Free compliance scanner · coming soon

See how your Microsoft 365 tenant is really configured.

Connect a tenant with Microsoft consent and scan it against five open frameworks: Maester, CIS, CISA SCuBA, EIDSCA and ORCA. Every finding comes with severity, evidence and the fix. Free forever, no card, nothing to install.

Coming soon: free forever, no card Nothing to install Up to four scans a month
Scan findings · contoso.onmicrosoft.com · example MaesterCISSCuBAEIDSCAORCA
SeverityFinding, evidence and fix
High
Conditional Access does not require MFA for all usersMaester
Evidence No enabled policy grants access only with multifactor authentication for all users. Fix Create a Conditional Access policy that requires MFA for all users, with a break-glass exclusion.
High
Legacy authentication is not blockedCIS
Evidence No Conditional Access policy blocks legacy authentication clients. Fix Add a policy that blocks legacy authentication for all users and cloud apps.
Medium
SharePoint allows anonymous sharing linksCISA SCuBA
Evidence Tenant sharing level is set to Anyone. Fix Set sharing to new and existing guests and expire existing anonymous links.
Medium
Users can consent to apps accessing company dataEIDSCA
Evidence User consent is allowed for all applications. Fix Restrict user consent and turn on the admin consent request workflow.
Low
DKIM signing is not enabled for contoso.co.ukORCA
Evidence DKIM is disabled for the domain; a DMARC record is present. Fix Publish the two selector CNAME records and enable DKIM signing in Defender for Office 365.
Licence
Safe Attachments for SharePoint, OneDrive and TeamsORCA
Flagged, not failed Needs Defender for Office 365, which this tenant does not own.
Sent
PDF report on its way to your inbox.

How it works

Consent, scan, report. Minutes, not a project.

There is no agent to deploy and no service account to create. SocGenie reads the tenant's configuration through Microsoft Graph and gives it back to you as findings.

01

Consent

Sign in with a Microsoft account that can grant consent for the tenant, and approve the read-only permissions SocGenie asks for. Nothing is installed and nothing is changed.

02

Scan

Run a scan whenever you want one. SocGenie checks the tenant against Maester, CIS, CISA SCuBA, EIDSCA and ORCA. Checks that need a licence you do not own are flagged, not failed.

03

Report

Findings appear in your dashboard with severity, evidence and the fix, and a PDF report lands in your inbox. Share it with a customer or an auditor as it is.

What you get

Findings you can act on, not a score to argue about.

Every check maps to a named control in an open framework. Every finding tells you what was seen and what to change.

Findings with severity, evidence and the fix

Each finding shows what the scanner saw in the tenant and the remediation guidance for it, drawn from a curated knowledge base.

Licence-aware results

Checks that need a licence the tenant does not own are flagged, not failed. You are never marked down for a feature you cannot switch on.

PDF report by email

A full scan report arrives in your inbox after every scan. It is ready to forward to a customer, a board or an auditor.

Dashboards for every role

A client view for the customer, an operator view for the engineer doing the work, and a partner view across every tenant you look after.

Up to four scans a month, on demand

Scan when it suits you: after a change, before a review, or when a customer asks. No schedule to wait for.

Monthly access review report

A PDF each month listing who holds privileged roles and access in the tenant, so reviews happen on time and with evidence.

The five frameworks

Open frameworks, not one vendor's opinion.

Every check in the scanner comes from an open, community-maintained project. You can read every test, and so can your auditor.

Maester

Open-source test framework for Microsoft 365

Built and maintained by Microsoft security practitioners in the community. Its tests cover Entra ID, Conditional Access, Exchange Online and Intune settings, and they are updated as Microsoft ships new controls.

CIS

Microsoft 365 Foundations Benchmark

The Center for Internet Security's consensus-built configuration recommendations for identity, Exchange, SharePoint, Teams and Defender, in two profile levels. It is the benchmark auditors ask about most.

CISA SCuBA

Secure Cloud Business Applications baselines

Prescriptive settings for Entra ID, Exchange Online, SharePoint and OneDrive, Teams and Defender, published by the US Cybersecurity and Infrastructure Security Agency for federal agencies and free for anyone to use.

EIDSCA

Entra ID Security Config Analyzer

A community project that checks tenant-level Entra ID settings, such as authentication methods, consent policies and default user permissions, against documented recommended values.

ORCA

Office 365 Recommended Configuration Analyzer

An open-source tool for Exchange Online Protection and Defender for Office 365 settings: anti-phishing, anti-spam, Safe Links, Safe Attachments, DKIM and DMARC.

What happens next

Fix the findings systematically, not one at a time.

The scanner tells you what is wrong. Zerotouch fixes it as code: Intune, Conditional Access and Entra RBAC baselines from a curated catalogue, deployed policy by policy into the tenant. Once a baseline is in place, the next scan shows what it closed.

Baselines as code

Pick the policies you want from the catalogue. They are deployed into the tenant as code, and every run is kept in history.

Drift detection

When a setting moves away from the deployed baseline, SocGenie flags it, so a quiet change in the admin centre does not undo last month's work.

Detections mapped to ATT&CK

Microsoft Defender custom detections deployed into the tenant and refreshed continuously, with a coverage map you can show a customer.

Questions

Scanner questions

Is the scanner really free?
Yes, and it opens soon. Register interest and we will email you the day it does. One Microsoft 365 tenant, up to four scans a month, free forever. There is no card, no clock and nothing you have to upgrade to.
What permissions does SocGenie need?
Read-only Microsoft Graph permissions, granted through Microsoft consent by an administrator of the tenant. Nothing is installed and a scan changes nothing in the tenant. You can revoke consent from Entra ID at any time.
What does licence-aware mean?
Some checks need a licence the tenant may not own, such as Defender for Office 365 or Entra ID P2. SocGenie flags those checks instead of failing them, so the report reflects what you can actually fix.
How do I fix what the scanner finds?
Every finding carries remediation guidance from a curated knowledge base, so your team can make the change by hand. If you would rather fix things systematically, Zerotouch deploys Intune, Conditional Access and Entra RBAC baselines as code and flags drift afterwards.
Can an MSP scan more than one customer?
Yes. Customers connect through GDAP delegated access and each tenant appears in the partner console. The free tier covers one tenant; the paid tiers add more tenants, more scans a month and more team members.
Where does my data live?
SocGenie runs on Microsoft Azure in the UK. Your configuration stays in your tenant; SocGenie reads it through delegated, least-privilege consent and never uses it to train models.
See pricing For MSP partners Security overview

Free scanner coming soon

Scan your first tenant today.

Connect with Microsoft consent, run a scan, and get findings with evidence and fixes, plus a PDF report in your inbox.