Help & Knowledge Base

Everything you need to get the most from M365Clarity.

Contents

🚀 Getting started
✨ AI features
📊 Features & data
🏢 Multi-Tenant (MSP)
🔒 Security & compliance
❓ FAQ & billing

Connecting your Microsoft 365 tenant

When you sign in for the first time, Microsoft will show a permissions consent screen listing what M365Clarity is requesting access to. There is an important checkbox at the bottom of this screen:

Tick "Consent on behalf of your organisation" before clicking Accept.

This checkbox only appears if you are signed in as a Global Administrator. If you do not tick it, M365Clarity's permissions apply only to your own user account — tenant-wide settings (MFA policies, SharePoint configuration, Conditional Access, audit logs, etc.) will not be readable and your scan will return incomplete or empty results.

Who needs to connect the tenant?

You must sign in as a Global Administrator of the tenant you want to scan. This is required because many of the configuration settings M365Clarity checks are only readable by a tenant admin. If you sign in as a regular user, the consent checkbox will not appear and tenant-wide data will not be accessible.

What role does the connecting account need?

For full coverage, the account you use to connect should be a Global Administrator. For complete SharePoint and OneDrive results, the connecting account must have the SharePoint Administrator or Global Reader role. Surprisingly, Global Administrator alone is not listed as a permitted role for the SharePoint settings API — this is a Microsoft platform decision confirmed in their official API documentation. You can assign SharePoint Administrator in Microsoft Entra ID → Roles and administrators → SharePoint Administrator.

Does my connection expire?

Microsoft access tokens expire after 1 hour. M365Clarity automatically refreshes your token in the background each time you open the dashboard — you should never need to reconnect unless you revoke access from the Microsoft side or the refresh token itself expires after 90 days of inactivity. If a refresh fails, an amber banner appears on your dashboard with a Re-scan button to try again.

What if I forgot to tick the box?

If you signed in without ticking "Consent on behalf of your organisation", your scan will likely show many features as Not Verified or return empty results. To fix this:

  1. Go to Account → Connected Tenants and click Disconnect next to the affected tenant
  2. Click + Add Tenant (or Connect Tenant if you have no tenants connected)
  3. Sign in again with your Global Administrator account
  4. On the Microsoft consent screen, tick "Consent on behalf of your organisation" before clicking Accept

What permissions are requested?

All scopes are read-only. M365Clarity cannot modify your tenant, send emails, change settings, or access the content of messages or files. A full list of scopes is in the Security & data privacy section below.

How M365Clarity works

M365Clarity connects to your Microsoft 365 tenant using read-only OAuth and checks your actual configuration via the Microsoft Graph API. It does not install any agents, scripts, or extensions in your environment.

The process is:

  1. You sign in with your Microsoft 365 account
  2. M365Clarity requests read-only Graph API permission for your tenant
  3. A scan runs — typically completing in 20–40 seconds
  4. Results are displayed as Configured ✓, Needs Review ⚠, or Not Verified for each feature
  5. Paid plans unlock AI-powered analysis, compliance mapping, and PDF reports
M365Clarity can never modify your tenant. All Microsoft Graph scopes requested are read-only. We cannot send emails, edit files, change settings, or access the content of messages or documents.

Feature scan explained

Feature Health Score

Every scan produces a Feature Health Score from 0–100. The score is calculated from your configurable features only (not always-on productivity services):

What "Not Verified" means

A grey "Not Verified" tile means M365Clarity attempted to check that feature but could not produce a reliable result. This happens for one of two reasons:

Not Verified tiles do not penalise your score. They are excluded from the Feature Health Score calculation entirely.

Why some tiles don't appear at all

M365Clarity only shows feature tiles that are relevant to your Microsoft 365 plan. Features your licence does not include are hidden from the main tile grid — they appear in a collapsible "not available on your plan" section below the grid instead, so you can see what exists at higher tiers without cluttering your results. Features can also be hidden where an evaluator has been permanently retired — because the API endpoint no longer exposes the data needed for a reliable assessment.

