For UK MSPs and the businesses they protect
SocGenie assesses, hardens, detects, investigates and responds across every Microsoft tenant you look after. AI agents do the reading and the legwork. A person approves anything that changes a tenant.
The loop
Most MSPs run these as six tools, three spreadsheets and a Teams channel. SocGenie runs them as one loop, and each stage feeds the next.
Scan each tenant against five open frameworks: Maester, CIS, CISA SCuBA, EIDSCA and ORCA. Every finding carries severity, evidence and the fix, and results are licence-aware so you are never marked down for a feature you do not own.
FreeDeploy Intune, Conditional Access and Entra RBAC baselines as code, policy by policy, from a curated catalogue. Drift against the deployed baseline is flagged, and every run is kept in history.
ZerotouchMicrosoft Defender detections mapped to MITRE ATT&CK, deployed into the tenant and refreshed continuously as new techniques appear. See your coverage, export it to ATT&CK Navigator, and see which countermeasures matter.
ZerotouchAgents triage and enrich every Microsoft Sentinel incident with sign-in, device and mailbox context and threat intelligence. Watch it live, replay it later, and find similar incidents across the fleet.
Managed MDRThe agent proposes containment. A person approves it in Slack, Microsoft Teams or the portal. The action runs through Microsoft Graph and lands in the audit trail with who approved it and why.
Managed MDRDrift, coverage gaps and repeat incidents feed the next scan and the next baseline. Fleet health tells you which customer needs attention today.
All tiersTwo ways to run it
Same platform, same audit trail, same rule: nothing changes in a tenant without a human yes.
Start with the free scanner. Add baselines and detections when you are ready. You see everything the agents see and you approve everything that changes.
Microsoft Sentinel deployed and tuned, agents triaging every incident around the clock, and Reddome analysts on every approval gate. Your customer relationship stays yours.
Human in the loop
Read-only work is unlimited: enrichment, correlation, mapping to ATT&CK, writing the summary. Anything that changes a tenant waits for a person, and the decision is recorded with the evidence that led to it.
For MSPs
Connect customers through GDAP delegated access. See fleet health, scan freshness and open incidents across your whole book, and work the SOC queue by severity and SLA.
| Tenant | Tier | Last scan | Open incidents | Health |
|---|---|---|---|---|
| fabrikam.com | Managed MDR | Today | 2 | Attention |
| contoso.com | Managed MDR | Today | 1 | Drift |
| adventure-works.com | Zerotouch | Yesterday | 0 | Healthy |
| tailwindtraders.com | Zerotouch | 3 days ago | 0 | Healthy |
| northwind.com | Free | 12 days ago | — | Scan due |
Trust
Runs on Microsoft Azure in the UK. Your telemetry stays in your tenant; SocGenie reads it through delegated consent.
Scoped Microsoft consent, encrypted secrets, short-lived sessions, and every request scoped to one organisation.
Every agent action, tool call and human approval is written down. Replay any investigation step by step.
Customer data is never used to train models. Tenants are isolated from each other at every layer.
Assessment engines and baselines come from open, community-maintained projects, so you can read every check.
Questions
Free scanner coming soon
Register interest and we will email you the day it opens. Free forever, no card, nothing to install.