Security State

Know the security state of your entire Microsoft environment.

Identities. Devices. Data. Apps. Infrastructure. AI. Defend 365 continuously understands what is exposed, what changed, why it matters and what should happen next.

Powered by 700+ continuous Microsoft 365 security tests.

  • Identities
  • Devices
  • Data
  • Apps
  • Infrastructure
  • AI

Security state

CONTROLLED, WITH EXPOSURE

72 / 100

+4 this month

Your environment improved this month, but three material exposures remain. Identity is stable. Data protection needs attention. AI adoption introduced two new governance gaps.

The score is a summary, not the truth. Material exposures below decide what actually happens next.

  • 3material exposures
  • 12risks being remediated
  • 4new risks this month
  • 17risks resolved
  • 6configuration drifts
  • 2emerging AI risks
  • 1expert engagement active

Environment model

Select a domain

Six domains, one connected model. Lines are real dependencies — the paths risk travels along.

Identities

Strong authentication, privileged access has 2 gaps

82
+5 · last 30 days

Material exposures

  • 2 privileged identities sit outside the intended just-in-time access model
  • Break-glass accounts are not covered by an alerting rule

What changed recently

  • Number matching enforced for all Authenticator users (11 days ago)
  • 1 new Global Administrator assigned outside change window (3 days ago)
Affected assets
1,840 identities · 9 privileged accounts
Ownership
Identity team · M. Bakker
Business impact
A single standing administrator compromise would give full tenant control.
Recommended next action
Convert 2 standing administrators to PIM-eligible with approval.
CISNIS2 / CBWMicrosoft Zero TrustISO 27002

What changed since your last visit

Material exposures

Risk that spans domains. Not a list of failed checks — a prioritized executive backlog.

SIA executive brief

What should I care about today?

Three developments deserve your attention. External data exposure increased after a SharePoint configuration change. Two privileged identities remain outside your target access model. Copilot usage increased while AI data controls remain incomplete.

Defender engagements

  • Purview remediation60%

    Defender engaged · Data

  • Identity exposure cluster20%

    Scoping with Defender · Identities

One security state. Multiple compliance lenses.

The same underlying exposure can affect CIS, NIS2 / CBW, BIO and NEN 7510 at once. Frameworks are evidence on top of the state, not the starting point.

All figures on this page are seeded demo data for illustration.

Two levels, one truth

The same data, at the resolution each role needs.

Executives get state, exposure, ownership and progress. Engineers get controls, evidence, drift and remediation detail. Switching views never changes the underlying data.

Security State view

  • · Executive security state and qualitative summary
  • · Six domains as one connected model
  • · Material cross-domain exposures with blast radius
  • · Trends, business impact, ownership and progress
  • · SIA executive brief and Defender engagements

Technical view

  • · 700+ continuous controls and tests
  • · Raw findings with configuration evidence
  • · Drift history per setting and change
  • · Step-by-step remediation and automation detail
  • · Framework mapping down to control level

Security graph

Risk does not respect domain boundaries.

A privileged identity, an over-permissioned app and a confidential SharePoint site are three ordinary findings. Together they are one material exposure.

Defend 365 connects the environment model so exposure is expressed as a dependency path, with an owner, a recommended route and a way to hand the whole thing to a Defender.

SIA executive brief

What should I care about today?

Three developments deserve your attention. External data exposure increased after a SharePoint configuration change. Two privileged identities remain outside your target access model. Copilot usage increased while AI data controls remain incomplete.

Walk the security state demo