For UK MSPs and the businesses they protect

Security for Microsoft 365, run as a loop.

SocGenie assesses, hardens, detects, investigates and responds across every Microsoft tenant you look after. AI agents do the reading and the legwork. A person approves anything that changes a tenant.

Free scanner coming soon, no card, free forever Nothing to install Human approval on every change
Assess
Harden
Detect
Investigate
Respond
Improve
AssessFree
Scan the tenant against Maester, CIS, CISA SCuBA, EIDSCA and ORCA. Every finding comes with evidence and a fix.
contoso.onmicrosoft.com01/06
Built on open frameworks and standards
Maester CIS Benchmarks CISA SCuBA EIDSCA ORCA OpenIntuneBaseline MITRE ATT&CK MITRE D3FEND CISA KEV Microsoft Graph Terraform

The loop

Six stages. One platform. Every tenant.

Most MSPs run these as six tools, three spreadsheets and a Teams channel. SocGenie runs them as one loop, and each stage feeds the next.

01 Assess

Scan each tenant against five open frameworks: Maester, CIS, CISA SCuBA, EIDSCA and ORCA. Every finding carries severity, evidence and the fix, and results are licence-aware so you are never marked down for a feature you do not own.

Free
02 Harden

Deploy Intune, Conditional Access and Entra RBAC baselines as code, policy by policy, from a curated catalogue. Drift against the deployed baseline is flagged, and every run is kept in history.

Zerotouch
03 Detect

Microsoft Defender detections mapped to MITRE ATT&CK, deployed into the tenant and refreshed continuously as new techniques appear. See your coverage, export it to ATT&CK Navigator, and see which countermeasures matter.

Zerotouch
04 Investigate

Agents triage and enrich every Microsoft Sentinel incident with sign-in, device and mailbox context and threat intelligence. Watch it live, replay it later, and find similar incidents across the fleet.

Managed MDR
05 Respond

The agent proposes containment. A person approves it in Slack, Microsoft Teams or the portal. The action runs through Microsoft Graph and lands in the audit trail with who approved it and why.

Managed MDR
06 Improve

Drift, coverage gaps and repeat incidents feed the next scan and the next baseline. Fleet health tells you which customer needs attention today.

All tiers

Two ways to run it

Run it yourself, or let Reddome run it for you.

Same platform, same audit trail, same rule: nothing changes in a tenant without a human yes.

Free and Zerotouch

Your team runs it

Start with the free scanner. Add baselines and detections when you are ready. You see everything the agents see and you approve everything that changes.

  • Free posture scan of any tenant, no card (coming soon)
  • Intune, Conditional Access and RBAC baselines as code
  • Defender detections mapped to ATT&CK, updated continuously
  • Drift detection and a coverage map you can show a customer
Managed MDR

Reddome runs it with you

Microsoft Sentinel deployed and tuned, agents triaging every incident around the clock, and Reddome analysts on every approval gate. Your customer relationship stays yours.

  • Sentinel deployment and detection baseline
  • Agent triage and enrichment on every incident, 24/7
  • Containment approved by a person, executed through Graph
  • Cross-tenant SOC queue with SLA tracking

Human in the loop

Agents investigate. People decide.

Read-only work is unlimited: enrichment, correlation, mapping to ATT&CK, writing the summary. Anything that changes a tenant waits for a person, and the decision is recorded with the evidence that led to it.

SocGenie in #soc-approvals
Revoke sessions for a.khan@contoso.com?
Sign-in from an unfamiliar country minutes after a UK sign-in, new mailbox forwarding rule, source IP flagged by two intelligence sources. Mapped to ATT&CK T1078, Valid accounts.
ApproveRejectAsk for more
Example investigation · contoso.comHigh
09:14:02incidentSentinel · Unfamiliar sign-in properties · a.khan@contoso.com
09:14:03contextsign-in history, device compliance, MFA methods, mailbox rules
09:14:05intelsource IP flagged by VirusTotal and AbuseIPDB
09:14:06attackMITRE ATT&CK T1078 · Valid accounts
09:14:07proposalrevoke sessions, remove forwarding rule, require MFA re-registration
09:14:07approvalwaiting for a person in #soc-approvals
09:21:40approvedby SOC lead · executed through Microsoft Graph
09:21:41auditevery step, tool call and decision written to the trail
Approvals in Slack, Microsoft Teams or the portalEscalation via PagerDuty

For MSPs

Every customer tenant, one console.

Connect customers through GDAP delegated access. See fleet health, scan freshness and open incidents across your whole book, and work the SOC queue by severity and SLA.

  • Fleet health signals that say which customer needs attention today
  • Cross-tenant SOC queue with severity, SLA and assignee filters
  • Invite your team with Entra invitations and role-based access
  • Per-tenant pricing with volume tiers; your customers, your terms
See the partner programme Compare with an MSSP
Fleet · 5 tenantsSorted by attention
TenantTierLast scanOpen incidentsHealth
fabrikam.comManaged MDRToday2Attention
contoso.comManaged MDRToday1Drift
adventure-works.comZerotouchYesterday0Healthy
tailwindtraders.comZerotouch3 days ago0Healthy
northwind.comFree12 days ago—Scan due

Trust

Built the way you would want a security vendor to build.

UK hosted

Runs on Microsoft Azure in the UK. Your telemetry stays in your tenant; SocGenie reads it through delegated consent.

Least privilege

Scoped Microsoft consent, encrypted secrets, short-lived sessions, and every request scoped to one organisation.

Audit trail

Every agent action, tool call and human approval is written down. Replay any investigation step by step.

Your data stays yours

Customer data is never used to train models. Tenants are isolated from each other at every layer.

Open frameworks

Assessment engines and baselines come from open, community-maintained projects, so you can read every check.

Read the security overview

Questions

Frequently asked

What is SocGenie?
SocGenie is a security operations platform for Microsoft 365, built by Reddome for UK MSPs and the SMEs they look after. It runs security as a loop over each customer's Microsoft tenant: assess, harden, detect, investigate, respond and improve. AI agents do the reading and the legwork; a human approves anything that changes a tenant.
What does the free compliance scanner include?
A posture scan of one Microsoft 365 tenant against five open frameworks: Maester, CIS, CISA SCuBA, EIDSCA and ORCA. You get findings with severity, evidence and remediation guidance, licence-aware results and a PDF report by email. Up to four scans a month, free forever, no card, nothing to install. More about the scanner
What does human in the loop mean in SocGenie?
Agents investigate and propose. A person approves. Any action that changes a tenant, such as revoking sessions or disabling an account, waits for approval in Slack, Microsoft Teams or the SocGenie portal, and every decision is written to the audit trail. Read the explainer
Does SocGenie work with Microsoft Sentinel and Microsoft Defender?
Yes. SocGenie deploys Defender custom detections mapped to MITRE ATT&CK, deploys a Sentinel detection baseline for Managed MDR customers, ingests Sentinel incidents and enriches them with Sentinel data and threat intelligence. It connects through Microsoft consent, with nothing to install. See all integrations
Is SocGenie only for Microsoft 365?
Yes. SocGenie is built for Microsoft 365, Entra ID, Intune, Microsoft Defender and Microsoft Sentinel. Going deep on one platform is how it stays accurate.

Free scanner coming soon

Be first in line when the free scanner opens.

Register interest and we will email you the day it opens. Free forever, no card, nothing to install.