Configurable vs Always-On features

Configurable services are features included in your licence that require admin action to enable or configure — things like Conditional Access, DLP policies, or Teams meeting policies.

Always-On services are core productivity features included as part of your licence — Exchange Online, SharePoint, Teams, OneDrive, Forms, Planner, and Stream. These tiles show as green to confirm the service is part of your licenced plan. They do not indicate whether the service is currently online or experiencing issues — M365Clarity is not a monitoring tool. For live service health, check the Microsoft 365 Service Health dashboard in your admin centre.

What plans are detected?

M365Clarity automatically detects your Microsoft 365 licence plan via the subscribed SKUs API. Supported plans include Business Basic, Business Standard, Business Premium, Office 365 E1/E3/E5, Microsoft 365 E3/E5/E7, F1/F3, Education A1/A3/A5, and Entra ID P1/P2.

AI features guide

M365Clarity's AI features are powered by Anthropic's Claude. They are designed to translate raw scan data into plain English guidance — no technical background required.

Plain English explanations Free

Every feature card in the scan results includes a plain English description of what the feature does and why it matters to your business. Click any feature to see a one-sentence business impact statement. This is available to all users on the free tier — no upgrade required.

Priority Actions Pro

Claude analyses all red and amber findings from your scan and produces a ranked action list — ordered by business impact and effort, not just severity. Each action includes a one-sentence rationale, an effort rating (Low / Medium / High), an estimated time to complete, and a direct link to the relevant Microsoft documentation. Priority Actions covers every feature M365Clarity scans — including identity, threat protection, compliance, Purview, Intune, and collaboration — so the list reflects your full tenant posture, not just the most obvious gaps. Find it under Insights → Priority Actions. A ⟳ Regenerate button appears after a new scan has run, since new data would change the recommendations.

Executive Summary Pro

Generates a board-ready summary of your Microsoft 365 health — written for a business owner, IT Director, or CFO audience, not a technical team. The summary includes: a one-sentence headline specific to your tenant's situation, a 3–4 paragraph narrative referencing actual scores and domain grades, a Domain Health section showing AI-assessed grades for Incident Readiness, Backup & Recovery, CA Coverage, and Intune Health, a Purview compliance snapshot showing how many elements were assessed and how many have critical gaps, a Top Risks section with business impact and recommended fix for each risk, a What's Configured Well list, and a 5–7 step recommended next steps plan. The summary uses cached results from other AI tabs — opening Incident Readiness, Backup & Recovery, and Intune Health before generating the summary gives it the most data to work with. Find it under Insights → Executive Summary.

AI explanations on click Pro

Pro users can click any feature card to open a side panel with a full AI-generated explanation — written specifically for your tenant's configuration. Instead of "MFA registration is amber", you get "Most of your staff have set up MFA, but 3 admin accounts haven't. Admin accounts are the highest-value target for attackers — this should be resolved urgently."

Explanations are generated once per feature per scan and cached — you can re-open them instantly without waiting.

Step-by-step setup guides Pro

In the same side panel, switch to the "How to fix" tab to get a generated step-by-step guide for that specific feature. The guide includes:

Guides are tailored to your specific Microsoft 365 plan — instructions for Business Basic will differ from E3 where relevant.

Priority Actions Pro

Analyses your red and amber findings and produces up to 6 prioritised fix actions ranked by business impact. Each action includes an effort estimate, impact rating, rationale, step-by-step instructions, and a link to Microsoft documentation.

AI change alerts Pro

When a scheduled scan detects a configuration change vs the previous scan (for example, if SharePoint external sharing moved from amber to red), an AI-written email is sent explaining:

Change alerts are only sent when something actually changes — you will not receive emails for scans where nothing has changed.

