M365Clarity Blog · 14 July 2026 · MSP AI Features Portfolio Management

Natural Language Queries Across Your Microsoft 365 Client Portfolio

An MSP managing 20 Microsoft 365 clients has a problem that single-tenant tools don't solve: knowing which client to call first. Not after an hour of opening dashboards, scanning tiles, and cross-referencing notes — right now, in the next two minutes before a client calls.

M365Clarity's Portfolio Query answers that question. Type a plain-English question about your client base and get an immediate, specific answer drawn from your clients' actual scan data.

What it looks like in practice

💬 "Which clients have red findings?"
TDR Capital has 3 critical findings — Identity: MFA not enforced on admin accounts, Conditional Access disabled; Threat: Defender for Business not configured.

UK Connect has 1 critical finding — Identity: Legacy authentication not blocked.

Contoso Ltd, Sharaf Shipping, and Vivantes Zorggroep have no critical findings.
💬 "Which tenants would fail Cyber Essentials right now?"
Based on current scan data, TDR Capital and UK Connect would likely fail Cyber Essentials. TDR Capital has failures in User Access Control (MFA gaps) and Malware Protection (Defender not configured). UK Connect has a failure in Firewalls (legacy auth enabled). The other three clients are passing all five Cyber Essentials control areas.
💬 "Show me a health score ranking for all clients"
1. Contoso Ltd — 82/100 (A)
2. Sharaf Shipping — 74/100 (B)
3. UK Connect — 71/100 (B)
4. Vivantes Zorggroep — 61/100 (C)
5. TDR Capital — 48/100 (D)

Portfolio average: 67/100. TDR Capital requires the most urgent attention.

No portal switching. No spreadsheet. No memory of which client you last looked at. One question, one answer, specific to your portfolio.

What kinds of questions it answers

Risk prioritisation
"Which client needs urgent attention?" / "Who has the most critical findings?" / "Which clients have deteriorating health scores?" — answered with specific client names and the driving factors.
Feature-specific queries
"Which clients have MFA issues?" / "Who still has legacy auth enabled?" / "Which tenants have SharePoint external sharing open?" — answered from actual scan results, not memory.
Compliance readiness
"Which clients would pass Cyber Essentials?" / "Who has DLP policies configured?" / "Which tenants are missing retention policies?" — drawn from the compliance and risk data in each client's scan.
Portfolio health overview
"Show health scores for all clients" / "Rank clients by security grade" / "Which clients improved since last scan?" — answered with ranked lists and client-specific context.
Plan-specific questions
"Which clients are on Business Premium?" / "Which tenants have Copilot licences?" — answered from the plan data recorded at scan time.

How data isolation works

This is the question that matters most for an MSP handling client data. Here is exactly how Portfolio Query is isolated:

🔒 Three layers of data isolation

1. Authentication. Every query requires a valid signed session. No session = no response.

2. Database scoping. The query that fetches tenant data is bound to your user ID: WHERE t.user_id = [your_id]. No SQL parameter comes from user input — your question goes only into the AI prompt, never into a database query. A crafted question cannot retrieve another client's data from the database.

3. Data injection. The AI only receives the text built from your D1 query results. It has no database access, no API access, no ability to make external requests. Even a question designed to extract other clients' data would return nothing — because that data is not present in the prompt. The guardrail is physical, not just a system instruction.

Client data from your M365Clarity account is never shared with, compared against, or visible to any other MSP account. This applies at the database layer, the application layer, and the AI layer.

What it does not do

Portfolio Query deliberately does not answer questions outside your client data. If you ask for general Microsoft 365 security advice, or anything unrelated to your portfolio, it redirects you back. This is intentional — an AI assistant that drifts off topic during portfolio analysis is more likely to cause confusion than resolve it.

Green (passing) features are not included in the query context. The AI works from red and amber findings across your clients. If you need the full feature breakdown for a specific client, that client's dashboard in M365Clarity shows the complete picture.

Available on the Multi-Tenant plan. Portfolio Query is in the MSP Portfolio → Query tab. Rate limited to 20 queries per hour. Answers reflect the latest complete scan per tenant.

The broader picture

Portfolio Query sits alongside two other features released at the same time: Portfolio Benchmarking, which ranks all your clients by health score and shows which features are most commonly failing across your client base; and Tenant-to-Tenant Benchmarking, which lets you compare any two clients side by side.

Together, these features shift the MSP experience from "I need to open five dashboards to understand my portfolio" to "I asked one question and know exactly which client to call and why."

See it in the live demo

The Portfolio Query demo shows real example questions and answers — no sign-in required.

Try the live demo →