How it works

One loop, run over every tenant you look after.

SocGenie connects to a Microsoft 365 tenant with Microsoft consent, then runs security as a loop: assess, harden, detect, investigate, respond, improve. AI agents do the reading and the legwork. A person approves anything that changes the tenant.

Nothing to install Free scanner coming soon, no card Human approval on every change
Example investigation · fabrikam.comHigh
14:02:11incidentSentinel · New inbox rule forwarding to an external address · p.novak@fabrikam.com
14:02:12contextsign-in history, MFA methods, recent mailbox rule changes, device compliance
14:02:14intelsign-in IP flagged by AbuseIPDB and GreyNoise
14:02:15attackMITRE ATT&CK T1114.003 · Email forwarding rule
14:02:16similarmatching pattern seen at contoso.com · replay linked
14:02:17proposalremove the rule, revoke sessions, require MFA re-registration
14:02:17approvalwaiting for a person in Microsoft Teams
14:09:03approvedby MSP engineer · executed through Microsoft Graph
14:09:04auditevery step, tool call and decision written to the trail
Approvals in Slack, Microsoft Teams or the portalReplay any investigation
The loop · six stages, each feeding the nextSelect a stage to jump to it
  1. AssessScan against five open frameworks
  2. HardenBaselines deployed as code
  3. DetectDetections mapped to ATT&CK
  4. InvestigateAgents triage every incident
  5. RespondA person approves containment
  6. ImproveWhat was learned feeds the next pass
Before the loop

Connect

Connect with Microsoft consent. Nothing to install.

You sign in with Microsoft and grant SocGenie delegated, least-privilege consent to read the tenant through Microsoft Graph. There are no agents to install and no log shippers to configure. Setup takes minutes, and the first scan starts straight away.

MSPs connect customer tenants through GDAP delegated access and see them side by side in the partner console. Your team joins through Entra invitations with role-based access, so each person sees only the customers they look after.

What you see
  • A Microsoft consent screen listing the permissions requested
  • A tenant dashboard within minutes of consent
  • For MSPs, the customer listed in your fleet with its scan status
Connect a tenant · fabrikam.comConnected
1
Sign in with MicrosoftGlobal administrator or GDAP delegated role
Done
2
Review and grant consentDelegated, least-privilege Microsoft Graph permissions
Done
3
First posture scanMaester, CIS, CISA SCuBA, EIDSCA and ORCA
Running
MSP? Connect customers through GDAPNothing installed in the tenant
01 Free

Assess

See where the tenant stands, with evidence for every finding.

The scanner checks the tenant against five open frameworks: Maester, CIS, CISA SCuBA, EIDSCA and ORCA. Every finding carries a severity, the evidence behind it and remediation guidance drawn from a curated knowledge base.

Results are licence-aware. A check that needs a licence the tenant does not own is flagged as such, not marked as a failure. A PDF report lands in your inbox after each scan, and the free tier includes up to four scans a month.

What you see
  • Findings grouped by severity, each with evidence and a fix
  • A PDF scan report by email
  • Dashboards for the client, the MSP operator and the partner
Posture scan · fabrikam.comCompleted today
High
Legacy authentication is still allowedCIS · CISA SCuBA
Fix available
High
MFA not required for all admin rolesMaester · EIDSCA
Fix available
Medium
Anonymous sharing links allowed in SharePointCISA SCuBA
Fix available
Medium
Outbound spam policy uses defaultsORCA
Fix available
Licence
Safe Links not configuredNeeds Defender for Office 365
Flagged, not failed
PDF report sent to security@fabrikam.comScans used this month: 1 of 4
02 Zerotouch

Harden

Deploy baselines as code, one policy at a time.

Pick Intune policies from a curated catalogue derived from the OpenIntuneBaseline community project, add Conditional Access and Entra RBAC governance baselines, and deploy them as code through Terraform Cloud. You choose policy by policy. Nothing is pushed wholesale.

Once a baseline is deployed, SocGenie watches for drift against it and keeps the history of every deployment run. Customers can ask for a policy through a request workflow, so each change arrives with a record of who asked and who approved.

What you see
  • A catalogue of policies with per-policy selection
  • Deployment run history for the tenant
  • Drift alerts when the tenant moves away from its baseline
Baseline catalogue · contoso.comDeployed as code
Device compliance baselineIntune · Windows
Deployed
Microsoft Defender antivirus settingsIntune · Windows
Deployed
Require MFA for all usersConditional Access
Drift detected
Block legacy authenticationConditional Access
Deployed
Limit permanent Global Administrator assignmentsEntra RBAC
Not selected
Last run: today · Terraform CloudPolicy request open: 1
03 Zerotouch

Detect

Detections mapped to ATT&CK, kept current for you.

SocGenie deploys Microsoft Defender custom detection rules into the tenant, each mapped to MITRE ATT&CK. The library is updated continuously as new techniques and campaigns appear, so coverage does not go stale between reviews.

The coverage view shows which tactics and techniques the tenant is covered for, exports to ATT&CK Navigator, and suggests D3FEND countermeasures for the gaps. CISA KEV and threat-feed relevance are scored per client, so you know which campaigns matter to which customer. Managed MDR adds a Microsoft Sentinel analytics-rule baseline.

What you see
  • A coverage map you can show a customer, with Navigator export
  • A rule browser with the ATT&CK mapping for each detection
  • D3FEND suggestions and CISA KEV relevance for each client
ATT&CK coverage · contoso.comExport to Navigator
CoveredPartialGap, with D3FEND suggestion
Library updated continuouslyCISA KEV relevance scored per client
04 Managed MDR

Investigate

Every Sentinel incident triaged and enriched, day and night.