Compliance Mapping Pro

Maps your scan results against three frameworks: Cyber Essentials, ISO 27001, and NIST CSF. Each framework shows a grade, pass/fail percentage, and per-control status based on your actual configuration.

Executive Summary Pro

Generates a board-ready summary with a risk level, top risks (with business impact), positive findings, and recommended next steps — written for a non-technical executive audience.

What If & Licence Advisor Pro

Ask what-if questions about your tenant configuration before making changes — for example: "What if I enabled external email forwarding?", "What if I removed permanent Global Admin assignments?", or "What would happen to my score if I fixed all RED items?" Each response describes the security posture impact and compliance implications based on your actual scan data. 10 prompts per day.

The same chat also answers licensing questions grounded in your tenant's active licences and Microsoft's published licensing terms. For example: "What licences would I need to add Copilot for Microsoft 365?", "Do I need to license all users for Defender for Business or just specific ones?", or "What is the difference between Defender for Business and Defender for Endpoint P2?" For more accurate answers, set your Agreement Type (CSP, EA, MCA, etc.) and Microsoft Cloud (Commercial, GCC, etc.) under Tenant Settings — the AI uses these to tailor its answers to how your agreement type affects procurement options.

When the AI detects a specific licensing intent — something you've expressed a decision to act on, such as "Add Copilot for 10 users" — a 💼 Licensing intent detected chip appears below the response. Tap Add to renewal briefing to save it. Saved intents accumulate in the Licence Recommendations tab under "Licensing changes queued" and are automatically included in your next partner renewal brief. Tap Dismiss to discard the chip without saving.

Responses are informational only and do not constitute security, IT, or licensing advice. Always verify licensing requirements with your Microsoft partner before purchasing.

Adoption Coach Pro

Adoption by Department

Teams, Email, and OneDrive adoption rates broken down by department — pulled from the department field in your Azure AD user profiles. Departments are sorted by lowest overall adoption first, so the teams that need the most attention appear at the top. Tap any department row to expand it and see per-workload adoption rates (Teams, Email, OneDrive separately). Users without a department set in Azure AD are grouped under "No department set". Data is drawn from the per-user activity reports already collected at scan time — no additional Graph calls are made at load time except one call to fetch department names. Cached after first load. Pro plan only. Find it in the Workload Adoption tab.

Adoption Coach is built into the Workload Adoption tab — it is not a separate navigation item. For each workload with adoption below 70%, a 🎯 Adoption Coach toggle appears below the adoption bar. Click it to generate a specific action plan grounded in your tenant's actual scan results. The plan includes a root cause (for example, if Teams adoption is low and meeting policies are on defaults, it identifies that Teams has not been formally deployed), three concrete steps with effort ratings (Low/Medium/High) and the exact admin centre path for each, an expected outcome, and an optional user communications note suggesting what to tell end users before or after the change. The plan is generated on first click (10-15 seconds) and cached per scan — re-opening is instant.

Change Management Pro

The Change Management tab analyses your scan data and workload adoption rates to identify which organisational transitions are currently in progress — for example, moving from email to Teams meetings, or from a shared network drive to SharePoint. Rather than reporting at service level, it infers the specific transition underway and positions your organisation within the ADKAR change model (Awareness, Desire, Knowledge, Ability, Reinforcement). For each detected transition it shows: what the scan evidence suggests, where your organisation likely is in the change journey, the ADKAR stage with rationale, a recommended intervention specific to that stage, a realistic timeframe, and a link to the relevant M365Clarity blog guide. Results are generated on first click and cached per scan.

Digital Friction Pro

The Digital Friction tab reframes your tenant's amber and red configuration findings through an adoption lens — identifying not just what's misconfigured, but what that misconfiguration is causing your users to do instead. It produces a friction score (0–100) and grade (Low / Medium / High / Critical), a set of friction points, a Quick Wins section, and an AI narrative summary.

