Help & Knowledge Base
Everything you need to get the most from M365Clarity.
Contents
🚀 Getting started
✨ AI features
- AI features guide
- Priority Actions
- Executive Summary
- Incident Readiness
- Backup & Recovery
- Device Security Posture
- Compliance Posture
- CA Coverage Map
- App Audit
- Defender AI Posture
- Entra Governance Posture
- Teams Governance
- Teams AI Analysis
- Teams Phone & Voice
- Viva Adoption
- SharePoint AI Sharing Posture
- Intune Health Report
- 90-Day Adoption Roadmap
- M365 Changelog Monitor
- Upcoming Microsoft Retirements
- Conversational Remediation
- Executive Briefing PDF
- Predictive Risk Alerts
- Weekly Health Digest
- Health Score Trend
- Fixed Since Last Scan
📊 Features & data
- Shareable report links
- Viewer access
- Copilot Readiness
- Copilot & AI tab
- Scheduled scans
- PDF reports
- Guest account audit
- Licence utilisation
- Licence Waste Detection
- Workload Adoption
- Adoption by Department
- Cost Per Active User
- Compliance Risk Register
- SharePoint Site Health
- Unlocked but Unused
- Cyber Essentials Readiness
- Admin account review
- SLA tracking
- Scan comparison
- Ticket export
- Remediation tracking
- Exchange Online checks
- Microsoft Purview checks
🏢 Multi-Tenant (MSP)
🔒 Security & compliance
❓ FAQ & billing
Connecting your Microsoft 365 tenant
When you sign in for the first time, Microsoft will show a permissions consent screen listing what M365Clarity is requesting access to. There is an important checkbox at the bottom of this screen:
This checkbox only appears if you are signed in as a Global Administrator. If you do not tick it, M365Clarity's permissions apply only to your own user account — tenant-wide settings (MFA policies, SharePoint configuration, Conditional Access, audit logs, etc.) will not be readable and your scan will return incomplete or empty results.
Who needs to connect the tenant?
You must sign in as a Global Administrator of the tenant you want to scan. This is required because many of the configuration settings M365Clarity checks are only readable by a tenant admin. If you sign in as a regular user, the consent checkbox will not appear and tenant-wide data will not be accessible.
What role does the connecting account need?
For full coverage, the account you use to connect should be a Global Administrator. For complete SharePoint and OneDrive results, the connecting account must have the SharePoint Administrator or Global Reader role. Surprisingly, Global Administrator alone is not listed as a permitted role for the SharePoint settings API — this is a Microsoft platform decision confirmed in their official API documentation. You can assign SharePoint Administrator in Microsoft Entra ID → Roles and administrators → SharePoint Administrator.
Does my connection expire?
Microsoft access tokens expire after 1 hour. M365Clarity automatically refreshes your token in the background each time you open the dashboard — you should never need to reconnect unless you revoke access from the Microsoft side or the refresh token itself expires after 90 days of inactivity. If a refresh fails, an amber banner appears on your dashboard with a Re-scan button to try again.
What if I forgot to tick the box?
If you signed in without ticking "Consent on behalf of your organisation", your scan will likely show many features as Not Verified or return empty results. To fix this:
- Go to Account → Connected Tenants and click Disconnect next to the affected tenant
- Click + Add Tenant (or Connect Tenant if you have no tenants connected)
- Sign in again with your Global Administrator account
- On the Microsoft consent screen, tick "Consent on behalf of your organisation" before clicking Accept
What permissions are requested?
All scopes are read-only. M365Clarity cannot modify your tenant, send emails, change settings, or access the content of messages or files. A full list of scopes is in the Security & data privacy section below.
How M365Clarity works
M365Clarity connects to your Microsoft 365 tenant using read-only OAuth and checks your actual configuration via the Microsoft Graph API. It does not install any agents, scripts, or extensions in your environment.
The process is:
- You sign in with your Microsoft 365 account
- M365Clarity requests read-only Graph API permission for your tenant
- A scan runs — typically completing in 20–40 seconds
- Results are displayed as Configured ✓, Needs Review ⚠, or Not Verified for each feature
- Paid plans unlock AI-powered analysis, compliance mapping, and PDF reports
Feature scan explained
Feature Health Score
Every scan produces a Feature Health Score from 0–100. The score is calculated from your configurable features only (not always-on productivity services):
- Configured (green) — scores full points
- Needs Review (amber) — scores half points
- Needs Attention (red) — scores zero
- Not Verified (grey) — not counted
What "Not Verified" means
A grey "Not Verified" tile means M365Clarity attempted to check that feature but could not produce a reliable result. This happens for one of two reasons:
- Microsoft does not expose this data via the API. Some Microsoft 365 settings cannot be read programmatically — they are only visible in the admin portal. Where this is the case, the tile explains what to check manually and where to find it.
- A permissions error occurred during the scan. Certain Graph API endpoints require specific roles (for example, the Security Reader or Exchange Administrator role) in addition to Global Administrator. If a permission error occurred, the tile will say so and explain which role is needed.
Not Verified tiles do not penalise your score. They are excluded from the Feature Health Score calculation entirely.
Why some tiles don't appear at all
M365Clarity only shows feature tiles that are relevant to your Microsoft 365 plan. Features your licence does not include are hidden from the main tile grid — they appear in a collapsible "not available on your plan" section below the grid instead, so you can see what exists at higher tiers without cluttering your results. Features can also be hidden where an evaluator has been permanently retired — because the API endpoint no longer exposes the data needed for a reliable assessment.
Configurable vs Always-On features
Configurable services are features included in your licence that require admin action to enable or configure — things like Conditional Access, DLP policies, or Teams meeting policies.
Always-On services are core productivity features included as part of your licence — Exchange Online, SharePoint, Teams, OneDrive, Forms, Planner, and Stream. These tiles show as green to confirm the service is part of your licenced plan. They do not indicate whether the service is currently online or experiencing issues — M365Clarity is not a monitoring tool. For live service health, check the Microsoft 365 Service Health dashboard in your admin centre.
What plans are detected?
M365Clarity automatically detects your Microsoft 365 licence plan via the subscribed SKUs API. Supported plans include Business Basic, Business Standard, Business Premium, Office 365 E1/E3/E5, Microsoft 365 E3/E5/E7, F1/F3, Education A1/A3/A5, and Entra ID P1/P2.
AI features guide
M365Clarity's AI features are powered by Anthropic's Claude. They are designed to translate raw scan data into plain English guidance — no technical background required.
Plain English explanations Free
Every feature card in the scan results includes a plain English description of what the feature does and why it matters to your business. Click any feature to see a one-sentence business impact statement. This is available to all users on the free tier — no upgrade required.
Priority Actions Pro
Claude analyses all red and amber findings from your scan and produces a ranked action list — ordered by business impact and effort, not just severity. Each action includes a one-sentence rationale, an effort rating (Low / Medium / High), an estimated time to complete, and a direct link to the relevant Microsoft documentation. Priority Actions covers every feature M365Clarity scans — including identity, threat protection, compliance, Purview, Intune, and collaboration — so the list reflects your full tenant posture, not just the most obvious gaps. Find it under Insights → Priority Actions. A ⟳ Regenerate button appears after a new scan has run, since new data would change the recommendations.
Executive Summary Pro
Generates a board-ready summary of your Microsoft 365 health — written for a business owner, IT Director, or CFO audience, not a technical team. The summary includes: a one-sentence headline specific to your tenant's situation, a 3–4 paragraph narrative referencing actual scores and domain grades, a Domain Health section showing AI-assessed grades for Incident Readiness, Backup & Recovery, CA Coverage, and Intune Health, a Purview compliance snapshot showing how many elements were assessed and how many have critical gaps, a Top Risks section with business impact and recommended fix for each risk, a What's Configured Well list, and a 5–7 step recommended next steps plan. The summary uses cached results from other AI tabs — opening Incident Readiness, Backup & Recovery, and Intune Health before generating the summary gives it the most data to work with. Find it under Insights → Executive Summary.
AI explanations on click Pro
Pro users can click any feature card to open a side panel with a full AI-generated explanation — written specifically for your tenant's configuration. Instead of "MFA registration is amber", you get "Most of your staff have set up MFA, but 3 admin accounts haven't. Admin accounts are the highest-value target for attackers — this should be resolved urgently."
Explanations are generated once per feature per scan and cached — you can re-open them instantly without waiting.
Step-by-step setup guides Pro
In the same side panel, switch to the "How to fix" tab to get a generated step-by-step guide for that specific feature. The guide includes:
- Estimated time and difficulty level
- What you need before you start
- Numbered steps with exact admin centre navigation instructions
- How to verify the fix worked
- How to undo the change if needed
Guides are tailored to your specific Microsoft 365 plan — instructions for Business Basic will differ from E3 where relevant.
Priority Actions Pro
Analyses your red and amber findings and produces up to 6 prioritised fix actions ranked by business impact. Each action includes an effort estimate, impact rating, rationale, step-by-step instructions, and a link to Microsoft documentation.
AI change alerts Pro
When a scheduled scan detects a configuration change vs the previous scan (for example, if SharePoint external sharing moved from amber to red), an AI-written email is sent explaining:
- What changed (feature name, previous status, new status)
- Why it matters in plain business language
- What action to take
Change alerts are only sent when something actually changes — you will not receive emails for scans where nothing has changed.
Compliance Mapping Pro
Maps your scan results against three frameworks: Cyber Essentials, ISO 27001, and NIST CSF. Each framework shows a grade, pass/fail percentage, and per-control status based on your actual configuration.
Executive Summary Pro
Generates a board-ready summary with a risk level, top risks (with business impact), positive findings, and recommended next steps — written for a non-technical executive audience.
What If & Licence Advisor Pro
Ask what-if questions about your tenant configuration before making changes — for example: "What if I enabled external email forwarding?", "What if I removed permanent Global Admin assignments?", or "What would happen to my score if I fixed all RED items?" Each response describes the security posture impact and compliance implications based on your actual scan data. 10 prompts per day.
