How it works
SocGenie connects to a Microsoft 365 tenant with Microsoft consent, then runs security as a loop: assess, harden, detect, investigate, respond, improve. AI agents do the reading and the legwork. A person approves anything that changes the tenant.
Connect
You sign in with Microsoft and grant SocGenie delegated, least-privilege consent to read the tenant through Microsoft Graph. There are no agents to install and no log shippers to configure. Setup takes minutes, and the first scan starts straight away.
MSPs connect customer tenants through GDAP delegated access and see them side by side in the partner console. Your team joins through Entra invitations with role-based access, so each person sees only the customers they look after.
Assess
The scanner checks the tenant against five open frameworks: Maester, CIS, CISA SCuBA, EIDSCA and ORCA. Every finding carries a severity, the evidence behind it and remediation guidance drawn from a curated knowledge base.
Results are licence-aware. A check that needs a licence the tenant does not own is flagged as such, not marked as a failure. A PDF report lands in your inbox after each scan, and the free tier includes up to four scans a month.
Harden
Pick Intune policies from a curated catalogue derived from the OpenIntuneBaseline community project, add Conditional Access and Entra RBAC governance baselines, and deploy them as code through Terraform Cloud. You choose policy by policy. Nothing is pushed wholesale.
Once a baseline is deployed, SocGenie watches for drift against it and keeps the history of every deployment run. Customers can ask for a policy through a request workflow, so each change arrives with a record of who asked and who approved.
Detect
SocGenie deploys Microsoft Defender custom detection rules into the tenant, each mapped to MITRE ATT&CK. The library is updated continuously as new techniques and campaigns appear, so coverage does not go stale between reviews.
The coverage view shows which tactics and techniques the tenant is covered for, exports to ATT&CK Navigator, and suggests D3FEND countermeasures for the gaps. CISA KEV and threat-feed relevance are scored per client, so you know which campaigns matter to which customer. Managed MDR adds a Microsoft Sentinel analytics-rule baseline.
Investigate
When Microsoft Sentinel raises an incident, agents pick it up straight away. They read the incident, pull context from Sentinel data such as sign-in history, device compliance and mailbox rules, and enrich indicators with threat intelligence from sources such as AbuseIPDB, GreyNoise, urlscan and ThreatFox.
Each investigation is mapped to MITRE ATT&CK and ends in a written summary of what happened, what the evidence shows and what the agent proposes. You can watch the investigation stream live, replay any investigation step by step, and look up similar incidents across the fleet. Every agent action, tool call and decision is written to the audit trail.
A forwarding rule was created on p.novak's mailbox minutes after a sign-in from an address the user has never used. The source IP is flagged by two intelligence sources.
MITRE ATT&CK T1114.003, Email forwarding rule
Remove the rule, revoke sessions, require MFA re-registration. Waiting for approval.
Respond
Agents propose the containment they think fits: revoking sessions, disabling an account, removing a forwarding rule and similar Entra actions. The proposal goes to a person in Slack, Microsoft Teams or the SocGenie portal with the evidence attached. PagerDuty escalation reaches whoever is on call.
Once approved, the action runs through Microsoft Graph and is written to the audit trail with who approved it and why. For Managed MDR customers, Reddome analysts sit on the approval gates alongside your team. Nothing changes in your tenant without a human yes.
Improve
Drift, coverage gaps and repeat incidents feed the next scan and the next baseline. Fleet health signals in the partner console tell you which customer needs attention today, and a weekly digest email keeps the whole book in view.
A monthly access review report and a Defender assessment give you evidence to put in front of a customer. Jira tickets can be raised from findings, so remediation lands in the workflow you already run.
The rule
Read-only work is unlimited. Anything that changes a tenant waits for a person.
The agents can do as much of this as an incident needs, at any hour.
These wait at an approval gate in Slack, Microsoft Teams or the portal.
Every approval, and every rejection, is written to the audit trail with the evidence that was in front of the person who decided. For Managed MDR customers, Reddome analysts sit on the gates alongside your team.
Questions
Free scanner coming soon
Register interest and we will email you the day it opens. Free forever, no card, nothing to install.