Each friction point has four components: What's happening — the specific configuration gap causing friction. Quantified impact (shown in a cyan panel when data is available) — a specific number from your tenant scan, such as "22 of 24 Conditional Access policies have no session controls configured" or "68% of licensed users have never activated a desktop app". Likely workaround — what users are probably doing instead, for example "Users are likely sharing files via personal Google Drive instead of SharePoint". How to fix — the single most effective configuration change to reduce this friction.

The six friction signals M365Clarity detects and quantifies: MFA re-authentication fatigue — reads session controls from each active Conditional Access policy to identify policies with no frequency configuration, aggressive re-auth intervals, or every-sign-in requirements. Device management gap — cross-references Intune enrolled device count against licensed user count; when less than 50% of users have managed devices, unmanaged users face MFA re-prompts on every session. App activation gap — identifies licensed users who have never activated any Microsoft 365 desktop or mobile app (restricted to browser-only access). External sharing restrictions — detects over-restriction (sharing fully disabled) which drives users to personal file sharing services. OneDrive sync without device governance — flags unrestricted sync to unmanaged devices. Email activity gaps — high zero-activity rate alongside misconfigured EOP suggests over-aggressive spam filtering.

Results are generated using AI and cached per scan. Use the Regenerate option to refresh after a new scan or configuration change. Rate limited to 5 regenerations per hour.

Security Incident Readiness Pro

A five-pillar security readiness model (Detect, Protect, Recover, Identity, Compliance) that scores your tenant across controls drawn from your existing scan results. Each pillar receives an individual score (0–100) and grade (A–F), with a visual progress bar and a list of failing or warning controls. An AI narrative explains the overall score in plain English. Find it under Security & Compliance → Incident Readiness.

Backup & Recovery Readiness Pro

Assesses how recoverable your data is if ransomware or accidental deletion strikes today. Evaluates Microsoft 365 Backup status for Exchange, SharePoint, and OneDrive individually, along with retention policies, audit trail coverage, and ransomware prevention controls. Includes an AI-generated ransomware scenario. Find it under Security & Compliance → Backup & Recovery.

Device Security Posture Pro

A four-category scored assessment of your device security posture — Credential Protection (LAPS, Credential Guard, passkeys), Endpoint Hardening (BitLocker, WDAC, ASR rules, update rings), Device Management (Intune enrolment, compliance policies, Autopilot), and Threat Detection (Defender for Endpoint, Vulnerability Management, Endpoint Analytics). Each category is scored and graded, with an AI narrative on the real-world risk from your weakest controls. Find it under Security & Compliance → Device Security Posture.

Compliance Posture Pro

Compliance Risk Register

The Compliance tab has two views, toggled at the top: Risk Register (default) and Framework View. The Risk Register shows only failing and partial controls across all three frameworks (Cyber Essentials, ISO 27001, NIST CSF), ranked by exposure width — the number of failing features mapped to each control — rather than by a colour label. A control with 6 red features ranks above a control with 1 amber feature, even if both are categorised as "High". Exposure score = (red features × 3) + (amber features × 1). A secondary sort by control domain criticality breaks ties: access control and identity controls rank above audit and policy controls at equal exposure. Each row shows the severity chip (High/Medium/Low) as a visual indicator, the framework badge, and an "N of M features failing" count showing the actual exposure width. The Framework View shows the original accordion view with pass/fail/partial breakdown per framework. Empty state: "No failing controls" when all assessed controls pass.

A four-category scored assessment of your data governance and compliance readiness — Data Protection (DLP, sensitivity labels, Copilot DLP), Data Lifecycle (retention policies, Records Management, Data Lifecycle Management), Audit & Investigation (audit logging, eDiscovery), and Insider Risk (Insider Risk Management, Communication Compliance, Adaptive Protection). An AI narrative explains the regulatory exposure from your weakest areas. Find it under Security & Compliance → Compliance Posture.

