest ratio
14.5%
check
Device compliance
82.7%
check
Legacy auth blocked
Enforced
close
Phishing-resistant MFA for GA
Not set
M.03Identity lifecycle

Onboard and offboard in one click.

Pick a user, pick a template, hit Schedule. Manage runs the full playbook — joiner (create, license, provision, welcome) or leaver (rename, revoke, reclaim, hide from GAL). Every step logged.

  • task_altRole-specific checklist templates
  • task_altSchedule for overnight or run now
  • task_altLive log streams each Graph API call
  • task_altFailures captured — retry in one click
manage.yourdomain.com / Identity / Lifecycle
person_addOnboarding
person_removeOffboarding
EN
Emma Nichols
emma.nichols@contoso.com
New hire · Sales
check
Create user account
→ UPN · licence group · region
check
Assign licences (M365 E3 + Power BI)
→ 2 licences · group-based
check
Add to 4 security + DL groups
→ Sales-All · UK-Employees · All-Staff · …
check
Provision mailbox + archive
→ Exchange Online · 100GB
check
Send welcome email to manager
→ Includes temp password + SSPR link
0%
Ready
09:02:11Creating user
09:02:14Assigning licences
09:02:17Adding to groups
09:02:21Provisioning mailbox
09:02:26Sending welcome email
✓ Onboarding complete · 15s
JD
John Doe
john.doe@contoso.com
Standard offboarding
check
Update display name
→ Former_Employee_John_Doe
check
Revoke all sign-in sessions
→ graph.microsoft.com/users/.../revokeSignInSessions
check
Remove all licences (3)
→ M365 E5 · EMS E5 · Defender CA
check
Convert mailbox to shared
→ Exchange Online · SetMailbox
check
Hide from Global Address List
→ HiddenFromAddressListsEnabled = true
0%
Ready
14:22:15Updating display name
14:22:18Revoking sessions
14:22:20Removing licences
14:22:24Converting mailbox
14:22:27Hiding from GAL
✓ Offboarding complete · 12s
M.04Workflow automation

Automate the response. Save your night.

Set triggers, conditions, and actions once — Manage runs them every night. Catch dormant users, stale guests, admin-role changes, unused licences, and anything else you can wire up.

  • task_altLow-code builder — no scripts
  • task_altRun-history with matched counts
  • task_altAI-suggested workflows from your posture
  • task_altEnable / disable with one toggle
manage.yourdomain.com / Automation / Workflows
Reclaim licences from dormant users
Trigger · Inactive > 45 days · 2 conditions
blockBlock sign-in verifiedRemove licences mailNotify manager
142 runs · 98% success
Clean up stale guests
Trigger · Guest inactive > 90 days
logoutRevoke sessions person_removeDelete user
28 runs · 100% success
Alert on privileged role changes
Trigger · Admin role added · instant
notifications_activeAlert security descriptionLog to audit
7 triggers · 90d
Disable legacy auth for new admins
Trigger · Role assignment · on create
policyApply CA policy mailEmail admin
0 runs · never fired
M.05Score boost

Quick wins, ranked by impact.

Every Secure Score recommendation, sorted by points-per-hour. Click Deploy — Manage applies the fix via Graph. No PowerShell. No portal trip. Watch your score climb in real time.

  • task_altRanked by points / effort ratio
  • task_altOne-click deploy for 80% of controls
  • task_altTrack Applied / In discussion / Not compatible
  • task_altScore updates within an hour
manage.yourdomain.com / Automation / Score-Boost
0%
Secure Score
Excellent
315 of 400 points
trending_up+45 pending to apply
+15 pts
Enable self-service password reset
bolt30m effortpsychologyIdentity
+12 pts
Block legacy authentication
bolt15m effortpsychologyIdentity
+10 pts
Enforce device compliance for admins
bolt1h effortpsychologyDevices
+8 pts
Require phishing-resistant MFA for GA
bolt5m effortpsychologyIdentity
M.06External sharing control

See every externally shared file.

Every doc, folder, and site shared outside your org — named guest or anonymous link — in one table. Filter by risk, see the evidence, revoke or delete in one click. No PowerShell, no ticket.