The same chat also answers licensing questions grounded in your tenant's active licences and Microsoft's published licensing terms. For example: "What licences would I need to add Copilot for Microsoft 365?", "Do I need to license all users for Defender for Business or just specific ones?", or "What is the difference between Defender for Business and Defender for Endpoint P2?" For more accurate answers, set your Agreement Type (CSP, EA, MCA, etc.) and Microsoft Cloud (Commercial, GCC, etc.) under Tenant Settings — the AI uses these to tailor its answers to how your agreement type affects procurement options.
When the AI detects a specific licensing intent — something you've expressed a decision to act on, such as "Add Copilot for 10 users" — a 💼 Licensing intent detected chip appears below the response. Tap Add to renewal briefing to save it. Saved intents accumulate in the Licence Recommendations tab under "Licensing changes queued" and are automatically included in your next partner renewal brief. Tap Dismiss to discard the chip without saving.
Responses are informational only and do not constitute security, IT, or licensing advice. Always verify licensing requirements with your Microsoft partner before purchasing.
Adoption Coach Pro
Adoption by Department
Teams, Email, and OneDrive adoption rates broken down by department — pulled from the department field in your Azure AD user profiles. Departments are sorted by lowest overall adoption first, so the teams that need the most attention appear at the top. Tap any department row to expand it and see per-workload adoption rates (Teams, Email, OneDrive separately). Users without a department set in Azure AD are grouped under "No department set". Data is drawn from the per-user activity reports already collected at scan time — no additional Graph calls are made at load time except one call to fetch department names. Cached after first load. Pro plan only. Find it in the Workload Adoption tab.
Adoption Coach is built into the Workload Adoption tab — it is not a separate navigation item. For each workload with adoption below 70%, a 🎯 Adoption Coach toggle appears below the adoption bar. Click it to generate a specific action plan grounded in your tenant's actual scan results. The plan includes a root cause (for example, if Teams adoption is low and meeting policies are on defaults, it identifies that Teams has not been formally deployed), three concrete steps with effort ratings (Low/Medium/High) and the exact admin centre path for each, an expected outcome, and an optional user communications note suggesting what to tell end users before or after the change. The plan is generated on first click (10-15 seconds) and cached per scan — re-opening is instant.
Change Management Pro
The Change Management tab analyses your scan data and workload adoption rates to identify which organisational transitions are currently in progress — for example, moving from email to Teams meetings, or from a shared network drive to SharePoint. Rather than reporting at service level, it infers the specific transition underway and positions your organisation within the ADKAR change model (Awareness, Desire, Knowledge, Ability, Reinforcement). For each detected transition it shows: what the scan evidence suggests, where your organisation likely is in the change journey, the ADKAR stage with rationale, a recommended intervention specific to that stage, a realistic timeframe, and a link to the relevant M365Clarity blog guide. Results are generated on first click and cached per scan.
Digital Friction Pro
The Digital Friction tab reframes your tenant's amber and red configuration findings through an adoption lens — identifying not just what's misconfigured, but what that misconfiguration is causing your users to do instead. It produces a friction score (0–100) and grade (Low / Medium / High / Critical), a set of friction points, a Quick Wins section, and an AI narrative summary.
Each friction point has four components: What's happening — the specific configuration gap causing friction. Quantified impact (shown in a cyan panel when data is available) — a specific number from your tenant scan, such as "22 of 24 Conditional Access policies have no session controls configured" or "68% of licensed users have never activated a desktop app". Likely workaround — what users are probably doing instead, for example "Users are likely sharing files via personal Google Drive instead of SharePoint". How to fix — the single most effective configuration change to reduce this friction.
The six friction signals M365Clarity detects and quantifies: MFA re-authentication fatigue — reads session controls from each active Conditional Access policy to identify policies with no frequency configuration, aggressive re-auth intervals, or every-sign-in requirements. Device management gap — cross-references Intune enrolled device count against licensed user count; when less than 50% of users have managed devices, unmanaged users face MFA re-prompts on every session. App activation gap — identifies licensed users who have never activated any Microsoft 365 desktop or mobile app (restricted to browser-only access). External sharing restrictions — detects over-restriction (sharing fully disabled) which drives users to personal file sharing services. OneDrive sync without device governance — flags unrestricted sync to unmanaged devices. Email activity gaps — high zero-activity rate alongside misconfigured EOP suggests over-aggressive spam filtering.
Results are generated using AI and cached per scan. Use the Regenerate option to refresh after a new scan or configuration change. Rate limited to 5 regenerations per hour.
Security Incident Readiness Pro
A five-pillar security readiness model (Detect, Protect, Recover, Identity, Compliance) that scores your tenant across controls drawn from your existing scan results. Each pillar receives an individual score (0–100) and grade (A–F), with a visual progress bar and a list of failing or warning controls. An AI narrative explains the overall score in plain English. Find it under Security & Compliance → Incident Readiness.
Backup & Recovery Readiness Pro
Assesses how recoverable your data is if ransomware or accidental deletion strikes today. Evaluates Microsoft 365 Backup status for Exchange, SharePoint, and OneDrive individually, along with retention policies, audit trail coverage, and ransomware prevention controls. Includes an AI-generated ransomware scenario. Find it under Security & Compliance → Backup & Recovery.
Device Security Posture Pro
A four-category scored assessment of your device security posture — Credential Protection (LAPS, Credential Guard, passkeys), Endpoint Hardening (BitLocker, WDAC, ASR rules, update rings), Device Management (Intune enrolment, compliance policies, Autopilot), and Threat Detection (Defender for Endpoint, Vulnerability Management, Endpoint Analytics). Each category is scored and graded, with an AI narrative on the real-world risk from your weakest controls. Find it under Security & Compliance → Device Security Posture.
Compliance Posture Pro
Compliance Risk Register
The Compliance tab has two views, toggled at the top: Risk Register (default) and Framework View. The Risk Register shows only failing and partial controls across all three frameworks (Cyber Essentials, ISO 27001, NIST CSF), ranked by exposure width — the number of failing features mapped to each control — rather than by a colour label. A control with 6 red features ranks above a control with 1 amber feature, even if both are categorised as "High". Exposure score = (red features × 3) + (amber features × 1). A secondary sort by control domain criticality breaks ties: access control and identity controls rank above audit and policy controls at equal exposure. Each row shows the severity chip (High/Medium/Low) as a visual indicator, the framework badge, and an "N of M features failing" count showing the actual exposure width. The Framework View shows the original accordion view with pass/fail/partial breakdown per framework. Empty state: "No failing controls" when all assessed controls pass.
A four-category scored assessment of your data governance and compliance readiness — Data Protection (DLP, sensitivity labels, Copilot DLP), Data Lifecycle (retention policies, Records Management, Data Lifecycle Management), Audit & Investigation (audit logging, eDiscovery), and Insider Risk (Insider Risk Management, Communication Compliance, Adaptive Protection). An AI narrative explains the regulatory exposure from your weakest areas. Find it under Security & Compliance → Compliance Posture.
Conditional Access Coverage Map Pro
Analyses every Conditional Access policy in your tenant to surface coverage gaps — scenarios where users, apps, or sign-in conditions have no active CA policy protecting them. Critical gaps (no enforced MFA-for-all, legacy auth not blocked, non-compliant devices permitted) are flagged with severity levels. All policies are shown with their attribute chips (users, apps, conditions, grant controls) and an enforced/report-only filter. AI-generated gap explanations explain the business risk for each uncovered scenario. Find it under Security & Compliance → CA Coverage Map.
Application Audit Pro
Lists every third-party enterprise application and OAuth app with access to your tenant, scored by permission risk. High-risk permissions (Mail.ReadWrite, Files.ReadWrite.All, Directory.ReadWrite.All) are highlighted. Unverified publishers are flagged separately. Each app shows which users have consented, which permissions are granted, and a risk level (High / Medium / Low). Find it under Security & Compliance → App Audit. Requires the Application.Read.All consent scope — if you connected before this scope was added, reconnect to enable it.
90-Day Adoption Roadmap Pro
The 90-Day Adoption Roadmap generates a sequenced, dependency-mapped plan for enabling and adopting Microsoft 365 features — specific to your tenant's actual scan data and licence plan. It organises work into three phases: Phase 1 Foundation (Weeks 1–4) covers security and identity basics that everything else depends on, using only features flagged red or amber in your scan. Phase 2 Collaboration (Weeks 5–8) covers workload adoption tools once the foundation is in place. Phase 3 Optimisation (Weeks 9–12) covers advanced features, governance, and automation. The roadmap also surfaces three quick wins — changes that take under an hour with immediate high impact. Every step includes an effort rating, expected outcome, dependency chain, and the exact admin centre link to make the change. Results are generated on first click and cached per scan.
M365 Changelog Monitor Pro
The M365 Changelog Monitor fetches the last 90 days of Microsoft Message Centre announcements via Graph API and uses AI to filter them to what is relevant for your specific plan and tenant configuration. Each announcement is categorised as New Feature, Change, Deprecation, Security, or Action Required. Urgent items — those requiring action before a deadline or with security implications — are flagged with a red border and appear first. Each entry includes a plain-English explanation of why it matters for your plan and exactly what action to take (or confirms no action is required). You can filter posts by All, Urgent, or Action Required. The monitor refreshes every 24 hours. Note: this feature requires the ServiceMessage.Read.All Graph permission. If this was not granted when you connected your tenant, reconnect from the Account page to add it.
July 2026 — new permission added: M365Clarity added DeviceManagementServiceConfig.Read.All to its scope list (v10). This unlocks Windows Autopilot, Intune Enrolment Restrictions, and Remote Help visibility. If you connected your tenant before 15 July 2026, you will see a "Reconnect recommended" banner — clicking it takes you through a one-time consent step to grant the new permission. No data is lost and your scan history is preserved.
Upcoming Microsoft Retirements Pro
The Deprecated Features section appears below the Changelog Monitor and shows Microsoft retirement notices specifically — features, APIs, or authentication methods that Microsoft has announced will be withdrawn. Each notice shows the retirement date, the affected service, urgency (Critical / Warning / Watch / Future based on days remaining), and an AI-generated one-sentence summary of the impact on your tenant. Notices that affect services active in your tenant are shown first with a "Your tenant" badge. This section reads from the same pre-fetched Message Centre data as the Changelog Monitor — it does not make additional API calls. Note: if the Changelog Monitor has not been loaded for this scan, load it first and then the retirement section will populate automatically.