Conditional Access Coverage Map Pro

Analyses every Conditional Access policy in your tenant to surface coverage gaps — scenarios where users, apps, or sign-in conditions have no active CA policy protecting them. Critical gaps (no enforced MFA-for-all, legacy auth not blocked, non-compliant devices permitted) are flagged with severity levels. All policies are shown with their attribute chips (users, apps, conditions, grant controls) and an enforced/report-only filter. AI-generated gap explanations explain the business risk for each uncovered scenario. Find it under Security & Compliance → CA Coverage Map.

Application Audit Pro

Lists every third-party enterprise application and OAuth app with access to your tenant, scored by permission risk. High-risk permissions (Mail.ReadWrite, Files.ReadWrite.All, Directory.ReadWrite.All) are highlighted. Unverified publishers are flagged separately. Each app shows which users have consented, which permissions are granted, and a risk level (High / Medium / Low). Find it under Security & Compliance → App Audit. Requires the Application.Read.All consent scope — if you connected before this scope was added, reconnect to enable it.

90-Day Adoption Roadmap Pro

The 90-Day Adoption Roadmap generates a sequenced, dependency-mapped plan for enabling and adopting Microsoft 365 features — specific to your tenant's actual scan data and licence plan. It organises work into three phases: Phase 1 Foundation (Weeks 1–4) covers security and identity basics that everything else depends on, using only features flagged red or amber in your scan. Phase 2 Collaboration (Weeks 5–8) covers workload adoption tools once the foundation is in place. Phase 3 Optimisation (Weeks 9–12) covers advanced features, governance, and automation. The roadmap also surfaces three quick wins — changes that take under an hour with immediate high impact. Every step includes an effort rating, expected outcome, dependency chain, and the exact admin centre link to make the change. Results are generated on first click and cached per scan.

M365 Changelog Monitor Pro

The M365 Changelog Monitor fetches the last 90 days of Microsoft Message Centre announcements via Graph API and uses AI to filter them to what is relevant for your specific plan and tenant configuration. Each announcement is categorised as New Feature, Change, Deprecation, Security, or Action Required. Urgent items — those requiring action before a deadline or with security implications — are flagged with a red border and appear first. Each entry includes a plain-English explanation of why it matters for your plan and exactly what action to take (or confirms no action is required). You can filter posts by All, Urgent, or Action Required. The monitor refreshes every 24 hours. Note: this feature requires the ServiceMessage.Read.All Graph permission. If this was not granted when you connected your tenant, reconnect from the Account page to add it.

July 2026 — new permission added: M365Clarity added DeviceManagementServiceConfig.Read.All to its scope list (v10). This unlocks Windows Autopilot, Intune Enrolment Restrictions, and Remote Help visibility. If you connected your tenant before 15 July 2026, you will see a "Reconnect recommended" banner — clicking it takes you through a one-time consent step to grant the new permission. No data is lost and your scan history is preserved.

Upcoming Microsoft Retirements Pro

The Deprecated Features section appears below the Changelog Monitor and shows Microsoft retirement notices specifically — features, APIs, or authentication methods that Microsoft has announced will be withdrawn. Each notice shows the retirement date, the affected service, urgency (Critical / Warning / Watch / Future based on days remaining), and an AI-generated one-sentence summary of the impact on your tenant. Notices that affect services active in your tenant are shown first with a "Your tenant" badge. This section reads from the same pre-fetched Message Centre data as the Changelog Monitor — it does not make additional API calls. Note: if the Changelog Monitor has not been loaded for this scan, load it first and then the retirement section will populate automatically.

Conversational Remediation Pro

Every step in every AI Setup Guide has a built-in "🤔 Stuck on this step?" button. Click it to open an inline question input scoped specifically to that step. Ask what's going wrong — for example, "Error connecting with Connect-SPOService" or "The policy saved but it's not showing as enforced" — and the assistant responds with help specific to that exact step. The response is deliberately narrow: it can only answer questions about the specific remediation step you're on. It cannot provide general Microsoft 365 advice, discuss other features, or go off topic. If you ask something outside the scope of the step, it redirects you back. This constraint is intentional — a broad AI assistant drifting off topic during active remediation is more likely to cause problems than solve them. Rate limited to 10 questions per hour per user. Available to Pro and Multi-Tenant accounts.

