Platform

A deep technical engine with a calm surface.

Defend 365 turns 700+ continuous tests into one honest security state - then makes sure something actually happens next.

Security state

72/ 100

Continuous tests
700+
Changes last 7 days
14
Critical exposures
3
  • Identities82
  • Devices74
  • Data58
  • Apps69
  • Infrastructure79
  • AI51
Seeded example tenant. Your own state appears minutes after onboarding.

Inside the product

The working surface, with seeded data.

Switch tenant, choose frameworks, run a scan, open a failed control, ask SIA beside the evidence, accept a risk with a note, or look at which Microsoft services drive the risk.

Risk score

68

+4 over the selected range

Contoso Ltd. · last 30 days

Trend

4 frameworks applied

Passed486Failed105Investigate38Not Run42Skipped34

Attention now

  • 12Open high severity failures

    Entra ID and Exchange Online lead the list

  • 3Regressed since last scan

    Previously passing controls that now fail

  • 42Coverage gaps

    Tests not run, mostly licensing or permission scope

  • 9Fixed this period

    Confirmed by re-test, not self-reported

Seeded demo data modelled on the Defend 365 product. 700+ security tests run against a connected tenant.

What the platform does

Nine things you actually do in Defend 365.

This is the product as it works today: tenants, scans, tests, evidence, SIA in context, governed exceptions, change over time, service hotspots and expert help.

01

See the state

Risk score, trend, test status and what needs attention now

The dashboard opens on a risk score for the selected date range, the trend behind it, the full test status breakdown (passed, failed, investigate, not run, skipped) and an Attention now area that surfaces open high severity failures, regressions, coverage gaps and what was fixed.

02

Work across tenants

Tenant switching and an all-tenants overview

Search and switch tenant from the top bar, or read every tenant in one table: risk score, high severity failures, regressed, fixed and last scan. Built for teams that carry more than one Microsoft 365 environment.

03

Drill into the evidence

The test table, the test detail and the licence reality

Every test shows ID, title, framework, status, severity and its change history inline (Not Run → Failed → Changed). Open one and you get the concrete result from your tenant, the details behind the check, its category and tags, the remediation action, and the minimum Microsoft licence required next to the licence actually detected.

04

Understand with SIA

A drawer scoped to the exact control you are reading

Ask SIA from a test row or the test view and it opens beside the evidence, already holding the test, its output in your tenant and its framework mapping. Ask it in plain language, or use suggested questions like explain this test in simple terms, which risks are mitigated, or show me the PowerShell fix. SIA gives guidance; it does not decide for you whether to automate, assign internally or bring in a Defender.

05

Govern exceptions

Risk acceptance with a mandatory note

Not everything gets fixed, and pretending otherwise is how posture tools lose credibility. Mark a test as risk accepted and Defend 365 requires a note before saving it. Notes also carry ordinary operational context, such as who is working on a finding and when the change window is.

06

Measure change

Every scan compared to the one before it

Reports show the risk score and all test totals, plus what moved since the previous scan: newly passed, new failures, regressed and fewer skipped. Filter on status, severity, framework, service and required licence, narrow to Changed only or risk accepted, ask for a SIA report summary, and export to CSV.

07

Focus by service

Service hotspots

See which Microsoft services actually drive your open risk: Entra ID, Exchange Online, SharePoint Online, Microsoft 365 Apps, Teams, Intune, Defender for Office 365 and Purview, each with assessed coverage, failed count, high or critical count, and a direct route into the tests behind it.

08

Control the scope

Framework selection and on-demand scans

Toggle the frameworks that count: CIS, NIS2, CISA, ISO 27002, the Defend365 baseline, Copilot Readiness, BIO-related coverage and Purview MCCA. Scoring and reporting follow your selection. Run a new scan whenever you need a fresh read rather than waiting for the schedule.

09

Bring in expertise

Defenders, the expert layer

When a finding, a service cluster or a whole framework needs specialist hands, Defenders connects it to screened Microsoft security experts with the technical context attached. This is the expert layer of the Defend 365 ecosystem, not a replacement for your own team.

Coverage

Six domains, one connected model.

Identities, devices, data, apps, infrastructure and AI are tested as one environment, because that is how they are attacked.

Data

External sharing and information protection create exposure

Business impact
Confidential information is reachable without authentication.
Next action
Restrict tenant sharing and expire anonymous links on confidential sites.
Underneath
26 failed of 143 continuous tests

Connect in minutes. Not a project.

Self-service onboarding in minutes, no agents to deploy. Defend 365 focuses on preventing avoidable exposure before an incident happens - it does not replace a SOC or MDR service.

  1. 01

    Connect the tenant

    Consent once. Testing starts immediately.

  2. 02

    Get the first state

    Findings, severity and framework mapping in minutes.

  3. 03

    Decide the route

    Automate, assign internally, or send to a Defender.

Want to see SIA inside a control?

How SIA works →