Conversational Remediation Pro
Every step in every AI Setup Guide has a built-in "🤔 Stuck on this step?" button. Click it to open an inline question input scoped specifically to that step. Ask what's going wrong — for example, "Error connecting with Connect-SPOService" or "The policy saved but it's not showing as enforced" — and the assistant responds with help specific to that exact step. The response is deliberately narrow: it can only answer questions about the specific remediation step you're on. It cannot provide general Microsoft 365 advice, discuss other features, or go off topic. If you ask something outside the scope of the step, it redirects you back. This constraint is intentional — a broad AI assistant drifting off topic during active remediation is more likely to cause problems than solve them. Rate limited to 10 questions per hour per user. Available to Pro and Multi-Tenant accounts.
Executive Briefing PDF Pro
The Executive Briefing is a board-ready document generated from your Executive Summary scan data. Unlike the technical PDF report — which lists all feature checks, scores, and remediation steps — the executive briefing is written entirely in plain English for a CEO, CFO, or board audience. It contains: an overall grade and health score with a plain-English narrative, domain grades for Identity, Threat, Compliance, Devices, and Collaboration, top risks described as business impacts with recommended actions, what is working well, a compliance overview where relevant, Copilot readiness if applicable, and numbered next steps. To generate it: open the Executive Summary tab and wait for it to load, then scroll to the bottom and click "📄 Download Executive Briefing." The document opens in a new tab with a "Download PDF" button that triggers your browser's print-to-PDF dialog. The Executive Summary tab must have been loaded at least once before the briefing can be generated. If your account has a company logo uploaded, it will appear in the briefing header.
Predictive Risk Alerts Pro
Predictive Risk Alerts appear on the Overview tab when time-bound risk signals are detected in your tenant's scan data. Currently M365Clarity generates two types of alert: retirement-based alerts, which flag Microsoft retirement notices that directly affect services active in your tenant (for example, SMS/voice MFA retiring on 1 September 2026 for tenants with users registered for those methods), and trend-based alerts, which surface features that have degraded across two or more consecutive scans, suggesting an underlying configuration issue that is not being consistently remediated. Alerts are colour-coded by urgency — Critical (less than 30 days to deadline), Warning (30–90 days), Watch (90–180 days), and Future (beyond 180 days). The card is hidden when no alerts exist. Note: trend-based alerts require at least two complete scans to generate comparison data. More predictive signals will be added as scan history grows across the platform.
Report logo Pro
Pro and Multi-Tenant accounts can upload a company logo from the Account page. Your logo appears in the header of PDF reports exported from M365Clarity — replacing the M365Clarity brand text. Supported formats: PNG, JPG, SVG, WebP. Maximum size: 512KB. Upload or remove your logo at any time from Account → Report Logo.
Client notes Multi-Tenant
Multi-Tenant accounts can add internal freetext notes to each client tenant directly from the MSP Portfolio dashboard. Notes are visible only to your MSP account — they are never shared with clients or included in client-facing reports. Notes are limited to 2,000 characters per client. Use them to track context such as renewal dates, outstanding actions, or client-specific configuration decisions. Notes are saved immediately on clicking Save and persist across sessions.
Natural Language Portfolio Queries Multi-Tenant
The Query tab in the MSP Portfolio lets you ask plain-English questions about your client tenants and get instant answers drawn from their scan data. Type a question — for example, "Which clients have MFA issues?", "Show health scores for all clients", or "Which tenants have SharePoint external sharing enabled?" — and M365Clarity returns a plain-English answer referencing your specific clients by name.
What you can ask: Any question about the security posture, health scores, specific features, or findings across your portfolio. The AI answers from the actual scan data — not generically.
Guardrails: Queries are scoped strictly to your own connected tenants. The AI only receives data from your portfolio — it physically cannot access or reference data from any other account. Even a question attempting to retrieve another organisation's data would return nothing, because that data is not present in the context. This is enforced at the data layer, not just the prompt layer.
Limitations: Green (passing) features are not included in the query context to keep the payload compact — if you ask what's passing for a client, the AI will direct you to that client's dashboard for the full picture. The query reflects the latest complete scan per tenant. Rate limited to 20 queries per hour. Available to Multi-Tenant accounts only.
Portfolio Benchmarking Multi-Tenant
The Benchmarks tab in the MSP Portfolio ranks all your client tenants by health score, shows each client's position relative to your portfolio average, and surfaces which features are most commonly failing across clients. This lets you identify systemic gaps — if 80% of your clients have a failing DLP policy, that's a practice-level issue to address, not a one-off remediation. Benchmarks are scoped to your own portfolio only — client data is never compared against or shared with other MSP accounts.
Multi-Tenant Portfolio AI Summary Multi-Tenant
From the Portfolio view, click "AI Summary" to get an AI-generated overview of your entire client portfolio in one paragraph — including urgent cross-tenant actions and highlights. Results are cached for 6 hours and can be refreshed on demand.
Cross-tenant pattern detection Multi-Tenant
The "Patterns" tab in the Portfolio view uses AI to detect configuration issues that appear across multiple client tenants — for example, "4 of your 8 clients have SharePoint external sharing open." Each pattern includes which tenants are affected and a recommended remediation approach. This lets you address systemic issues systematically rather than one client at a time.
AI risk ranking Multi-Tenant
The "Risk Ranking" tab orders all your client tenants from highest to lowest risk, with an AI-generated explanation of what is driving each client's risk level and what the recommended first action is. Use this to prioritise which client to call first.
Client report narrative Multi-Tenant
In the Executive tab for any tenant, MSP users see a "Generate Client Report Narrative" button. This produces a full set of professional paragraphs suitable for a client-facing report or QBR document — introduction, quarterly summary, key findings, recommended investments, and a conclusion. Click "Print / Export PDF" to save it.
Cross-tenant weekly digest Multi-Tenant
Every Monday, Multi-Tenant users automatically receive a single email summarising every client tenant — health score, number of red/amber issues, and week-on-week trend. Tenants with 5+ critical issues are flagged for immediate attention at the top of the email.
You can also trigger the digest manually from the MSP Portfolio view using Send weekly summary — useful if you want it before Monday or are setting up a new client.
Bulk schedule all tenants Multi-Tenant
From the MSP Portfolio view, click Schedule all weekly to set weekly automated scans across all connected client tenants in one action. Scans are staggered and run at 06:00 UTC on their scheduled day. You can override individual tenants in their tenant settings after bulk scheduling.
Return Summary Pro
When you open the dashboard after being away for more than 24 hours, a card appears at the top of the Overview tab showing exactly what changed since your last visit — which features improved, which regressed, how many days have passed, and an AI sentence describing the most significant change. Dismiss it with the ✕ button once read. Shown once per scan, not on every page load.
Proactive AI Insights Pro
Each time you open a scan, Claude independently analyses your full configuration and surfaces one observation worth flagging — a pattern you might have missed, a contradiction between two features, or a compounding gap. It appears as a 💡 card at the top of the Overview tab. Generated once per scan, cached for 7 days, and different to the Return Summary (which tracks changes over time).
Health Score Benchmarking Pro
The History tab shows your health score trend over time alongside the average score across all tenants M365Clarity monitors. A benchmark card compares your score to the average, with context about how many tenants are included. An AI sentence below the chart describes your direction — for example "Your health score has improved 8 points across your last 5 scans. A few more fixes could reach an A grade." The benchmark is anonymised and aggregated; no individual tenant data is shared.
Health Score Trend (Overview tab)
A compact sparkline card on the Overview tab showing your health score across every complete scan — from first connection to today. The card shows your current score, best score, total scan count, and a trend badge (↑ improving / ↓ declining / stable). Green line when improving, red when declining. Requires at least 2 complete scans to appear. Pro plan only. Find it on the Overview tab below This Month's Focus.
Fixed Since Last Scan (Overview tab)
A factual feature-by-feature comparison between your most recent scan and the one before it. Shows two sections: ✅ Fixed — features that moved from red or amber to green since the previous scan, and ⚠️ New Issues — features that moved from green to red or amber. Each row shows the feature name and the status change (e.g. "red → green"). A score delta badge shows the overall point change between scans. The card is hidden when there is no previous scan to compare against, or when no features changed status. Find it on the Overview tab below the Health Score Trend card. Available on all plans.
Shareable Report Links Pro
From the Overview tab, click 🔗 Share report to generate a read-only public link. Anyone with the link can view the report — no M365Clarity account required. Links expire after 30 days and can be regenerated at any time. The public report includes: health score and grade, a full feature list grouped by category with red/amber/green status for each item, and — when you have already opened the relevant AI tabs — an enriched executive summary with domain health grades (Incident Readiness, Backup & Recovery, CA Coverage, Intune Health), top risks with business impact and recommended fix, a Purview compliance snapshot, what's configured well, and recommended next steps. The AI enrichment is sourced entirely from cached results — no additional API calls are made when the link is opened. Use it to share scan results with an IT director, auditor, board member, or external consultant.
Viewer access Pro
Pro and Multi-Tenant users can invite one read-only viewer per tenant. The viewer sees the full dashboard including all AI tabs but cannot run scans, change settings, or invite additional viewers. Invite a viewer from Settings → Share access. The viewer receives an email invitation and is prompted to create a free M365Clarity account if they do not have one. This is different from the public report link — a viewer has a persistent account with full dashboard access, while a public link recipient sees a read-only report page with no login required.
PowerShell Commands Pro
Setup guides include a PowerShell command wherever one is applicable. Click any red or amber feature to open the feature drawer, then click Get Fix Guide to generate a step-by-step guide for your specific tenant. Commands are shown in a copyable code block. A separate verification command is shown at the end of each guide to confirm the fix has taken effect. Commands require a PowerShell session connected to your Microsoft 365 tenant (typically via the Microsoft Teams or Exchange Online PowerShell modules).