Executive Briefing PDF Pro

The Executive Briefing is a board-ready document generated from your Executive Summary scan data. Unlike the technical PDF report — which lists all feature checks, scores, and remediation steps — the executive briefing is written entirely in plain English for a CEO, CFO, or board audience. It contains: an overall grade and health score with a plain-English narrative, domain grades for Identity, Threat, Compliance, Devices, and Collaboration, top risks described as business impacts with recommended actions, what is working well, a compliance overview where relevant, Copilot readiness if applicable, and numbered next steps. To generate it: open the Executive Summary tab and wait for it to load, then scroll to the bottom and click "📄 Download Executive Briefing." The document opens in a new tab with a "Download PDF" button that triggers your browser's print-to-PDF dialog. The Executive Summary tab must have been loaded at least once before the briefing can be generated. If your account has a company logo uploaded, it will appear in the briefing header.

Predictive Risk Alerts Pro

Predictive Risk Alerts appear on the Overview tab when time-bound risk signals are detected in your tenant's scan data. Currently M365Clarity generates two types of alert: retirement-based alerts, which flag Microsoft retirement notices that directly affect services active in your tenant (for example, SMS/voice MFA retiring on 1 September 2026 for tenants with users registered for those methods), and trend-based alerts, which surface features that have degraded across two or more consecutive scans, suggesting an underlying configuration issue that is not being consistently remediated. Alerts are colour-coded by urgency — Critical (less than 30 days to deadline), Warning (30–90 days), Watch (90–180 days), and Future (beyond 180 days). The card is hidden when no alerts exist. Note: trend-based alerts require at least two complete scans to generate comparison data. More predictive signals will be added as scan history grows across the platform.

Pro and Multi-Tenant accounts can upload a company logo from the Account page. Your logo appears in the header of PDF reports exported from M365Clarity — replacing the M365Clarity brand text. Supported formats: PNG, JPG, SVG, WebP. Maximum size: 512KB. Upload or remove your logo at any time from Account → Report Logo.

Client notes Multi-Tenant

Multi-Tenant accounts can add internal freetext notes to each client tenant directly from the MSP Portfolio dashboard. Notes are visible only to your MSP account — they are never shared with clients or included in client-facing reports. Notes are limited to 2,000 characters per client. Use them to track context such as renewal dates, outstanding actions, or client-specific configuration decisions. Notes are saved immediately on clicking Save and persist across sessions.

Natural Language Portfolio Queries Multi-Tenant

The Query tab in the MSP Portfolio lets you ask plain-English questions about your client tenants and get instant answers drawn from their scan data. Type a question — for example, "Which clients have MFA issues?", "Show health scores for all clients", or "Which tenants have SharePoint external sharing enabled?" — and M365Clarity returns a plain-English answer referencing your specific clients by name.

What you can ask: Any question about the security posture, health scores, specific features, or findings across your portfolio. The AI answers from the actual scan data — not generically.

Guardrails: Queries are scoped strictly to your own connected tenants. The AI only receives data from your portfolio — it physically cannot access or reference data from any other account. Even a question attempting to retrieve another organisation's data would return nothing, because that data is not present in the context. This is enforced at the data layer, not just the prompt layer.

Limitations: Green (passing) features are not included in the query context to keep the payload compact — if you ask what's passing for a client, the AI will direct you to that client's dashboard for the full picture. The query reflects the latest complete scan per tenant. Rate limited to 20 queries per hour. Available to Multi-Tenant accounts only.