  • task_altNamed guests and anonymous links
  • task_altAuto-ranked by risk (new, anonymous, unverified domain)
  • task_altStop sharing or delete — both leave an audit trail
  • task_altBulk action on filtered results
manage.yourdomain.com / DataGovernance / Oversharing
Externally shared
23
files + folders
Anonymous links
2
⚠ anyone with the link
Unverified domains
8
outside allowlist
Last 7d activity
47
access events
File / Folder
Shared with
Site
Risk
Action
folder_shared
Q4 Financials FY26
⚠ anonymous link
Finance
High
picture_as_pdf
Customer Pricing v3.pdf
john@acme-external.biz
Sales
High
folder_shared
Candidate Evaluations
3 external recruiters
HR-Hiring
Medium
table_chart
Roadmap Plan 2026.xlsx
⚠ anonymous link
Product
High
description
NDA Template.docx
legal@vendor.com
Legal
Low
slideshow
All-Hands Deck.pptx
board@contoso-guests.com
Executive
Medium
M.07Framework compare

Your compliance status, every framework.

Your real tenant state, mapped control-by-control against the frameworks auditors care about. Pass / partial / fail in one grid — with a one-click Fix that applies the control through Graph.

  • task_altCIS v6 · NIST CSF · ISO 27001 · CMMC L1 in one view
  • task_altPartial ticks show which framework sub-controls pass
  • task_alt"Fix" button applies the control — no portal trip
  • task_altLifts multiple frameworks per control
manage.yourdomain.com / Compare-Frameworks

Contoso Ltd · 47 controls evaluated

Tenant state · live
CIS v6 NIST CSF ISO 27001 CMMC L1
Control
CIS
NIST
ISO
CMMC
MFA enforced for all users
Conditional Access policy active
check
check
check
check
✓ Compliant
Legacy authentication blocked
SMTP Auth + POP3 + IMAP disabled
check
check
check
remove
Phishing-resistant MFA for admins
FIDO2 / WinHello required for GA
close
close
remove
close
Mailbox audit enabled globally
Unified audit log + per-mailbox
check
check
check
check
✓ Compliant
DLP policy covers sensitive data
CC numbers · passports · health IDs
check
check
remove
check
External sharing restricted
Existing guests only · no anonymous
remove
close
remove
close
Device compliance required
Intune compliant for any M365 access
check
check
check
remove
M.08Policy replication

Apply your baseline to every tenant.

Pick the policies from your gold-standard tenant, pick the customers to apply them to, and Alif rolls them out. Conditional Access, DLP, mail-flow rules, retention — every customer aligned in one move.

  • task_altOne "source of truth" tenant, N targets
  • task_altPreview diff before deploying
  • task_altRollback with one click if a tenant fails
  • task_altPer-tenant exclusions for legit exceptions
manage.yourdomain.com / Deploy / Replicate
uploadSource tenant
C
Contoso Ltd · gold standard
expand_more
policyPolicies
Require MFA for all usersCA
Block legacy authenticationCA
Phishing-resistant MFA for adminsCA
7-year Exchange retentionRetain
Sensitive data DLP — FinanceDLP
Disable auto-forward to externalMail
Teams external access allowlistTeams
5 policies
corporate_fareTarget tenants · 4 selected
NW
Northwind Trading
F
Fabrikam Inc
WB
Woodgrove Bank
AW
Adventure Works
TG
Tailspin Group
LP
Litware Partners
5 policies will deploy to 4 tenants · estimated ~35 seconds · rollback available up to 30 days after
M.09Observation & AI alerts

Watch risky users in plain English.

Put a watch on any user — internal or guest. Manage tracks every sign-in and audit event, runs your alert rules, and when something fires hands you a plain-English summary plus a 4-step AI-written fix.