Teams & Slack Webhook Alerts Pro
Go to Account → Alert Webhook to connect M365Clarity to your Microsoft Teams or Slack channel. Paste your incoming webhook URL, select the platform type, and save. When a scheduled scan detects a configuration change, M365Clarity posts a message to your channel naming the specific features that changed. This is in addition to the email alert — you can use both, or just the webhook. Webhook URLs are stored encrypted per tenant and can be removed at any time.
Weekly Health Digest Pro
Every Monday morning, Pro and Multi-Tenant users automatically receive a weekly digest email. It shows your current health score, the trend versus the previous scan, the number of remaining issues, and a brief summary of any notable change from the week. If your score dropped, the email says so and links back to Priority Actions. If the score is unchanged, the digest still sends with a summary of open issues — keeping the platform visible even in quiet weeks. No configuration required — the digest fires automatically as long as you have a completed scan in the last 14 days.
SharePoint & OneDrive AI Sharing Posture Pro
Found under Security & Compliance → Teams & SharePoint, the AI Sharing Posture card analyses your tenant's external sharing configuration and produces a plain-English risk assessment. It evaluates six key settings from the SharePoint tenant settings API: sharingCapability (who can share externally), defaultSharingLinkType (what type of link is created by default), defaultLinkPermission (whether default links grant view or edit access), sharingDomainRestrictionMode (whether sharing is restricted to specific domains), preventExternalUsersFromResharing, and requireAcceptingUserToMatchInvitedUser.
The feature returns a risk level (low / medium / high / critical), a one-sentence headline specific to your tenant's settings, a narrative explanation in plain English, a breakdown of specific risks with severity labels, what is configured well, and a list of recommended actions with effort ratings. Results are generated on first click and cached per scan — subsequent visits load instantly. The analysis updates automatically after each rescan.
Unlike the feature status rows above it (which give a binary pass/fail), the AI Sharing Posture explains the combination of settings and what they mean together — for example, anonymous sharing enabled with default edit permissions is significantly higher risk than anonymous sharing with view-only defaults.
Teams Governance AI Analysis Pro
Appears below the Teams list in the Teams Governance tab. Unlike the raw data table above it (which shows every team with owner counts and risk flags), the AI Analysis synthesises the governance data into a risk narrative: how many teams have no owner, how many are public, how many are potentially abandoned, and what the business risk of that state is.
The analysis requires the Teams Governance report to be loaded first — it reads from the cached governance data rather than making new Graph API calls. If Teams Governance has not been run in the current session, the card will prompt you to run it first. Results are cached per scan and regenerated after each rescan.
Teams Phone & Voice Pro
Found under Security & Compliance → Teams Phone, this tab combines a feature status view of your Teams calling configuration with an AI assessment of your voice deployment health. It assesses six areas: Teams Phone voice policies, meeting policies, guest access, external federation, meeting recording policy, and Teams Premium feature availability.
The AI Voice Configuration Analysis generates a risk level and narrative specific to your tenant's voice configuration. It is particularly useful for tenants that have purchased Teams Phone System licences (included in E5 or as an add-on) and want to confirm voice policies are correctly deployed to users. If Teams Phone is not licensed, the tab returns a clear explanation rather than an error. Results are cached per scan and regenerated after each rescan.
Viva Adoption Pro
A dedicated tab under Adoption & Change Management → Viva Adoption that analyses the health of your Microsoft Viva workload deployment. The tab only appears in the sidebar if the tenant plan includes at least one Viva workload (Viva Engage, Viva Learning, Viva Connections, Viva Amplify, Viva Goals, or Microsoft Loop).
For each detected Viva workload, the AI assigns an adoption grade (A through F) and a one-sentence insight explaining the grade. The tab also returns an overall adoption health level and a list of recommended actions to improve Viva rollout. If no Viva licences are detected, the tab displays a clear explanation rather than an error. Results are cached per scan and regenerated after each rescan.
Intune Health Report Pro
The Intune Health Report gives you a structured view of your device management posture across seven sections:
- Fleet Overview — total enrolled devices, OS distribution (Windows / iOS / Android / macOS), device ownership split (corporate vs personal), compliance percentage, and devices not synced in 7+ days.
- Device Compliance — compliance policies in place, platforms covered, and how many devices are currently non-compliant. AI explanation of what the compliance percentage means in practice.
- Windows Update for Business — update rings configured, ring names, quality update deferral, and feature update deferral status. AI explanation of why rings matter and the risk of uncontrolled updates.
- BYOD & App Protection (MAM) — iOS and Android MAM policy coverage, personal device count, and a red flag if personal devices are accessing company data with no app protection policy. AI explanation of what MAM policies prevent.
- Configuration Profile Gaps — profiles deployed and missing coverage in five areas: BitLocker, password policy, update rings, firewall, and antivirus.
- Non-Compliant Devices — per-device list showing device name, user, operating system, version, and ownership type for all non-compliant devices.
- Autopilot & Enrolment — Autopilot device count, deployment profiles, and enrolment restrictions.
The report also generates a lost/stolen device scenario — a realistic AI-written description of what would happen if a device was lost today given your current BitLocker, PIN policy, remote wipe, and MAM configuration. No new Microsoft permissions are required — Intune scopes were already included in the M365Clarity connection.
Copilot Readiness Pro
Microsoft 365 Copilot has specific licence and configuration prerequisites that must be met before it can be deployed. The Copilot Readiness tab checks your tenant against every known requirement and gives you:
- A readiness score (0–100)
- A pass/fail status for each prerequisite
- A list of blockers with remediation guidance
- An estimated time to achieve readiness
Copilot prerequisites checked include: appropriate licence SKU (M365 E3/E5 or Business Standard/Premium), MFA enforced, Entra ID configured, Exchange Online active, SharePoint and OneDrive enabled, Teams deployed.
Copilot & AI Pro
The Copilot & AI tab is a dedicated Pro view with three sections, switchable within the tab. It goes beyond readiness checking to show what you have, how well it is being used, and whether your tenant is safe for autonomous agents.
📋 What You Have
Detects your Copilot tier from your subscribed licences and shows a feature inclusion table across all Copilot capabilities:
- Copilot (Basic) — included with eligible M365 Business and Enterprise plans. Provides Copilot Chat (web-grounded), Copilot in Word, Excel, PowerPoint, Outlook, OneNote, Code Interpreter, and File Upload.
- Copilot (Premium) — the £30/user/month add-on. Adds Copilot in Teams meetings, Meeting Intelligent Recap, Copilot Pages, and Copilot Studio access.
- Agent 365 — standalone add-on or included in M365 E7. Adds the Agent 365 management layer for governing autonomous agents.
- Microsoft 365 E7 — includes Copilot Premium + Agent 365 + Entra Suite + Work IQ in a single bundle.
Each feature in the table shows either ✓ Included at your current tier, or the plan required to unlock it.
📊 Adoption Health & ROI
Pulls live per-user Copilot usage data from Microsoft Graph (the last 30 days). Requires paid Copilot licences to be assigned in your tenant — the API only returns data for licensed users.
The adoption section shows:
- Licensed seats — total paid Copilot licences in your tenant
- Active users (30 days) — how many licensed users have used any Copilot app in the last month
- Unused seats — the gap between licensed and active users
- Monthly waste — unused seats × £30/seat/month shown in GBP
Copilot ROI signal — a colour-coded card that answers the question your CFO or IT director is asking: are we getting value from the Copilot investment?
- Green — 70%+ of licensed users active. Strong return on investment.
- Amber — 40–69% active. Specific number of unused licences and monthly cost called out. Recommendation to run training or reassign unused licences.
- Red — Under 40% active. Monthly wasted spend shown. Immediate action recommended.
The card also shows cost per active user per month — if you have 5 licences at £30 each and only 3 are active, the real cost per active user is £50/month. This is the number that cuts through in a board conversation about whether Copilot is delivering value.
The per-app breakdown shows adoption rates for Teams, Word, Excel, PowerPoint, Outlook, OneNote, Loop, and Copilot Chat individually — sorted from highest to lowest. Apps with zero 30-day usage are flagged immediately.
M365Clarity records a monthly adoption snapshot each time you open this tab, building a 12-month trend over time.
🤖 Agent 365 Readiness
Before deploying autonomous agents via Agent 365 or Copilot Studio, seven governance controls should be in place. This section checks each one against your existing scan data — no additional API calls required.
Controls checked:
- DLP policies for Copilot — Data Loss Prevention should cover what Copilot can access and share
- Sensitivity labels published — Labels classify content so Copilot knows what to protect
- SharePoint external sharing controlled — Copilot surfaces SharePoint content; unrestricted sharing expands agent access
- Purview audit logging active — Copilot interactions must be auditable for compliance and incident response
- Conditional Access enforced — Agents operate as the user identity; CA policies govern what they can access
- MFA enforced across users — Compromised accounts with agent access are extremely high risk
- Insider Risk Management configured — Adaptive protection can restrict agent access for users showing risky behaviour
Each control shows Pass, Review, or Fix with the actual finding from your scan. An overall Agent Readiness Score (0–100%) summarises your governance posture with a plain-language verdict.
Workload Adoption Pro
The Workload Adoption tab shows how many of your licensed users are actively using each Microsoft 365 workload over the last 30 days. It fetches live data from the Microsoft Graph activity reports API using the Reports.Read.All permission, which is included in your standard M365Clarity consent.
Workloads covered:
- Microsoft Teams — active users (messages, meetings, calls)
- Exchange Online — active mailboxes (sent email)
- SharePoint — active users (files viewed or edited)
- OneDrive — active users (files synced or shared)
- Viva Engage — active users (posts, reads, likes)
Each workload shows a coloured bar: green (≥70% adoption), amber (40–69%), red (<40%). Low adoption workloads include a plain-language note suggesting training or licence right-sizing.
