All your tenants in one dashboard.
Sign in and see every customer tenant's secure score side-by-side. Add new ones with a domain or tenant ID. Consent verifies in real time before the first sync runs.
- task_altAdd tenant by domain or tenant ID
- task_altConsent verified before sync starts
- task_altStatus chips — Secure / Review / At risk
- task_altSync all tenants in one click
One tenant, nine focused views.
Switch between Dashboard, Users, Devices, Email, Data, Policies, Apps, Licenses and Baselines — each tab a different angle on the same assessment. No re-fetching, no waiting.
- task_altMicrosoft Secure Score + Alif posture score
- task_altAI findings prioritised by impact
- task_altTile grids drill into detailed tables
- task_altClick a tab below — it actually switches
Privileged role lacks phishing-resistant MFA
Global Administrator role is protected by a Conditional Access policy requiring any MFA — not yet hardened to FIDO2 / Windows Hello.
24 members without registered MFA method
Users are covered by CA but have never completed initial MFA setup. First sign-in after policy activation will fail.
Compare against 9 compliance frameworks.
Click a framework — CIS, NIST, ISO 27001, Essential 8, and more — to see your tenant scored against it instantly. The dashed ring is the 70% target. Anything outside it needs work.
- task_altTry it — click a framework pill
- task_altHover a point to see its score
- task_altOverall score animates too
- task_altTarget: 70% (dashed grey ring)
Audit every privileged admin.
Click any admin to see job title, department, MFA method, risk score, last sign-in, and full licence list — pulled live from Microsoft Graph. The fastest way to answer "is this admin still safe?"
- task_altIdentity signals — MFA, risk level, account status
- task_altProfile context — title, department, UPN
- task_altFull licence list — not just a count
- task_altBreak-glass detection + last sign-in age
Every finding explains itself.
We don't just flag the issue — AI writes a plain-English paragraph explaining the risk, who it affects, and how to fix it. All grounded in your real tenant state. Edit before you export.
- task_altSeverity mapped to CVSS-style bands
- task_altCross-references multiple frameworks
- task_altCopy to clipboard or rewrite with AI
- task_altExecutive-summary generator included
AI Security Analysis
Live · GPT-4oBreak-glass accounts missing MFA exclusion
Two emergency-access accounts inherit the tenant-wide MFA Conditional Access policy. During a mass MFA outage — a documented Entra failure mode — these accounts would be locked out. This defeats the purpose of break-glass entirely.
Guest sharing permits anonymous links
External sharing at the SharePoint tenant level allows "anyone" links. 14 sites have been shared externally in the last 90 days. Recommend downgrading to "Existing guests" and reviewing each exception.
Conditional Access gap in admin role bundle
Only 3 of 9 privileged Entra roles are covered by the admin-bundle CA policy requiring phishing-resistant MFA. Roles like Exchange Admin and SharePoint Admin can still use SMS-based MFA
Two reports, one click.
A branded PDF for the boardroom and a full Excel workbook for the engineer. Same assessment, two formats — exported in seconds.
- task_altBranded PDF with your logo and colour
- task_altExcel export — one sheet per data view (users, devices, mailboxes, policies, licences)
- task_altGenerated in under 30 seconds
- task_altEvery chart embedded, not linked
White-label everything as yours.
Your customers never need to know you use Alif. Swap the name, logo, tagline and accent colour — every report, email, and URL shows your brand. Try the controls below to see it live.
- task_altTry renaming it — watch the preview
- task_altPick a brand colour — everything re-themes
- task_altUpload logo replaces shield mark
- task_altApplied to PDF and portal
Brand controls
Built for MSPs managing many tenants.
Every customer in one console. Schedule automatic syncs, compare scores side-by-side, and catch security drops the week they happen.
- task_altUnlimited tenants per workspace
- task_altEach user keeps their own tenant shortlist
- task_altScheduled re-syncs (weekly / monthly)Soon
- task_altScore drift alerts — email / Slack / TeamsSoon
Read-only. Revocable. Stays in your region.
We request only read permissions. Your data never leaves the Azure region you signed up in. Remove a tenant from your inventory and our app is auto-removed from your directory — no extra steps.
Read-only scopes
We inspect your tenant. We can't change it.
Your data, your region
Assessments run in the Azure region your workspace is deployed to. Nothing leaves.
