Microsoft 365 security, configuration, and getting more from the licences you're already paying for.
M365Clarity now shows Copilot ROI — cost per active user, monthly wasted spend in GBP, and a colour-coded signal for whether your investment is justified. See exactly how many licences are unused and what they're costing.
Ask plain-English questions across all your client tenants — "which clients have MFA issues?", "who needs urgent attention?", "show me a health score ranking." Answers draw only from your own portfolio data. Available on the Multi-Tenant plan.
M365Clarity generates a board-ready Microsoft 365 briefing in plain English — no jargon, no feature tables. Top risks with business impact, domain grades, and next steps. Download as PDF and share with your CEO or CFO.
M365Clarity doesn't just tell you what's wrong — it walks you through fixing it. Step-by-step guides built from your tenant data, with an inline AI assistant for when you get stuck on a specific step. From finding to fixed without leaving the dashboard.
A breakdown of the 15 Defender signals assessed — Secure Score, XDR incidents, Safe Attachments, ASR rules, attack simulation — and what the AI posture narrative tells you that individual scores don't.
Secure Score tells you what's configured. M365Clarity tells you whether anyone is using it — and what your users are doing when they can't. A plain-English comparison of what each tool covers and how they work together.
The Digital Friction report now quantifies MFA re-prompt fatigue, device compliance gaps, and app activation rates — turning security findings into specific adoption impact numbers your users will recognise.
Digital friction is when your IT configuration makes it harder to do the job than using a personal workaround. M365Clarity now identifies exactly where that's happening — and what your users are probably doing instead.
M365Clarity now generates a ready-to-send partner renewal briefing grounded in your tenant's active licences, inactive users, and AI Licensing Advisor conversations — so you go into renewal with the right data.
M365Clarity now shows exactly which users haven't signed in for 90+ days — by name, email, and last sign-in date — directly inside the Licence Recommendations tab and inside your partner renewal brief.
M365Clarity now answers licensing questions grounded in your tenant's active licences and your agreement type — what to procure, per-user vs tenant-wide requirements, and how CSP, EA, and MCA affect your options.
PIM, access reviews, leaver lifecycle workflows, emergency access accounts — what Entra ID governance actually means for an SMB and why the most damaging breaches are identity governance failures, not zero-days.
Anonymous links, default edit permissions, and no resharing restrictions — how to assess your SharePoint sharing risk, what the six key settings mean, and what to fix first.
M365Clarity shows exactly which users are inactive in Teams, Email, and OneDrive, which mailboxes are near quota, and which licences have never been activated — named user lists sorted by highest risk first.
Voice policies, PSTN connectivity, meeting recording governance, guest access, and external federation — M365Clarity scans all six and generates an AI risk assessment from your live tenant data.
M365Clarity grades each Viva workload — Engage, Learning, Connections, Amplify, Goals and Loop — and generates an AI adoption health narrative. Find out which Viva features you're paying for but not using.
A breakdown of every Intune health check — device compliance, WUfB update rings, BYOD and MAM coverage, config profile gaps, and the AI lost-device scenario that explains risk in plain English.
Microsoft raised prices 5-33% on 1 July 2026. Which plans changed, the new GBP prices in a single table, and the three things to do before your next renewal. Business Premium did not change — which changes the upgrade maths for a lot of organisations.
Most Teams rollouts stall at 35% and stay there. A practical four-week campaign you can run as an IT admin or MSP — champions, use cases, measurement, and the one thing that actually shifts user behaviour.
The announcement, the day-before reminder, and the week-one follow-up — three email templates you can adapt and send. Covers Known Folder Move, shared drive migration, and the three things that make users resistant to file changes.
MFA enforcement, Conditional Access, external sharing restrictions — each makes your org more secure and creates friction. How to frame each change so users understand it, and why communicating first is always cheaper than the support calls that follow.
The exact OAuth scopes M365Clarity requests, what each one reads, and why read-only delegated access is enforced by Microsoft's API — not just by convention.
Read article →Third-party enterprise apps with Mail.ReadWrite.All or Files.ReadWrite.All permissions are a silent breach risk. How to find them, what to do, and how M365Clarity surfaces this automatically.
Read article →Device compliance, WUfB update rings, BYOD MAM coverage, configuration profiles, and the AI lost-device scenario. Every check explained.
Read article →Microsoft 365 is one product but it has at least 15 separate admin portals. Here is what each one does and why having this many dashboards makes visibility genuinely hard.
Microsoft's first Autopilot agent announced at Build 2026. What Scout does, what it accesses, and the configuration work your tenant needs before deploying autonomous AI agents.
Read article →How MSPs can audit Microsoft 365 security and configuration across every client tenant without manual checks, spreadsheets, or per-client admin access.
Read article →Most organisations pay for Defender XDR but only have a fraction configured. Safe Attachments gaps, ASR rules, MDI sensors, attack simulation — the most common gaps across real tenants.
Read article →A practical checklist covering the full Microsoft Purview data governance stack. What to check, what the common gaps are, and how to fix them.
Read article →A complete guide to Entra ID Governance. What PIM, access reviews, lifecycle workflows, and entitlement management do and how to configure each one.