Per-user activity detail
Below the workload bars, click Per-user activity detail to expand a panel showing per-user inactive users and licence waste signals. This data is pre-fetched during every scan using eight Microsoft Graph v1.0 report endpoints and requires no additional permissions. The panel shows:
- Teams inactive users — users with no Teams activity (messages, calls, meetings) in the last 30 days
- Exchange inactive users — users who sent zero emails in the last 30 days
- OneDrive inactive users — users with no file activity (viewed, edited, synced, shared) in the last 30 days
- Inactive M365 Groups — groups with no email, file, or meeting activity in the last 30 days
- Mailbox quota warnings — mailboxes above 80% of their Prohibit Send quota, sorted by fullest first
- Never activated Office apps — users who have a licence including Office apps but have never activated them on any device
- Stale sign-ins — users with no recorded sign-in in the last 90 days (requires
AuditLog.Read.All, included in standard M365Clarity consent)
SharePoint Site Health Pro
The SharePoint Site Health tab is available under Teams & SharePoint → SharePoint Site Health in the sidebar. It reads per-site activity and storage data from the Microsoft Graph getSharePointSiteUsageDetail report (v1.0, D30 period) using the Reports.Read.All permission already included in your M365Clarity consent. Data is pre-fetched during every scan — the tab loads instantly.
For each SharePoint site the tab shows:
- Site URL
- Last activity date
- File count and active file count
- Storage used vs storage allocated (shown as a progress bar)
- Whether the site is abandoned (no activity in the last 30 days)
Sites are split into two views:
- Abandoned — sites with no activity in the last 30 days, sorted by storage consumed (largest first)
- Active — sites with activity in the last 30 days, sorted by storage used (largest first)
The summary section at the top shows total sites, abandoned site count, abandoned storage (in GB), and active site count.
SharePoint Site Health AI Governance Assessment
The tab automatically generates an AI governance assessment after the site data loads. The assessment uses Claude (AI_MODEL_FAST) grounded in your actual site counts and storage numbers — not generic advice. It returns:
- Risk level — low, medium, high, or critical, shown as a badge in the section header
- Headline — one sentence summarising the biggest governance concern
- Narrative — 2–3 sentences explaining what the findings mean in practice (storage cost, data risk, accountability gaps)
- Three recommendations — each with an effort rating (low, medium, or high), ordered easiest first
- Storage reclaim estimate — how much storage could be recovered if abandoned sites were archived
Risk level thresholds:
- Low — fewer than 10% of sites abandoned and less than 5 GB of abandoned storage
- Medium — 10–30% of sites abandoned, or 5–20 GB of abandoned storage
- High — 30–50% of sites abandoned, or 20–50 GB of abandoned storage
- Critical — more than 50% of sites abandoned, or more than 50 GB of abandoned storage
Unlocked but Unused Pro
The Unlocked but Unused tab crosses two data sources to find features you are already paying for but have not switched on:
- M365 Feature Registry — M365Clarity's catalogue of Microsoft 365 features and which licence plans include them, built from daily scans of m365maps.com
- Your scan results — the RAG status of each feature in your actual tenant configuration
Any feature that is included in your plan but shows red (not configured), amber (partially configured), or unknown in your scan is surfaced as a gap. Features are grouped by workload (Teams, Entra ID, Purview etc.) and each has a direct link to Microsoft's documentation.
You can filter by status: All, Not Configured (red), or Partial (amber).
⚡ What Now — baseline config guides
Every gap card has a ⚡ What now button. Clicking it generates an AI-powered baseline adoption guide specifically for that feature, grounded in your tenant's plan, sector, and size — and aware of which adjacent features you already have configured.
Each guide includes: a plain-English summary of why the feature matters for your specific setup, an adoption tip tailored to your sector and organisation size, step-by-step setup instructions with direct links to the correct Microsoft admin centre pages, a verification step to confirm the baseline is working, and a rollback note in case you need to undo it.
What Now guides are different from the remediation guides available on the main tile grid. Remediation guides fix a misconfiguration — something you've tried to set up but done incorrectly. What Now guides start from scratch — they assume you haven't touched the feature yet and walk you through the recommended first-time setup.
Cost Per Active User
Shows what you are paying per person who actually uses Microsoft 365, broken down by plan SKU. For each SKU: total licensed seats, active users (signed in within 90 days), inactive users, total monthly cost, and cost per active seat in GBP. The header shows your overall cost per active seat and total monthly spend at a glance. Tap to expand for the full per-SKU table, including the monthly cost attributable to inactive seats. Uses GBP list prices from M365Clarity's price table — if you are on a CSP or EA agreement, your contracted rate will differ. Active user count is based on sign-in data from your scan; inactive count is capped at 200 users per scan. Pro plan only. Find it at the top of the Licence Recommendations tab.
Scheduled scans Pro
Pro and MSP users can enable automated scanning per tenant. Choose from:
- None — manual scans only (default)
- Daily — scans every day
- Weekly — once a week
- Bi-weekly — every two weeks
- Monthly — once a month
To configure: open tenant settings in the dashboard, select a frequency, and choose whether to receive an email when each scan completes. Scans run automatically in the background — no further action needed.
MSPs can set different schedules per client tenant — for example, daily for high-risk clients and weekly for stable ones.
Multi-Tenant users can also bulk-schedule all tenants at once using Schedule all weekly in the MSP Portfolio view. This sets weekly scans on every connected client tenant simultaneously.
MSP portfolio dashboard Multi-Tenant
The MSP plan includes a portfolio dashboard that gives you a single view across all connected client tenants. From the portfolio view you can:
- See the Feature Health Score and grade for every tenant at a glance
- Identify tenants with open red or amber findings
- See each tenant's scan schedule and last scan date
- Trigger an on-demand scan for any tenant
- Click through to the full dashboard for any client
To access: click Portfolio View in the top navigation (visible to MSP users only), or go to /dashboard/portfolio.
To add a client tenant: click + Add Tenant from the portfolio view. A modal will ask for a client contact email address (the person at the client organisation who should receive a connection notification — not necessarily the admin account you'll sign in with) and an optional note to include in the notification. On confirm, you'll be redirected to Microsoft to authenticate with the client's credentials or as a delegated admin. Once connected, a notification email is automatically sent to the client contact email explaining what M365Clarity is, what data is read, and that access is read-only.
To remove a client tenant: click the red ✕ button on any tenant card in the portfolio. Confirm the removal in the dialog. The tenant is soft-deleted immediately — it disappears from your portfolio and scans stop. Historical scan data is retained and purged on schedule. The client's own M365Clarity account (if they have one) is unaffected.
PDF reports Pro
Any dashboard view — Overview, Executive Summary, Compliance, Priority Actions — can be exported as a PDF. Click the Export PDF button (where available) to open a print-ready version of the current view.
PDF reports are generated from your live scan data and include your tenant name, scan date, plan, and Feature Health Score. MSP users can generate client-ready reports for use in QBRs, audits, or board presentations.
Guest account audit Pro
The Guest Audit tab shows every external guest user in your Microsoft 365 tenant — people from outside your organisation who have been invited to access Teams, SharePoint, or other services.
For each guest, M365Clarity shows:
- Last sign-in date and days since last activity
- Never signed in — guests who were invited but never used their access
- Stale (90+ days) — guests who have not signed in for 3 months or more
Guest accounts are a common finding in Cyber Essentials assessments and GDPR reviews. Stale or unused guest accounts increase your attack surface and may represent a data protection obligation to remove. Use the filter buttons to focus on stale or never-active guests.
Licence utilisation Pro
The Licences tab shows how many seats you have assigned vs how many are actually in use — broken down per Microsoft 365 SKU.
- Assigned: licences purchased and allocated to users
- In use: licences actively consumed by user accounts
- Unused: the gap — licences you are paying for but not using
- Estimated monthly cost: an approximate GBP figure for unused seats based on standard UK pricing
Licence prices are estimated from publicly available Microsoft pricing and are approximate. Actual costs will vary based on your agreement, any negotiated discounts, and currency fluctuations. Use the figures as a guide for conversations with your Microsoft partner or reseller — not as an invoice.
To reduce unused licences, go to Microsoft 365 Admin Centre → Billing → Licences.
See also the Licence Waste Detection tab for a user-level view showing which specific people have active licences but have not signed in recently.
Licence Waste Detection Pro
The Licence Waste tab identifies licensed users who have not signed in to Microsoft 365 in the last 90 days. These are accounts that are costing money but may no longer be needed — leavers whose accounts were not disabled, contractors who finished, or accounts that were created but never used.
For each inactive user, M365Clarity shows:
- Display name and email
- Last sign-in date — or "Never signed in" if no activity has ever been recorded
- Number of licences assigned to the account
At the top of the tab, an estimated monthly and annual cost is shown for all inactive accounts combined. Prices are based on the average licence cost across your active subscriptions and are approximate.
To review or remove inactive accounts, go to Microsoft 365 Admin Centre → Users → Active Users. M365Clarity is read-only and cannot remove or disable accounts on your behalf.
Cyber Essentials Readiness Pro
The Cyber Essentials tab maps your Microsoft 365 configuration against the five UK Government Cyber Essentials controls. It gives you a readiness score and a pass/fail status for each control, based on your actual scan data.
The five Cyber Essentials controls checked:
- CE1 — Firewalls: boundary protection and network access controls
- CE2 — Secure Configuration: devices and services configured to reduce vulnerabilities
- CE3 — User Access Control: accounts managed with least-privilege access
- CE4 — Malware Protection: protection against viruses and other malware
- CE5 — Patch Management: devices and software kept up to date
A Download Report button on the tab generates a standalone HTML report. Open it in a browser and use Print → Save as PDF to create a shareable PDF document.
The Compliance tab continues to show CE alongside ISO 27001 and NIST CSF for a combined view. The Cyber Essentials tab provides a more focused view with the downloadable report.
Admin account review Pro
The Admin Accounts tab checks the number of Global Administrator accounts configured in your tenant and compares it against best practice.
Recommended range: 2–4 Global Admins.
- Fewer than 2: a single point of failure — if that account is locked out or compromised, no admin access is possible. Best practice is to have a second break-glass account.
- 2–4: the recommended range for most organisations
- More than 4: over-provisioned — each additional Global Admin is an additional target for attackers. Use least-privilege roles (e.g. Exchange Administrator, User Administrator) instead of Global Admin where possible.