Revoke anytime — one click
Delete the tenant from your inventory and the enterprise app is removed from your Entra directory automatically. No leftovers.
Now fix what we found.
Manage by Alif turns your findings into action. Govern identities, automate offboarding, enforce policy, and close the loop on every alert — without leaving the console.
9 Microsoft portals replaced by 1.
Manage every Microsoft 365 setting from Alif. Stop tab-hopping between Entra, Exchange, Teams, SharePoint, Intune, Defender, and Compliance — they're all in one place here.
- task_altSingle sign-on with your admin identity
- task_altNo context-switching between admin tabs
- task_altOne search box across every surface
- task_altOne permission model, one audit trail
The whole tenant on one screen.
Identity counts, licence usage, compliant endpoints, active risks, and Secure Score — every key metric for the tenant you picked, all live, all on one page.
- task_alt4 KPI tiles with live deltas
- task_altPosture checklist — 6 critical checks
- task_altAnimated Secure Score ring
- task_altClick any tile to drill into the module
Onboard and offboard in one click.
Pick a user, pick a template, hit Schedule. Manage runs the full playbook — joiner (create, license, provision, welcome) or leaver (rename, revoke, reclaim, hide from GAL). Every step logged.
- task_altRole-specific checklist templates
- task_altSchedule for overnight or run now
- task_altLive log streams each Graph API call
- task_altFailures captured — retry in one click
Automate the response. Save your night.
Set triggers, conditions, and actions once — Manage runs them every night. Catch dormant users, stale guests, admin-role changes, unused licences, and anything else you can wire up.
- task_altLow-code builder — no scripts
- task_altRun-history with matched counts
- task_altAI-suggested workflows from your posture
- task_altEnable / disable with one toggle
Quick wins, ranked by impact.
Every Secure Score recommendation, sorted by points-per-hour. Click Deploy — Manage applies the fix via Graph. No PowerShell. No portal trip. Watch your score climb in real time.
- task_altRanked by points / effort ratio
- task_altOne-click deploy for 80% of controls
- task_altTrack Applied / In discussion / Not compatible
- task_altScore updates within an hour
Enable self-service password reset
Block legacy authentication
Enforce device compliance for admins
Require phishing-resistant MFA for GA
See every externally shared file.
Every doc, folder, and site shared outside your org — named guest or anonymous link — in one table. Filter by risk, see the evidence, revoke or delete in one click. No PowerShell, no ticket.
- task_altNamed guests and anonymous links
- task_altAuto-ranked by risk (new, anonymous, unverified domain)
- task_altStop sharing or delete — both leave an audit trail
- task_altBulk action on filtered results
Your compliance status, every framework.
Your real tenant state, mapped control-by-control against the frameworks auditors care about. Pass / partial / fail in one grid — with a one-click Fix that applies the control through Graph.
- task_altCIS v6 · NIST CSF · ISO 27001 · CMMC L1 in one view
- task_altPartial ticks show which framework sub-controls pass
- task_alt"Fix" button applies the control — no portal trip
- task_altLifts multiple frameworks per control
Contoso Ltd · 47 controls evaluated
Apply your baseline to every tenant.
Pick the policies from your gold-standard tenant, pick the customers to apply them to, and Alif rolls them out. Conditional Access, DLP, mail-flow rules, retention — every customer aligned in one move.
- task_altOne "source of truth" tenant, N targets
- task_altPreview diff before deploying
- task_altRollback with one click if a tenant fails
- task_altPer-tenant exclusions for legit exceptions
Watch risky users in plain English.
Put a watch on any user — internal or guest. Manage tracks every sign-in and audit event, runs your alert rules, and when something fires hands you a plain-English summary plus a 4-step AI-written fix.
- task_altPer-user and tenant-wide alert rules
- task_altRaw evidence archived alongside the alert
- task_altGPT-4o writes remediation — you just approve
- task_altRuns for 7-day trailing window by default
7 failed sign-ins from unfamiliar region
14:22 UTCFull audit trail. Forever.
Every change made through Manage — user onboarded, policy deployed, licence reclaimed, alert dismissed — captured in an immutable log. Filter, export, and hand to your auditor in seconds.
- task_altEvery Manage action — no gaps
- task_altDistinguishes human, workflow, and system actors
- task_altImmutable — append-only, no edit, no delete
- task_altExport CSV / JSON · retain up to 7 years