Microsoft 365 Security & Compliance
Know where your Microsoft 365 tenant stands—then prove it.
TenantSentinel builds tools for the people responsible for a Microsoft 365 tenant: IT admins, MSPs, and the organizations that eventually have to answer to an auditor or an insurer. Two products, one job—understand your real security posture, and produce the evidence that demonstrates it.
Both run read-only. Neither modifies your tenant, deploys an agent, or asks you to change a firewall rule.
Free for organizations with up to 50 licensed users. No credit card, no expiry.
Two Products, One House
Recon tells you where you stand. Proof shows everyone else.
Security Assessment
TenantSentinel Recon
An on-demand assessment of your Microsoft 365 security posture. Run a scan and get a single health score backed by a ten-tab executive report: MFA coverage, Conditional Access validation, privileged role risk, enterprise app permissions, licensing waste, security gaps, and remediation runbooks that tell you exactly what to fix.
Written for the person who has to explain the risk to leadership, not just the person who has to fix it.
CMMC Evidence · Early Access
TenantSentinel Proof
Technical evidence for a CMMC 2.0 / NIST SP 800-171 assessment, collected read-only from your tenant. Proof evaluates all 110 controls and produces a tamper-evident evidence ledger, a full assessor report, and an SSP-ready evidence packet with the underlying data for every control.
It is an evidence engine, not a compliance platform. It gathers what your tenant can prove and states plainly what it cannot.
Built on the Same Principles
Read-only, always
Both products request read-only Microsoft Graph permissions and hold no write scopes. They cannot create, modify, or delete anything in your tenant. Consent is granted once by your Global Administrator and can be revoked by you at any time.
Your data stays yours
Scans run from a Windows desktop application on your machine. Reports and evidence are written locally. The only network calls a scan makes are read-only requests to Microsoft.
Honest output
If a check cannot run, we say so rather than guessing. If a control is outside what a tenant scan can establish, we print it and explain why. Neither product will tell you that you passed something it did not actually verify.
Who We Build For
IT admins and MSPs
You manage one tenant or fifty. You need to know which ones are exposed, what it would cost to fix, and how to show progress over time.
Security and risk leaders
You need a number you can bring to a board, backed by findings specific enough that your team knows what to do on Monday.
Defense contractors and the compliance-bound
You have an assessment coming, or an underwriter asking questions. You need evidence with a verifiable chain of custody, not a folder of screenshots.
Start with a free assessment
Recon is free for organizations with up to 50 licensed users—no credit card, no expiry, no sales review. Run a scan and see your score.