The tab lists the display name and email address of each Global Administrator account. Cyber Essentials Plus and ISO 27001 assessors typically review admin account hygiene during assessments.
SLA tracking Pro
The SLA tab tracks how long each open finding has been present in your tenant — from the first time M365Clarity detected it.
Default SLA targets:
- Red (critical) findings: 14-day target
- Amber (review) findings: 30-day target
Findings that have exceeded their SLA target are flagged in red with a "SLA BREACHED" badge. A progress bar shows how far through the SLA window each finding is.
SLA tracking requires at least two scans — the first scan establishes the baseline, subsequent scans track how long issues have persisted. If a finding is fixed and then reappears in a later scan, the SLA clock resets.
Use the filter buttons to view all findings, only breached ones, or filter by severity.
Scan comparison Pro
The Compare tab lets you select any two completed scans for the same tenant and see a before-and-after diff.
The comparison shows:
- Improved: features that moved from red/amber to a better status (e.g. red → green)
- Degraded: features that moved to a worse status between the two scans
- Score change: the numeric difference between the two scan Health Scores
- Unchanged: the number of features with no status change
This is useful for demonstrating remediation progress to stakeholders, tracking the impact of a change window, or identifying unintended regressions after a configuration change.
Click the Print / Save as PDF button within the Compare tab to export the diff as a PDF — useful for audit evidence or client reporting.
Ticket export Pro
The Tickets tab lets you convert scan findings into actionable tickets for your IT helpdesk or ITSM system.
Export formats
- Email: a formatted email body listing each selected finding with severity, category, and remediation hint. Paste it into your email client or helpdesk system.
- CSV: a comma-separated file suitable for import into Excel, ServiceNow, or other ITSM tools. Columns: Priority, Feature, Category, Remediation.
- Jira: Jira-formatted text (h3 headers, *bold* fields) ready to paste into a Jira issue description. Each finding becomes a separate ticket block.
Direct email sending
You can also send findings directly from M365Clarity to your IT helpdesk email address. Each selected finding is sent as a separate pre-formatted email. Emails are sent via M365Clarity's transactional email service (Brevo) from noreply@m365clarity.com to the email address on your account. The helpdesk can reply directly to you — M365Clarity is not in the reply chain.
Remediation tracking Pro
When you click Mark as resolved on a feature in the Priority Actions tab, you can add an optional note (e.g. ticket reference) and a target due date. The due date is stored and visible in the resolved items list, making it easier to track remediation progress across your team. Resolved items persist across scans so you can see your remediation history over time.
The Priority Actions tab shows Claude's ranked list of configuration gaps, ordered by business impact and implementation effort. Each action card has a Mark as resolved button. Clicking it opens an optional note field — useful for adding a ticket reference or brief description of what was done. Once marked, the action moves to a Resolved section at the bottom with a strikethrough. A progress bar at the top of the tab shows how many actions you have completed out of the total. Resolved status persists across sessions and devices. You can undo a resolution at any time.
What if my organisation has multiple Microsoft 365 plans?
Many organisations have more than one Microsoft 365 licence plan assigned at the same time. This is more common than you might think — for example:
- Office workers on Microsoft 365 Business Standard and warehouse staff on the cheaper Microsoft 365 F1 (frontline worker) plan
- A business that upgraded from Business Basic to Business Premium but still has both subscriptions active during the transition
- A company with a mix of Microsoft 365 E3 licences and Entra ID P2 add-ons for their IT admins
How M365Clarity handles this
M365Clarity checks every active licence subscription in your tenant and builds a combined picture. Here is how the process works:
A real-world example
Say your organisation has:
- 50 users on Microsoft 365 Business Standard (includes Teams, SharePoint, Exchange, Office apps)
- 10 IT admin users on Entra ID P2 (adds advanced identity features like Privileged Identity Management)
M365Clarity will scan features from both plans. Your office workers' features and your IT admins' advanced identity features are all included. You will see the full set of things configured (or not configured) across your whole environment — not just one half of it.
What M365Clarity does not check
M365Clarity checks what is available to your organisation based on your subscriptions — it does not check which individual users have been assigned which licence. For example, if only 5 of your 50 users have been assigned Microsoft 365 Business Standard, M365Clarity will still show all Business Standard features as available to scan, because the subscription exists on the tenant.
This is intentional — configuration decisions (like whether MFA is enforced, or whether external sharing is enabled) are tenant-wide settings, not per-user ones.
Upgrading your plan
You can upgrade from Free to Pro or from Pro to MSP (Multi-Tenant) at any time — no support ticket required.
Free → Pro: Click Get Pro in the top navigation or from any locked feature. You will be taken to a Stripe checkout page. After payment, your account is upgraded immediately.
Pro → MSP: Go to Settings → Upgrade to MSP. A card is shown at the bottom of the Settings tab for Pro users with a direct link to Stripe checkout. After payment, your account is upgraded to MSP tier and the portfolio dashboard becomes available.
Cancellation: Go to Account → Manage Billing to open the Stripe Customer Portal. You can cancel, downgrade, or update your payment method at any time. Cancellation takes effect at the end of your current billing period.
Exchange Online checks
M365Clarity assesses 14 Exchange Online elements across four areas:
Email authentication and anti-spoofing: DKIM Email Signing (including DMARC and SPF detection), External Email Warning Tag, and External Email Forwarding Blocked. These three checks cover the most common email spoofing and data exfiltration vectors.
Anti-malware and phishing: Exchange Online Protection Policies (spam and malware filter configuration), Exchange Anti-Spam Policy, Exchange Quarantine Policy, Safe Attachments (Defender for Office 365), Safe Links (Defender for Office 365), and Advanced Anti-Phishing Policy. Safe Attachments and Safe Links require Microsoft Defender for Office 365 Plan 1 or above — they will show as not licensed on Business Basic, Business Standard, or Office 365 E1 plans.
Access and authentication: Modern Authentication — Exchange (verifies that basic authentication is disabled) and Mailbox Auditing (confirms audit logging is enabled for all mailboxes).
Archiving and compliance: Exchange Online Archiving (In-Place Archive status) and Advanced Message Encryption (requires Office 365 E3 or above).
Exchange Online checks are visible in the Security & Compliance → Exchange Posture tab and also appear in the main feature scan results under the Collaboration category.
Microsoft Purview checks
M365Clarity assesses 25 Microsoft Purview elements across four categories. These are evaluated against your live tenant configuration and reflected in the Executive Summary's Purview compliance snapshot.
Data protection: Data Loss Prevention Policies (standard and endpoint), Sensitivity Labels and Auto-Labelling Policies, Azure Information Protection, Exact Data Match classification, Information Barriers, Advanced Message Encryption, and Adaptive Policy Scopes.
Audit and oversight: Unified Audit Logging, Audit Log Retention Policy, Audit (Premium), Purview Audit for Copilot Interactions, and Compliance Manager Assessments.
Retention: Retention Policies, Retention Labels, and Microsoft 365 Backup for Exchange Online, SharePoint, and OneDrive.
Risk and eDiscovery: Insider Risk Management, Communication Compliance, eDiscovery Standard, eDiscovery Premium, and Legal Hold configuration.
Purview elements requiring Microsoft Purview compliance add-ons (eDiscovery Premium, Insider Risk, Communication Compliance) will show as not licensed on plans below Microsoft 365 E5 or Purview Compliance. The checks that are available on your plan are evaluated automatically — no configuration required.
AI features reference
Score Delta — Why did your score change? Pro
Every time you scan, M365Clarity compares your results to your previous scan and explains what changed. Features that improved or degraded are grouped by category (Identity, Compliance, Threat Protection etc.) with an AI-written plain-English explanation. Find it in the History tab.
Admin Account Hardening Report Pro
Checks every Global Administrator in your tenant across four signals: MFA registration status, Privileged Identity Management (PIM) eligibility, on-premises sync status, and last sign-in date. Each admin is assigned a risk score and ordered highest risk first. Find it in the Admin Accounts tab.
Guest Risk Scoring Pro
Every guest account in your tenant is scored by risk — whether they have never signed in, how long since their last sign-in, and whether they are from an external domain. Results are sorted highest risk first with a High Risk filter. Find it in the Guests tab.
Licence Activation Gap Pro
Identifies users who have been assigned Microsoft 365 licences but have never activated a single Office app on any platform. Built from the Microsoft 365 activation report — the clearest signal of wasted licence spend. Find it in the Licence Recommendations tab.
Pre-Renewal Briefing Pro
When your renewal date is within 90 days, M365Clarity generates a full pre-renewal briefing from your scan data: licences and features to drop (with estimated savings), gaps worth adding, cost optimisation actions, and an executive summary you can share with your CFO or board. Find it in the Licence Recommendations tab.
Once the briefing is generated, you can also generate a Partner Briefing Draft — a plain-text email grounded in your active licences, inactive user count, and the drop/add recommendations from the briefing. The draft includes an appendix listing inactive users by name and last sign-in date so your partner knows exactly which accounts to review. Hit "Generate draft", personalise the partner name and sign-off, then use "Copy to clipboard" or "Open in Mail" to send it from your own email address.
Licensing intent queue: If you've saved licensing intents from the AI chat (via the 💼 chip), they appear in a "Licensing changes queued" panel at the top of the Licence Recommendations tab. Each intent shows the date it was captured and an in-window / outside-window indicator. Intents outside the 3-month window are not included in the next brief — you can re-confirm them via the chat if still relevant. Use the Remove button to discard any that are no longer needed.
Mark as sent: Once you've sent the brief to your partner, tap "Mark brief as sent" in the draft section. This closes the current renewal cycle — all queued intents are archived, the intent queue clears, and any new intents you capture will belong to the next renewal cycle. MSP users can see a history of past brief cycles (date dispatched, intents included) under Tenant Settings for each client.
Security Incident Readiness Score Pro
A five-pillar security readiness model (Detect, Protect, Recover, Identity, Compliance) that scores your tenant across 25 controls drawn from your existing scan results. Each pillar gets an individual score and grade. An AI narrative explains what the overall score means in plain English for an IT Director or CISO. Find it under Security & Compliance → Incident Readiness.