When Microsoft Sentinel raises an incident, agents pick it up straight away. They read the incident, pull context from Sentinel data such as sign-in history, device compliance and mailbox rules, and enrich indicators with threat intelligence from sources such as AbuseIPDB, GreyNoise, urlscan and ThreatFox.

Each investigation is mapped to MITRE ATT&CK and ends in a written summary of what happened, what the evidence shows and what the agent proposes. You can watch the investigation stream live, replay any investigation step by step, and look up similar incidents across the fleet. Every agent action, tool call and decision is written to the audit trail.

What you see
  • A live investigation stream and a replay of any past investigation
  • Similar-incident lookup, an attack heatmap and SOC metrics
  • A full audit trail for every incident
Investigation summary · fabrikam.comHigh
New inbox rule forwarding mail to an external address
What happened

A forwarding rule was created on p.novak's mailbox minutes after a sign-in from an address the user has never used. The source IP is flagged by two intelligence sources.

Evidence
  • Sign-in from an unfamiliar location, no compliant device
  • Rule forwards all mail to an external domain
  • No MFA method change; sessions still valid
Mapped to

MITRE ATT&CK T1114.003, Email forwarding rule

Proposed

Remove the rule, revoke sessions, require MFA re-registration. Waiting for approval.

Replay · Similar incidents · Audit trailWatched live in the SOC queue
05 Managed MDR

Respond

The agent proposes containment. A person approves it.

Agents propose the containment they think fits: revoking sessions, disabling an account, removing a forwarding rule and similar Entra actions. The proposal goes to a person in Slack, Microsoft Teams or the SocGenie portal with the evidence attached. PagerDuty escalation reaches whoever is on call.

Once approved, the action runs through Microsoft Graph and is written to the audit trail with who approved it and why. For Managed MDR customers, Reddome analysts sit on the approval gates alongside your team. Nothing changes in your tenant without a human yes.

What you see
  • An approval request with the evidence and the proposed actions
  • Approve, reject or ask for more, from Teams, Slack or the portal
  • The decision and the outcome in the audit trail
SocGenie in Security approvals · Microsoft Teams
Remove the forwarding rule and revoke sessions for p.novak@fabrikam.com?
A new inbox rule forwards all mail to an external address. It was created minutes after a sign-in from an IP flagged by two intelligence sources. Mapped to ATT&CK T1114.003, Email forwarding rule. Full investigation attached.
ApproveRejectAsk for more
Escalates to on-call through PagerDuty if nobody responds. Executed through Microsoft Graph on approval.
06 All tiers

Improve

What the loop learns feeds the next pass.

Drift, coverage gaps and repeat incidents feed the next scan and the next baseline. Fleet health signals in the partner console tell you which customer needs attention today, and a weekly digest email keeps the whole book in view.

A monthly access review report and a Defender assessment give you evidence to put in front of a customer. Jira tickets can be raised from findings, so remediation lands in the workflow you already run.

What you see
  • Fleet health and an activity feed across every customer
  • A weekly digest email and a monthly access review report as PDF
  • Jira tickets raised from findings
Weekly digest · your fleetSent weekly by email
fabrikam.comDrift on the Conditional Access baseline
Review
contoso.comMonthly access review report ready
PDF
adventure-works.comPosture scan due this week
Scan
tailwindtraders.comCoverage improved after the detection library update
Info
Findings raised as Jira ticketsFleet health sorted by attention

The rule

What the agents may and may not do.

Read-only work is unlimited. Anything that changes a tenant waits for a person.

Without asking

Read, enrich, correlate, write

The agents can do as much of this as an incident needs, at any hour.

  • Read incidents, sign-in logs, device and mailbox context from Sentinel and Graph
  • Enrich indicators with threat intelligence
  • Map activity to MITRE ATT&CK and look up similar incidents
  • Write the summary and propose the next step
  • Record every step in the audit trail
Only with a human yes

Anything that changes the tenant

These wait at an approval gate in Slack, Microsoft Teams or the portal.

  • Revoke sessions or disable an account
  • Remove a mailbox rule or require MFA re-registration
  • Deploy or change a baseline policy
  • Any other Entra or Intune action that changes state

Every approval, and every rejection, is written to the audit trail with the evidence that was in front of the person who decided. For Managed MDR customers, Reddome analysts sit on the gates alongside your team.

Questions

Frequently asked

Do I need to install anything?
No. You sign in with Microsoft and grant consent, and SocGenie reads the tenant through Microsoft Graph with delegated, least-privilege permissions. There are no agents, collectors or log shippers to deploy.
How do MSPs connect customer tenants?
Through GDAP delegated access. Each customer appears in your partner console with its scan status, drift, detection coverage and open incidents. Your team joins through Entra invitations with role-based access. See the partner programme
Can the agents change anything in a tenant on their own?
No. Agents read, enrich, correlate and propose. Any action that changes a tenant waits for approval in Slack, Microsoft Teams or the SocGenie portal, and the decision is written to the audit trail with the evidence behind it. Read the explainer
Which tier do I need for each stage?
Assess is free, forever, with no card, and opens soon. Harden and Detect come with Zerotouch. Investigate and Respond come with Managed MDR, where Reddome analysts also sit on the approval gates. Improve runs across all tiers. Compare the tiers

Free scanner coming soon

Start with the first stage today.

Register interest and we will email you the day it opens. Free forever, no card, nothing to install.