  • task_altPer-user and tenant-wide alert rules
  • task_altRaw evidence archived alongside the alert
  • task_altGPT-4o writes remediation — you just approve
  • task_altRuns for 7-day trailing window by default
manage.yourdomain.com / DataGovernance / Observation
Watched users 3
JT
John Townsend
john.t@contoso.com
SR
Sara R.
sara.r@contoso.com
MK
Marcus K. (guest)
marcus.k@acme.com
High
7 failed sign-ins from unfamiliar region
14:22 UTC
14:22:15john.t sign-in · failed · 103.29.14.200 (IN)
14:22:41john.t sign-in · failed · 103.29.14.200 (IN)
14:23:02john.t sign-in · failed · 103.29.14.200 (IN)
+4 more
AI Remediation plan · GPT-4o
Summary: User john.townsend@contoso.com triggered 7 failed sign-in attempts from India between 14:22 and 14:41 UTC, outside their normal sign-in pattern (previously always US-West)
1Check with the user — are they travelling?
2If not, force password reset and revoke sessions.
3Review mailbox rules for recent forwarding.
4Confirm legacy auth is blocked for this account.
M.10Audit log

Full audit trail. Forever.

Every change made through Manage — user onboarded, policy deployed, licence reclaimed, alert dismissed — captured in an immutable log. Filter, export, and hand to your auditor in seconds.

  • task_altEvery Manage action — no gaps
  • task_altDistinguishes human, workflow, and system actors
  • task_altImmutable — append-only, no edit, no delete
  • task_altExport CSV / JSON · retain up to 7 years
manage.yourdomain.com / Settings / Admin-Audit-Log

Admin audit log · last 24h

All User Automation System
FK
Fardeen K. Admin
Deployed 5 policies to 4 tenants via Policy Replicationpolicy.replicate
14:22:15 UTC
W
Workflow · Reclaim dormant licences Automation
Removed licences from 14 inactive users across Contoso Ltdlicence.remove
14:18:02 UTC
FK
Fardeen K. Admin
Stopped external sharing on "Q4 Financials FY26" (anonymous link)sharing.stop
14:12:47 UTC
A
AI Observation · Triggered alert Automation
Raised High severity alert on john.t@contoso.com — 7 failed sign-ins from unfamiliar regionalert.raise
13:56:11 UTC
AB
Aisha B. Admin
Completed onboarding for emma.nichols@contoso.com (Sales · M365 E3)user.onboard
09:02:26 UTC
S
Scheduled sync System
Re-synced posture for all 28 tenants (weekly schedule)tenant.sync
02:00:00 UTC
paymentsSimple pricing

Pick a plan. Cancel anytime.

No hidden fees. No surprise bills. Switch tiers or cancel any time.

Assess
$150 / month
billed monthly

Read-only security posture assessments. Perfect for audits, M&A diligence, and quarterly reviews.

  • check_circleFull 9-view security dashboard
  • check_circle9 framework mappings (CIS, NIST, ISO, more)
  • check_circleAI-written findings with the why & the fix
  • check_circleBranded PDF + Excel reports, unlimited
  • check_circleWhite-label for MSPs
  • check_circleGDAP customer auto-discovery
  • removeRead-only — no remediation
  • removeNo automation engine
credit_cardMake the payment
Secure checkout. All major payment options.
Common questions
Do I need a credit card to start?add
No. Both plans include a 14-day full-feature trial. Add billing only when you decide to keep it.
Is there a minimum commitment?add
No long-term contract. Pay monthly, cancel any time. Switch tiers or stop billing whenever you like.
Can MSPs get volume pricing?add
Yes. Discounts kick in at 25 tenants and scale up from there. Get a quote.
Can I switch tiers later?add
Up or down, any time. Upgrades are instant; downgrades take effect at the next billing cycle.
What permissions do you need?add
Assess uses read-only Graph scopes only. Manage adds write scopes for the specific actions you authorise — every change is logged.
Where is my data stored?add
In the Azure region your workspace is provisioned in. We never copy your tenant data outside that region.
handshakeReady when you are

Ready to try it on your tenant?

30-minute walk-through with an Alif engineer on your real tenant, under a read-only trial. Leave with a sample report you can hand straight to your team.

video_callLive walk-through with an engineer
shield_lockRead-only trial on your own tenant
downloadBranded sample report included

Set up your walk-through

We'll reach out within one business day. We only use your email to follow up.

You're in.

An engineer will reach out within one business day.