Free M365 security scanner

Score your M365 security posture.

Run a read-only PowerShell scan. Get a 100-point SecureGauge score, an HTML report, and a prioritized list of the tenant settings worth fixing first.

Read-only. No credit card. Your tenant stays in your control.

securegauge / report

PS C:\> .\SecureGauge.ps1 -ShowReport

Reading approved posture signals...

Writing evidence report...

Read-only scan complete.

M365 security score

94/100

Evidence before action.

94

MFA coverageAVAILABLE

Mailbox forwardingOPTIONAL EXO

Sharing policyOPTIONAL SPO

Evidence, not alarmism

One number. The details behind it.

Each deduction maps to a visible check and a practical remediation path. Start with the highest-impact issues. Keep the report for your next review.

01

A calculated SecureGauge score out of 100

02

A self-contained HTML report with a screenshot-ready scorecard

03

Prioritized critical, high, medium, and informational findings

04

Signal coverage notes when a permission or optional module is unavailable

What it checks

Find the settings attackers count on.

Baseline scan

Graph-only starts with identity evidence.

MFA registration coverage and direct high-impact admin account activity run with Microsoft Graph read scopes. Mail and sharing checks become available only when you choose the optional read-only modules.

Identity

MFA registration coverage

Scores the percentage of users reported as MFA registered through Microsoft Graph.

Privilege

Stale direct admin accounts

Flags enabled, directly assigned high-impact Entra admin accounts with no recent successful sign-in signal.

Mail

Mailbox forwarding

Optional Exchange Online read checks mailbox-level forwarding. It does not claim to inventory inbox rules.

Sharing

External sharing policy

Optional SharePoint Online read checks tenant and site sharing policy. It does not enumerate every link or file.

Permission boundary

Read the tenant. Change nothing.

SecureGauge requests delegated Microsoft Graph read permissions. It never creates, updates, deletes, remediates, or changes tenant configuration. It does not install modules or consent permissions for you.

Default Graph delegated scopes

User.Read.All

Directory.Read.All

AuditLog.Read.All

Reports.Read.All

RoleManagement.Read.Directory

Optional Exchange Online and SharePoint Online checks are clearly marked in the report. If a signal cannot be read, SecureGauge reports it as unavailable and does not deduct points.

Your score is the starting point

Run the scan. See the gaps. Fix what matters.

Work the critical and high findings first. Use a focused remediation script for a clear configuration gap, or bring in a posture review when the report points to wider tenant risk.

Includes a plain-text quick-start guide

Included download

PowerShell scanner and quick-start guide

View quick-start