Portfolio Benchmarking Multi-Tenant

The Benchmarks tab in the MSP Portfolio ranks all your client tenants by health score, shows each client's position relative to your portfolio average, and surfaces which features are most commonly failing across clients. This lets you identify systemic gaps — if 80% of your clients have a failing DLP policy, that's a practice-level issue to address, not a one-off remediation. Benchmarks are scoped to your own portfolio only — client data is never compared against or shared with other MSP accounts.

Multi-Tenant Portfolio AI Summary Multi-Tenant

From the Portfolio view, click "AI Summary" to get an AI-generated overview of your entire client portfolio in one paragraph — including urgent cross-tenant actions and highlights. Results are cached for 6 hours and can be refreshed on demand.

Cross-tenant pattern detection Multi-Tenant

The "Patterns" tab in the Portfolio view uses AI to detect configuration issues that appear across multiple client tenants — for example, "4 of your 8 clients have SharePoint external sharing open." Each pattern includes which tenants are affected and a recommended remediation approach. This lets you address systemic issues systematically rather than one client at a time.

AI risk ranking Multi-Tenant

The "Risk Ranking" tab orders all your client tenants from highest to lowest risk, with an AI-generated explanation of what is driving each client's risk level and what the recommended first action is. Use this to prioritise which client to call first.

Client report narrative Multi-Tenant

In the Executive tab for any tenant, MSP users see a "Generate Client Report Narrative" button. This produces a full set of professional paragraphs suitable for a client-facing report or QBR document — introduction, quarterly summary, key findings, recommended investments, and a conclusion. Click "Print / Export PDF" to save it.

Cross-tenant weekly digest Multi-Tenant

Every Monday, Multi-Tenant users automatically receive a single email summarising every client tenant — health score, number of red/amber issues, and week-on-week trend. Tenants with 5+ critical issues are flagged for immediate attention at the top of the email.

You can also trigger the digest manually from the MSP Portfolio view using Send weekly summary — useful if you want it before Monday or are setting up a new client.

Bulk schedule all tenants Multi-Tenant

From the MSP Portfolio view, click Schedule all weekly to set weekly automated scans across all connected client tenants in one action. Scans are staggered and run at 06:00 UTC on their scheduled day. You can override individual tenants in their tenant settings after bulk scheduling.

Return Summary Pro

When you open the dashboard after being away for more than 24 hours, a card appears at the top of the Overview tab showing exactly what changed since your last visit — which features improved, which regressed, how many days have passed, and an AI sentence describing the most significant change. Dismiss it with the ✕ button once read. Shown once per scan, not on every page load.

Proactive AI Insights Pro

Each time you open a scan, Claude independently analyses your full configuration and surfaces one observation worth flagging — a pattern you might have missed, a contradiction between two features, or a compounding gap. It appears as a 💡 card at the top of the Overview tab. Generated once per scan, cached for 7 days, and different to the Return Summary (which tracks changes over time).

Health Score Benchmarking Pro

The History tab shows your health score trend over time alongside the average score across all tenants M365Clarity monitors. A benchmark card compares your score to the average, with context about how many tenants are included. An AI sentence below the chart describes your direction — for example "Your health score has improved 8 points across your last 5 scans. A few more fixes could reach an A grade." The benchmark is anonymised and aggregated; no individual tenant data is shared.

Health Score Trend (Overview tab)

A compact sparkline card on the Overview tab showing your health score across every complete scan — from first connection to today. The card shows your current score, best score, total scan count, and a trend badge (↑ improving / ↓ declining / stable). Green line when improving, red when declining. Requires at least 2 complete scans to appear. Pro plan only. Find it on the Overview tab below This Month's Focus.

Fixed Since Last Scan (Overview tab)

A factual feature-by-feature comparison between your most recent scan and the one before it. Shows two sections: ✅ Fixed — features that moved from red or amber to green since the previous scan, and ⚠️ New Issues — features that moved from green to red or amber. Each row shows the feature name and the status change (e.g. "red → green"). A score delta badge shows the overall point change between scans. The card is hidden when there is no previous scan to compare against, or when no features changed status. Find it on the Overview tab below the Health Score Trend card. Available on all plans.