Backup & Recovery Readiness Pro
Assesses how recoverable your data is if ransomware or accidental deletion strikes. Shows the status of Microsoft 365 Backup for Exchange, SharePoint, and OneDrive individually, along with retention policies, audit trail coverage, and ransomware prevention controls. Includes an AI-generated ransomware scenario — what would actually happen to your data if hit today. Find it under Security & Compliance → Backup & Recovery.
Conditional Access Coverage Map Pro
Analyses every CA policy in your tenant to surface coverage gaps — scenarios where users, apps, or platforms have no active policy protecting them. Critical gaps (no enforced MFA-for-all, legacy auth not blocked) are flagged with severity levels. All policies are shown with their attribute chips (All users, All apps, Requires MFA etc.) and an enforced/report-only filter. Find it under Security & Compliance → CA Coverage Map.
Entra ID Application Audit Pro
Lists every third-party enterprise application and service principal with access to your tenant, scored by permission risk. High-risk permissions (Mail.ReadWrite, Files.ReadWrite.All, Directory.ReadWrite.All) are highlighted in red. Includes a search field and risk filter. Requires Application.Read.All consent — if this was not granted when you connected, reconnect your tenant to enable it. Find it under Security & Compliance → App Audit.
Defender AI Posture Pro
Found under Security & Compliance → Defender XDR, the Defender AI Posture card appears at the bottom of the Defender XDR tab. It synthesises 15 Defender feature results — including Secure Score, XDR active incidents, Safe Attachments, Safe Links, Advanced Anti-Phishing, Attack Simulation Training, Defender for Endpoint, Vulnerability Management, Cloud App Security, and Adaptive Protection — into a single risk level and plain-English narrative.
The assessment returns a risk level (low / medium / high / critical), a one-sentence headline, a board-level narrative, a breakdown of the top risks with severity labels, what is configured well, and prioritised recommended actions with effort ratings. Results auto-load from cache on tab open and are regenerated automatically after each rescan. Requires a Pro plan.
Entra ID Governance Posture Pro
Found under Identity & Access → Entra Governance, the AI Entra Governance Posture card synthesises 13 identity governance features: Privileged Identity Management (PIM), Access Reviews, Entitlement Management, Guest Access Review, Sign-in Risk Policy, Identity Protection, Lifecycle Workflows, Emergency Access Accounts, Conditional Access, CA enforcement vs report-only gap, Authentication Strengths, Enterprise App Permissions, and App Registrations Audit.
The output follows the same structure as Defender Posture — risk level, headline, narrative, top risks, positives, and recommendations. This is particularly valuable for tenants with Entra ID P1/P2 licences where standing privileged access and ungoverned guest accounts are common risks. Auto-loads from cache, regenerates after rescan.
Teams Governance Report Pro
Lists every Microsoft Teams in your tenant with owner count, visibility (public/private), age, and risk flags — no owner, public team, potentially abandoned. Results are sorted highest risk first. The report makes live Graph API calls when you open it, so it reflects the current state of your tenant rather than the last scan. Requires the Group.Read.All permission which is included in the standard M365Clarity consent. Find it under Security & Compliance → Teams Governance.
Scheduled automatic rescanning Pro
Pro and MSP users have a weekly scheduled scan automatically enabled on connection. The scan runs every Monday at 6am UTC using your stored refresh token — no manual action needed and no browser session required. If the scan detects configuration changes since the previous scan, you receive an email notification. You can change the frequency, preferred time, or disable the schedule entirely in Settings → Scan schedule.
PDF report — AI summaries included Pro
The PDF report (available via the PDF button at the top of the dashboard) now includes AI-generated summary sections alongside the full feature table: Priority Issues (all red features), Security Incident Readiness score and narrative, Backup & Recovery score and ransomware scenario, Conditional Access coverage score and gap list, and Admin Account Hardening flagged count. These sections only appear if you have already opened the relevant tabs in the current scan — the PDF pulls from cached results rather than making new API calls.
Frequently asked questions
Why not just use the free Microsoft admin dashboards?
Microsoft 365 comes with excellent tools — but they are spread across at least 15 separate admin portals, each with its own login, navigation, and data model. To get a complete picture of your tenant's security posture today, you would need to visit:
- Microsoft 365 Admin Centre — licences, users, service health
- Microsoft Entra Admin Centre — identity, Conditional Access, MFA, PIM, access reviews
- Microsoft Defender XDR — Secure Score, threat protection, endpoint security
- Microsoft Intune Admin Centre — device compliance, configuration profiles, BitLocker
- Microsoft Purview Compliance Portal — DLP, sensitivity labels, retention, eDiscovery, communication compliance
- SharePoint Admin Centre — sharing settings, site governance, external access
- Teams Admin Centre — Teams policies, guest access, federation, app governance
- Exchange Admin Centre — mail flow, anti-spam, DKIM, quarantine policies
- Microsoft 365 Apps Admin Centre — Office deployment, update channels
- Viva Insights / Adoption Score — usage analytics, adoption trends
- Azure Portal — enterprise app registrations, OAuth permissions, network access
- Microsoft Copilot Admin Centre — Copilot readiness, usage analytics
- Microsoft Endpoint Manager — Autopilot, device enrolment
- Microsoft Secure Score — aggregated security recommendations
- Microsoft 365 Usage Reports — per-user activity, licence utilisation
Even experienced Microsoft 365 administrators find it difficult to hold the full picture in their head across all of these portals simultaneously. Settings interact with each other in ways the portals don't surface — a Conditional Access policy that looks correct in Entra may have a scope gap that only becomes obvious when cross-referenced with your MFA registration report and your external sharing settings.
What M365Clarity does differently:
- Single scan, unified view. One read-only connection to your tenant pulls data from all relevant APIs simultaneously. You get a single dashboard covering identity, security, compliance, devices, collaboration, and adoption — no portal switching.
- Opinionated scoring. Microsoft's portals show you data. M365Clarity tells you whether that data represents a good or bad configuration — with a red/amber/green verdict and a plain-English explanation of why it matters.
- Cross-feature analysis. Issues like CA scope gaps, licence waste, and guest access sprawl only become visible when multiple data points are combined. Each Microsoft portal shows its own slice — M365Clarity connects them.
- Framework mapping. Your scan results are automatically mapped to Cyber Essentials, ISO 27001, and NIST CSF controls — something that would take hours to do manually against 15 portals.
- AI-guided remediation. Every red or amber finding includes a specific, step-by-step setup guide generated from your actual tenant data — not generic documentation.
- MSP-ready. For IT providers managing multiple tenants, M365Clarity provides a portfolio view across all clients from a single login — something that requires bespoke tooling or significant manual effort across Microsoft's native portals.
Microsoft's portals are free because they are designed for Microsoft's needs — to surface their products. M365Clarity is designed for the administrator who needs to know, quickly, whether their tenant is configured correctly and what to fix first.
Does M365Clarity monitor whether Microsoft 365 services are online?
No. M365Clarity is a configuration and adoption assessment tool, not a service monitoring platform. It scans your tenant once per scan and reports on how your Microsoft 365 environment is configured and how your users are adopting it — it does not continuously monitor uptime or service availability.
A green tile for Exchange Online, SharePoint, Teams, or any other core service means that service is included in your licence — not that it is currently online or performing normally. If Microsoft 365 is experiencing an outage, M365Clarity will still show those tiles as green because your licence has not changed.
For live service health and incident status, use the Microsoft 365 Service Health dashboard in your admin centre, or check status.office365.com.
Why is a feature showing as "Not Verified" (grey)?
Not Verified means M365Clarity attempted to check that feature but could not produce a reliable result. There are three possible reasons:
- Microsoft does not expose this setting via the API — some settings are only visible in the admin portal and cannot be read programmatically. The tile will explain what to check manually.
- A permissions error occurred during the scan — certain Graph API endpoints require specific roles beyond Global Administrator (for example, Exchange Administrator or Security Reader). The tile will say which role is needed.
Not Verified tiles are excluded from your Feature Health Score — they do not penalise your result.
Features your licence does not include are hidden from the main tile grid entirely — they appear in a collapsible section below the grid rather than as grey Not Verified tiles.
Why are some features not shown at all?
M365Clarity only shows a feature tile if the Microsoft Graph API can return data that allows a reliable, accurate assessment. Where this is not possible — for example, because the API endpoint exposes permission definitions rather than granted permissions, making false positives unavoidable — the feature is hidden rather than shown as a misleading grey card.
In these cases, the same security concern is typically covered by a different, more reliable check. For example, third-party application permissions are assessed via OAuth permission grants (what has actually been delegated to an app) rather than service principal definitions (which show permissions an app makes available to others, not permissions it has been given).
This is intentional — a smaller set of accurate results is more useful than a larger set containing misleading ones.
Why does my score change between scans even when I haven't changed anything?
Two things can change your score without any admin action on your part:
- Microsoft changes a default setting — Microsoft occasionally updates tenant defaults, which can move a feature from green to amber.
- Evaluator improvements — M365Clarity regularly refines how features are assessed. If an evaluator was previously producing false positives (flagging something as red when it was not actually a problem), a fix may move that feature from red to green on the next scan, improving your score.
If your score changes significantly without any known configuration change, check the scan results for any features that have changed status — the "Why this?" explanation on each tile will describe what was found.
Why does the scan say I need Global Administrator when I already am one?
Some Microsoft Graph API endpoints require specific administrative roles that are separate from Global Administrator, even though Global Administrator grants broad access to most services. The most common example is SharePoint and OneDrive settings — these require the SharePoint Administrator role to be assigned in Entra ID, in addition to Global Administrator.
To assign the SharePoint Administrator role: go to Entra admin centre → Roles & admins → SharePoint Administrator, add the account you connected with, then disconnect and reconnect your tenant in M365Clarity.
How accurate are the scan results?
M365Clarity reads directly from the Microsoft Graph API — every result is based on the actual configuration data Microsoft returns for your tenant, not estimates or assumptions. The accuracy of each result depends on:
- API availability — if Microsoft does not expose a setting via the API, M365Clarity cannot assess it and will show Not Verified rather than guess.
