Free compliance scanner · coming soon
Connect a tenant with Microsoft consent and scan it against five open frameworks: Maester, CIS, CISA SCuBA, EIDSCA and ORCA. Every finding comes with severity, evidence and the fix. Free forever, no card, nothing to install.
How it works
There is no agent to deploy and no service account to create. SocGenie reads the tenant's configuration through Microsoft Graph and gives it back to you as findings.
Sign in with a Microsoft account that can grant consent for the tenant, and approve the read-only permissions SocGenie asks for. Nothing is installed and nothing is changed.
Run a scan whenever you want one. SocGenie checks the tenant against Maester, CIS, CISA SCuBA, EIDSCA and ORCA. Checks that need a licence you do not own are flagged, not failed.
Findings appear in your dashboard with severity, evidence and the fix, and a PDF report lands in your inbox. Share it with a customer or an auditor as it is.
What you get
Every check maps to a named control in an open framework. Every finding tells you what was seen and what to change.
Each finding shows what the scanner saw in the tenant and the remediation guidance for it, drawn from a curated knowledge base.
Checks that need a licence the tenant does not own are flagged, not failed. You are never marked down for a feature you cannot switch on.
A full scan report arrives in your inbox after every scan. It is ready to forward to a customer, a board or an auditor.
A client view for the customer, an operator view for the engineer doing the work, and a partner view across every tenant you look after.
Scan when it suits you: after a change, before a review, or when a customer asks. No schedule to wait for.
A PDF each month listing who holds privileged roles and access in the tenant, so reviews happen on time and with evidence.
The five frameworks
Every check in the scanner comes from an open, community-maintained project. You can read every test, and so can your auditor.
Built and maintained by Microsoft security practitioners in the community. Its tests cover Entra ID, Conditional Access, Exchange Online and Intune settings, and they are updated as Microsoft ships new controls.
The Center for Internet Security's consensus-built configuration recommendations for identity, Exchange, SharePoint, Teams and Defender, in two profile levels. It is the benchmark auditors ask about most.
Prescriptive settings for Entra ID, Exchange Online, SharePoint and OneDrive, Teams and Defender, published by the US Cybersecurity and Infrastructure Security Agency for federal agencies and free for anyone to use.
A community project that checks tenant-level Entra ID settings, such as authentication methods, consent policies and default user permissions, against documented recommended values.
An open-source tool for Exchange Online Protection and Defender for Office 365 settings: anti-phishing, anti-spam, Safe Links, Safe Attachments, DKIM and DMARC.
What happens next
The scanner tells you what is wrong. Zerotouch fixes it as code: Intune, Conditional Access and Entra RBAC baselines from a curated catalogue, deployed policy by policy into the tenant. Once a baseline is in place, the next scan shows what it closed.
Pick the policies you want from the catalogue. They are deployed into the tenant as code, and every run is kept in history.
When a setting moves away from the deployed baseline, SocGenie flags it, so a quiet change in the admin centre does not undo last month's work.
Microsoft Defender custom detections deployed into the tenant and refreshed continuously, with a coverage map you can show a customer.
Questions
Free scanner coming soon
Connect with Microsoft consent, run a scan, and get findings with evidence and fixes, plus a PDF report in your inbox.