Read article →Business Basic tenants average 10+ findings on first scan. Business Premium averages 30+. Here's what to check and why SMBs are not immune to M365 configuration gaps.
Read article →CA governance score, PIM permanent assignments, at-risk users from Entra ID Protection, MFA method strength, and stale accounts. The identity gaps that are behind most Microsoft 365 breaches.
Read article →Cowork went GA on 17 June 2026. Admins must enable usage-based billing before 1 July or Frontier users lose access. Here is the 4-step readiness checklist covering licences, billing, and governance controls.
Read article →Agent 365 is GA. The governance control plane for AI agents only works if 7 tenant prerequisites are in place. Here is the readiness checklist — with a free scan to check them automatically.
Read article →You've deployed Copilot. Now how do you prove anyone is using it? Track adoption by workload, identify drop-off, and build a defensible ROI case.
Read article →Conditional Access is the most powerful security control in Microsoft 365. Here's what it is, which licences you need, and the five policies every tenant should have.
Read article →Legacy authentication protocols bypass MFA entirely. Here's what they are, how attackers exploit them, and how to block them.
Read article →SharePoint allows unauthenticated file access by default. Here's how to review your sharing policy and tighten it without breaking collaboration.
Read article →Compliance policies, WUfB update rings, BYOD app protection, config profile gaps, and the lost device scenario — the Intune checks that actually matter for MSPs and IT teams.
Read article →WHfB replaces passwords with device-bound credentials. Here's the correct deployment model, what goes wrong in hybrid environments, and how to measure adoption gaps in your tenant.
Read article →Intune is included in Business Premium but most tenants never configure it. Here's what it does and how to get started in under an hour.
Read article →Data Loss Prevention policies stop sensitive data leaving your organisation. Here's how to configure your first DLP policy in Microsoft 365.
Read article →Before deploying Copilot, your tenant permissions and security settings need to be in order. This checklist covers everything to review first.
Read article →Without governance, Teams sprawls fast — orphaned teams, guest access leakage, app risks. Here are eight settings to get it under control.
Read article →Audit logs are essential for incident response and compliance. Here's what Microsoft 365 captures, how to search it, and how to ensure it's enabled.
Read article →Defender for Business is included in Business Premium but often not set up. Here's what EDR adds over standard antivirus and how to enable it.
Read article →Three email authentication standards that together prevent domain spoofing. Here's what each does and how to configure them in Microsoft 365.
Read article →Guide · 20 Jun 2026
Understand how your tenant's health score is calculated, what it means, and how to improve it.
Guide · 20 Jun 2026
M365Clarity ranks your findings by impact so you know exactly where to start.
Guide · 20 Jun 2026
Generate a plain-English narrative about your M365 tenant health suitable for sharing with leadership or clients.
Guide · 20 Jun 2026
Scan history lets you see whether your health score is improving and when specific changes happened.
Guide · 20 Jun 2026
Pick any two scans and see a side-by-side diff of every feature that changed status.
Guide · 20 Jun 2026
M365 Backup provides point-in-time restore for Exchange, SharePoint, and OneDrive. Here's what M365Clarity checks.
Guide · 20 Jun 2026
M365Clarity checks your Security Copilot entitlement and whether your tenant is ready to use it effectively.
Guide · 20 Jun 2026
Too many permanent global admins create unnecessary risk. M365Clarity shows you exactly what you have.
Guide · 20 Jun 2026
Unmanaged guest accounts accumulate over time. M365Clarity shows you how many exist and whether policies are configured.
Guide · 20 Jun 2026
PIM gives admin roles on a time-limited basis. M365Clarity checks whether it's configured for your tenant.
Guide · 20 Jun 2026
Inactive user accounts are a common visibility gap. M365Clarity identifies them and the licences they're consuming.
Guide · 20 Jun 2026
Third-party apps with broad permissions are a common blindspot. M365Clarity shows you what's connected and why it matters.
Guide · 20 Jun 2026
M365Clarity shows you exactly how many licences are assigned, active, and idle across your tenant.
Guide · 20 Jun 2026
Unused licences cost real money. M365Clarity identifies assigned-but-inactive licences and quantifies the wasted spend.
Guide · 20 Jun 2026
M365Clarity identifies features that are configured but not being used by your team.
Guide · 20 Jun 2026
Ask natural language questions about your scan results without navigating through individual tabs.
Guide · 20 Jun 2026
Track health score commitments across client tenants and identify clients whose configuration has drifted.
Guide · 20 Jun 2026
Push M365Clarity findings directly to email, CSV, or Jira so your team can track and action them.
A practical checklist covering 30+ settings to review when an MSP takes on a new Microsoft 365 client tenant.
Read article →Cyber Essentials maps directly to Microsoft 365 settings. Here's what to configure across all five controls to pass your certification.
Read article →A plain-English walkthrough of the key M365 security settings every IT Manager should review — MFA, Conditional Access, external sharing, and more.
Read article →Account takeover is the number one cause of Microsoft 365 breaches. Here's why MFA alone isn't enough and how to enforce it properly.
Read article →Microsoft Secure Score is built in. M365Clarity is independent. Here's what each one tells you and why IT Managers use both.
Read article →