- Permission scope — if the account used to connect lacks a required role, the API returns a permission error. This shows as Not Verified with an explanation, not as a false red or green.
- Licence — features that require a specific licence (E3, E5, Purview, etc.) will show Not Verified on plans that do not include them, rather than flagging them as misconfigured.
Where M365Clarity cannot confirm a result with certainty, it will always show Not Verified rather than produce a misleading red or green result.
Billing FAQ
For billing questions not covered below, email support@m365clarity.com. We endeavour to respond within 24 hours on business days.
How do I upgrade from Free to Pro or MSP?
Can I cancel anytime?
Can I upgrade from Pro to MSP?
What payment methods are accepted?
Do you offer annual billing?
What happens if my payment fails?
Is there a free trial of paid features?
Security & data privacy
What data do you access?
M365Clarity requests the following Microsoft Graph read-only scopes:
User.Read— your name and email addressOrganization.Read.All— your tenant name and licence subscriptionsReports.Read.All— usage and activity reportsSecurityEvents.Read.All— Secure Score and security alertsPolicy.Read.All— Conditional Access and other policy configurationsDirectory.Read.All— directory settings and group configurations
We do not access the content of emails, files, Teams messages, or any user-generated content.
How are tokens stored?
Microsoft OAuth access and refresh tokens are encrypted with AES-256-GCM before being written to the database. The encryption key is stored separately from the data store. Tokens are decrypted only at scan time and never logged.
Where is data stored?
All data is stored in Cloudflare D1 (SQLite) in the WEUR region (Amsterdam, Netherlands). No data is replicated outside the EU. Cloudflare's infrastructure is ISO 27001 certified and SOC 2 Type II compliant.
Who has access to my data?
Only you. Data is scoped to your account and tenant. No M365Clarity team member has routine access to scan data. Access to production infrastructure requires multi-factor authentication.
Your data rights (GDPR / UK GDPR)
M365Clarity Limited is registered with the ICO (ZC173030) and complies with UK GDPR. You have the following rights:
- Access — export all your data as JSON from Account → Export My Data. The export includes your account details, tenant connections, scan history, and audit log.
- Erasure — delete your account from Account → Delete Account. Your email and name are anonymised immediately. All scan data, tenant tokens, AI caches, and associated records are permanently deleted within 30 days by an automated process.
- Rectification — update your display name from Account → Settings, or contact support@m365clarity.com for other corrections
- Portability — the JSON export includes all scan history, audit log, and account information in a machine-readable format
- Objection — you can disconnect your M365 tenant at any time from within the dashboard, which immediately revokes M365Clarity's access to your tenant
To exercise any of these rights or to make a complaint, contact: support@m365clarity.com. We endeavour to respond within 24 hours on business days.
Security team information pack
If your organisation's security or procurement team needs to assess M365Clarity before approving its use, this section covers the questions they are most likely to ask. You can also download a pre-formatted copy to share directly with your security team.
What does M365Clarity access in our Microsoft 365 tenant?
M365Clarity requests read-only access to the following Microsoft Graph API scopes. It cannot read, modify, or delete any data in your tenant — it can only retrieve configuration and usage metadata.
- User.Read — the authenticated admin account's name and email address
- Organization.Read.All — tenant name and licence subscription details
- Reports.Read.All — aggregated usage and activity reports (anonymised by Microsoft by default)
- SecurityEvents.Read.All — Microsoft Secure Score and security alert counts
- Policy.Read.All — Conditional Access policies and other tenant policy configurations
- Directory.Read.All — directory settings, group configurations, and user account metadata
- ServiceMessage.Read.All — Microsoft 365 service announcements and Message Centre posts
- Sites.Read.All — SharePoint site metadata (storage, activity dates) — no file content
M365Clarity does not access the content of emails, files, Teams messages, calendar events, or any user-generated content. It does not access OneDrive files, Exchange mailbox content, or Teams channel messages.
Where is our data stored and processed?
All data is stored in Cloudflare D1 (SQLite) located in the WEUR region (Amsterdam, Netherlands). No data is replicated outside the European Union. Processing runs on Cloudflare Workers at the same edge location.
M365Clarity Limited is a UK-registered company. Data storage within the EU means processing is covered by the EU GDPR and, for UK customers, the UK GDPR adequacy framework.
How are credentials and tokens protected?
Microsoft OAuth access and refresh tokens are encrypted with AES-256-GCM before being written to the database. The encryption key is stored separately from the data store using Cloudflare Workers Secrets, which are never logged or exposed in application code. Tokens are decrypted only at scan time in memory and are never written to logs, caches, or external services.
Token lifetimes follow Microsoft's standard — access tokens expire after approximately one hour, and refresh tokens are silently rotated on each use. If a token cannot be refreshed, the tenant is flagged and the user is prompted to reconnect.
What authentication mechanisms protect the M365Clarity application?
M365Clarity uses Microsoft OAuth 2.0 (delegated permissions) for tenant connections. User sessions are managed via server-side session tokens stored in Cloudflare KV with a 7-day TTL. Session tokens are passed as Bearer tokens in the Authorization header — never in cookies or query strings.
All API routes validate the session token server-side on every request. There is no client-side authentication state. Rate limiting is applied to all user-callable API endpoints at the Cloudflare edge.
The production infrastructure requires multi-factor authentication for access.
Who can access our scan data?
Scan data is scoped to the authenticated user account that connected the tenant. No other M365Clarity user can access your data. M365Clarity team members do not have routine access to customer scan data — production database access requires explicit authorisation and is logged.
Optional viewer access can be granted by the account owner to named email addresses. Viewers have read-only access to scan results and cannot trigger scans, modify settings, or access billing information.
Does M365Clarity use sub-processors or third parties?
- Cloudflare — infrastructure, edge compute, database (D1), KV storage, and R2 object storage. Data centre: Amsterdam (WEUR). Cloudflare sub-processors →
- Anthropic — AI language model processing for Priority Actions, Executive Summary, and other AI features. Scan data excerpts (configuration metadata only, no user-generated content) are sent to Anthropic's API for processing. Anthropic does not train on API data by default. Anthropic privacy policy →
- Microsoft — Microsoft Graph API for data retrieval; Microsoft OAuth 2.0 for authentication.
- Stripe — payment processing. M365Clarity does not store payment card data. All payment handling is managed by Stripe. Stripe privacy policy →
- Postmark — transactional email delivery (scan notifications, weekly digests).
No scan data is shared with any sub-processor beyond what is necessary to deliver the service.
What is your data retention policy?
- Scan results — retained for the lifetime of the account. When an account is deleted, all scan data is permanently deleted within 30 days by an automated process.
- Error logs — retained for 90 days, then automatically purged.
- AI usage logs — retained for 90 days.
- Audit logs — retained for 90 days.
- OAuth tokens — deleted immediately when a tenant is disconnected or when the account is deleted.
- Account deletion — email and name are anonymised immediately on deletion. All associated data is purged within 30 days.
All retention periods are enforced by an automated scheduled process running daily. There is no manual step required.
Is M365Clarity GDPR compliant?
Yes. M365Clarity Limited is registered with the UK Information Commissioner's Office (ICO registration number ZC173030) and complies with UK GDPR. Data is stored in the EU (Amsterdam) and processed under standard contractual clauses where applicable.
Users can export all their data as JSON, request deletion, or disconnect their tenant at any time from within the application. See the Your data rights section for full details.
M365Clarity does not store IP addresses. Rate limiting is handled at the Cloudflare edge without any IP logging in the application database.
Has M365Clarity undergone penetration testing or third-party security assessment?
M365Clarity has not yet undergone a formal third-party penetration test. The application is built on Cloudflare's infrastructure, which is ISO 27001 certified and SOC 2 Type II compliant. Cloudflare's security posture covers the underlying infrastructure layer.
The application layer follows OWASP security principles: all database queries use parameterised bindings (no string concatenation), all API routes validate session tokens server-side, user data is scoped per account with no cross-tenant access, and all external API calls are made over HTTPS with enforced timeouts.
If your organisation requires a completed penetration test or security questionnaire, please contact support@m365clarity.com to discuss.
What is the incident response process if a data breach occurs?
In the event of a confirmed data breach affecting personal data:
- Affected customers will be notified within 72 hours of M365Clarity becoming aware of the breach, in accordance with UK GDPR Article 33.
- Notification will be sent to the email address registered to the affected account.
- The notification will describe the nature of the breach, the data affected, the likely consequences, and the measures taken or proposed to address it.
- M365Clarity will notify the ICO as required.
To report a suspected security issue, email support@m365clarity.com with the subject line "Security Issue".
What Microsoft permissions are required and why?
M365Clarity requires the Global Administrator role to grant tenant-wide consent for the Microsoft Graph permissions listed above. This is a Microsoft requirement for delegated permissions that apply across the entire organisation — it does not grant M365Clarity any administrative access to your tenant.
Once consent has been granted, the connected account does not need to retain the Global Administrator role. The consent persists and the application continues to operate with read-only access. However, the connected account does need to remain active — if the account is disabled or deleted, the OAuth token will expire and the tenant will need to be reconnected.
The SharePoint Administrator role is additionally required to access SharePoint tenant-wide settings and site usage data. This role can be assigned to the connected account separately if SharePoint data is needed.
Can M365Clarity make any changes to our Microsoft 365 tenant?
No. All Microsoft Graph API permissions granted to M365Clarity are read-only. The application cannot create, modify, or delete any resource in your Microsoft 365 tenant. It cannot send emails, change policies, create users, modify group memberships, or alter any configuration.
This is enforced at the permission scope level by Microsoft — read-only scopes do not grant write access regardless of what the application requests.
What infrastructure and uptime commitments does M365Clarity provide?
M365Clarity runs on Cloudflare Workers and D1, which provide global availability across Cloudflare's network. Cloudflare's infrastructure SLA is 99.9% uptime. M365Clarity does not currently offer a formal SLA to customers beyond the underlying infrastructure guarantees.
Scheduled scans and AI features depend on Microsoft Graph API and Anthropic API availability respectively. Temporary unavailability of these services is handled gracefully — scans will fail cleanly and retry rather than producing incorrect results.