Integrations

Built on Microsoft. Connected with consent.

SocGenie is Microsoft-only. It reads each tenant and runs approved actions through Microsoft Graph, with app consent and nothing to install. Around that sit the tools your team already uses for approvals, tickets, intelligence and billing.

Nothing to install Delegated, least-privilege consent Every action in the audit trail
Microsoft GraphNothing to install
Reads the tenant and runs approved actions, with app consent.
Microsoft. Microsoft 365, Entra ID, Intune, Defender, Sentinel, Log Analytics and Terraform Cloud. The platform SocGenie is built for.
contoso.onmicrosoft.com01/06

How it connects

One consent. One path. Nothing on your endpoints.

Everything SocGenie reads, deploys or changes goes through Microsoft Graph with permissions the tenant owner has consented to.

Microsoft consent

SocGenie's app is consented once in the tenant, with delegated, least-privilege permissions. Customer data stays in the customer's tenant and is read through Microsoft Graph.

Nothing to install

No agents on endpoints, no log shippers, no middleware. Connect a tenant in minutes and run the first scan the same day.

Nothing changes without a yes

Reading is unlimited. Anything that changes a tenant waits for a person to approve it, and the decision is written to the audit trail with the evidence behind it.

What SocGenie connects to

Every integration, and what SocGenie does with it.

Grouped by the job they do in the loop. Nothing here is a placeholder: if it is listed, it works today.

01

Microsoft

The platform SocGenie is built for. Each service below is read, hardened or watched as part of the loop.

Microsoft 365

The tenant SocGenie assesses: posture checks run against its settings, and every finding carries severity, evidence and a fix.

Free and above
Entra ID

Sign-in, user and role data feed the posture scan, the monthly access review report and every investigation, and Conditional Access and RBAC baselines are deployed here.

Free and above
Intune

Baseline device policies from a curated catalogue are deployed into Intune, policy by policy, and drift against them is flagged.

Zerotouch
Microsoft Defender

Custom detection rules mapped to MITRE ATT&CK are deployed into Defender and kept current, and the Defender assessment shows what is switched on.

Zerotouch
Microsoft Sentinel

Managed MDR customers get a Sentinel analytics-rule baseline, and every Sentinel incident is ingested and triaged by agents around the clock.

Managed MDR
Microsoft Graph

The one path SocGenie uses to read a tenant with delegated consent and to run containment a person has approved.

All tiers
Log Analytics

Investigations query the tenant's Log Analytics data so the evidence behind a verdict is in the write-up.

Managed MDR
Terraform Cloud

The deployment engine behind Zerotouch: baselines are applied as code and every run is kept in history.

Zerotouch
02

Approvals and notifications

Where a person says yes, and where the reports and pages arrive.

Slack

Approval requests land in a channel you choose, a person approves or rejects there, and the decision is written to the audit trail.

Microsoft Teams

The same approval flow for teams that live in Microsoft 365, with the decision recorded the same way.

PagerDuty

High-severity incidents page whoever is on call, using the escalation policies you already run.

Email

Scan reports, the weekly digest and the monthly access review report arrive as PDFs in your inbox.

Outbound webhooks

Events are pushed to a URL you control, so findings and incidents can reach tooling you already run.

03

Ticketing

Remediation tracked where your engineers already work.

Jira

Create a Jira ticket from any finding, so the fix is owned, scheduled and closed in the tool your team already uses.

Zerotouch and above
04

Threat intelligence

The frameworks detections are mapped to, and the sources agents consult while they triage an incident.

MITRE ATT&CK

Every detection is mapped to a technique, the coverage view shows what you cover, and you can export it to ATT&CK Navigator.

MITRE D3FEND

Countermeasures are suggested for the techniques you see, so hardening follows detection.

CISA KEV

Known exploited vulnerabilities are matched against each client, so you know which advisories matter to whom.

VirusTotal

File, URL and IP reputation while an incident is being triaged.

AbuseIPDB

Reported abuse history for the source addresses in an incident.

Shodan

What an address exposes to the internet: open ports, services and banners.

GreyNoise

Whether an address is background internet noise or something aimed at you.

urlscan

A rendered look at a suspicious URL and what it loads.

ThreatFox

Indicators of compromise shared by the abuse.ch community, matched against an incident.

AlienVault OTX

Community threat pulses matched against the indicators in an incident.

Have I Been Pwned

Whether a user's address appears in a known breach.

05

Billing

There is no self-serve checkout. Paid tiers are scoped with you and activated by Reddome.

Stripe

Once a paid tier is scoped on a short call, Reddome sends you a Stripe payment link.

06

Platform

For teams that want SocGenie's data in their own tooling.

API keys

Programmatic access to SocGenie for your own dashboards and automation, with keys stored hashed and every request scoped to your organisation.

Microsoft-only, on purpose

Deep on one platform, not shallow on ten.

SocGenie does not connect to other identity providers, endpoint platforms or SIEMs. The checks, the baselines and the detections are all written for Microsoft 365, and the agents know how the platform's data fits together. That is how it stays accurate.

  • One consent and one path: everything reads and acts through Microsoft Graph
  • Baselines and detections written for Intune, Entra ID, Defender and Sentinel
  • Licence-aware: checks that need a licence you do not own are flagged, not failed
  • The same audit trail across every tenant you connect
See how the loop works Security and trust

Questions

Integration questions

Do I need to install anything to connect a tenant?
No. SocGenie connects through Microsoft consent and reads the tenant through Microsoft Graph. There are no agents on endpoints, no log shippers and no middleware. Setup takes minutes.
What permissions does SocGenie ask for?
Delegated, least-privilege permissions to read the tenant, plus what is needed to deploy baselines and detections and to run containment a person has approved. Customer data stays in the customer's tenant and is never used to train models. Read the security overview
Does SocGenie connect to platforms other than Microsoft?
No. SocGenie is Microsoft-only: Microsoft 365, Entra ID, Intune, Microsoft Defender and Microsoft Sentinel. Going deep on one platform is how it stays accurate.
How do I get data out of SocGenie?
PDF reports by email, Jira tickets from findings, outbound webhooks to a URL you control, and API keys for programmatic access.
How do approvals reach my team?
Approval requests are sent to Slack, Microsoft Teams or the SocGenie portal, and PagerDuty pages whoever is on call for high-severity incidents. Every decision is written to the audit trail. Read the explainer

Free scanner coming soon

Connect a tenant with Microsoft consent.

Run the free posture scan on one Microsoft 365 tenant and see findings with evidence and fixes, plus a PDF report in your inbox. Nothing to install.