Free Microsoft 365 Security Scan — What It Finds and How It Works
The free scan reads your tenant read-only, runs the 155 Microsoft Graph rules of the 201-rule library, and returns your posture in 90 seconds. Here is exactly what data it touches, what it detects, and what to do with the result. The 46 Azure Resource Manager controls add on with admin consent.
What is simiriki's free scan?
simiriki's free scan is an automated evaluation of your Microsoft 365 tenant's security configuration. You connect your account and the system reads the 155 Microsoft Graph rules of the 201-rule library in read-only mode. The preview typically appears in minutes. The complete report is delivered on a best-effort basis, with a non-guaranteed estimated target of up to 1 hour. The 46 Azure Resource Manager controls require separate admin consent and Reader access.
We install no software. We access no emails or files. We only read security settings — MFA policies, email configuration, sharing permissions, and similar.
How it works step by step
1. Connect your Microsoft 365 + Azure
Click "Connect Microsoft 365 + Azure" and authorize read-only access via OAuth. The permission is granular: security configuration only, not content.
What you're authorizing:
- Read directory data (users, groups, policies)
- Read security policies (Conditional Access, MFA status)
- Read email authentication records (SPF, DKIM, DMARC)
- Read sharing and DLP configuration
What you're NOT authorizing:
- No email access
- No file access
- No calendar access
- No modification of any settings
2. Automatic scan
Our system evaluates the 155 Microsoft Graph rules of the 201-rule library, organized into categories (the 46 Azure Resource Manager controls add on with admin consent):
- Identity (IAM): MFA enrollment, Conditional Access policies, guest accounts, password policy, legacy auth, admin role assignments
- Email (EML): SPF records, DKIM signing, DMARC enforcement, mailbox forwarding rules, anti-phishing policies, safe attachments
- Data (DLP): External sharing settings, DLP policy configuration, sensitivity labels, audit log retention, information barriers
- Devices (MDM): Intune enrollment, Defender for Endpoint status, compliance policies, device encryption requirements
- Infrastructure (AZR): Azure resource configuration, network security groups, key vault policies, storage account settings (if Azure subscription connected)
Each rule produces one of three results:
- Pass — the control is properly configured
- Fail — the control is misconfigured or missing (this becomes a "finding")
- Error — the rule couldn't evaluate (usually a permission or license issue)
3. Immediate results
You receive:
- Posture score (0-100) with letter grade (A+ to F)
- Critical findings that need immediate attention — these are actively exploitable vulnerabilities
- High-severity findings that represent ongoing risk exposure
- Category breakdown showing which security domains have the most gaps
- Rule-by-rule detail for every evaluation
What the score means
| Score | Grade | Interpretation |
|-------|-------|----------------|
| 90-100 | A/A+ | Excellent posture. Few or no critical gaps. |
| 80-89 | B+ | Good posture with minor improvements needed. |
| 70-79 | B/B- | Decent foundation but notable gaps in some areas. |
| 60-69 | C | Average. Several high-risk findings need attention. |
| 40-59 | D | Below average. Significant vulnerabilities present. |
| 0-39 | F | Critical. Your tenant is actively at risk. |
Most SMBs score between 45 and 65 on their first scan. Don't panic — Microsoft 365's defaults prioritize ease of use over security, and most fixes take minutes to apply.
What data we don't access
To be absolutely clear:
- ❌ We don't read emails
- ❌ We don't access files in OneDrive/SharePoint
- ❌ We don't see user data (names, phones, addresses)
- ❌ We don't modify any configuration
- ❌ We don't store your credentials (OAuth tokens are encrypted and used once)
- ✅ We only read: security policies, authentication configuration, email DNS records, sharing permissions
All data processing occurs on our servers (Azure Container Apps in East US 2, encrypted at rest). Your OAuth token is encrypted with AES-256-GCM and deleted after the scan completes. Our Trust Center has full details.
What to do with your results
Score 80-100 (A/A+): Excellent. Subscribe to Operación to maintain this posture and get alerted if anything changes.
Score 60-79 (B/C): Good foundation with important gaps. Review the high-severity findings first. Most can be fixed in under an hour. For guided remediation, our free Auditoría includes a prioritized action plan.
Score 40-59 (D): Significant gaps. We recommend a structured remediation plan. Our free Auditoría includes expert analysis, a 90-day roadmap, and a results walkthrough session.
Score below 40 (F): Your tenant has critical vulnerabilities that are actively exploitable. Schedule a call to discuss urgent remediation steps.
Ready to find out your score?
The scan is free, takes 90 seconds, and doesn't require any installation. You'll know exactly where your Microsoft 365 security stands.
Is your business protected?
A free Microsoft 365 audit—the automated scan delivers a preview in 90 seconds. Find risks before they become incidents.