Shareable Report Links Pro

From the Overview tab, click 🔗 Share report to generate a read-only public link. Anyone with the link can view the report — no M365Clarity account required. Links expire after 30 days and can be regenerated at any time. The public report includes: health score and grade, a full feature list grouped by category with red/amber/green status for each item, and — when you have already opened the relevant AI tabs — an enriched executive summary with domain health grades (Incident Readiness, Backup & Recovery, CA Coverage, Intune Health), top risks with business impact and recommended fix, a Purview compliance snapshot, what's configured well, and recommended next steps. The AI enrichment is sourced entirely from cached results — no additional API calls are made when the link is opened. Use it to share scan results with an IT director, auditor, board member, or external consultant.

Viewer access Pro

Pro and Multi-Tenant users can invite one read-only viewer per tenant. The viewer sees the full dashboard including all AI tabs but cannot run scans, change settings, or invite additional viewers. Invite a viewer from Settings → Share access. The viewer receives an email invitation and is prompted to create a free M365Clarity account if they do not have one. This is different from the public report link — a viewer has a persistent account with full dashboard access, while a public link recipient sees a read-only report page with no login required.

PowerShell Commands Pro

Setup guides include a PowerShell command wherever one is applicable. Click any red or amber feature to open the feature drawer, then click Get Fix Guide to generate a step-by-step guide for your specific tenant. Commands are shown in a copyable code block. A separate verification command is shown at the end of each guide to confirm the fix has taken effect. Commands require a PowerShell session connected to your Microsoft 365 tenant (typically via the Microsoft Teams or Exchange Online PowerShell modules).

Teams & Slack Webhook Alerts Pro

Go to Account → Alert Webhook to connect M365Clarity to your Microsoft Teams or Slack channel. Paste your incoming webhook URL, select the platform type, and save. When a scheduled scan detects a configuration change, M365Clarity posts a message to your channel naming the specific features that changed. This is in addition to the email alert — you can use both, or just the webhook. Webhook URLs are stored encrypted per tenant and can be removed at any time.

Weekly Health Digest Pro

Every Monday morning, Pro and Multi-Tenant users automatically receive a weekly digest email. It shows your current health score, the trend versus the previous scan, the number of remaining issues, and a brief summary of any notable change from the week. If your score dropped, the email says so and links back to Priority Actions. If the score is unchanged, the digest still sends with a summary of open issues — keeping the platform visible even in quiet weeks. No configuration required — the digest fires automatically as long as you have a completed scan in the last 14 days.

SharePoint & OneDrive AI Sharing Posture Pro

Found under Security & Compliance → Teams & SharePoint, the AI Sharing Posture card analyses your tenant's external sharing configuration and produces a plain-English risk assessment. It evaluates six key settings from the SharePoint tenant settings API: sharingCapability (who can share externally), defaultSharingLinkType (what type of link is created by default), defaultLinkPermission (whether default links grant view or edit access), sharingDomainRestrictionMode (whether sharing is restricted to specific domains), preventExternalUsersFromResharing, and requireAcceptingUserToMatchInvitedUser.

The feature returns a risk level (low / medium / high / critical), a one-sentence headline specific to your tenant's settings, a narrative explanation in plain English, a breakdown of specific risks with severity labels, what is configured well, and a list of recommended actions with effort ratings. Results are generated on first click and cached per scan — subsequent visits load instantly. The analysis updates automatically after each rescan.

Unlike the feature status rows above it (which give a binary pass/fail), the AI Sharing Posture explains the combination of settings and what they mean together — for example, anonymous sharing enabled with default edit permissions is significantly higher risk than anonymous sharing with view-only defaults.

Teams Governance AI Analysis Pro

Appears below the Teams list in the Teams Governance tab. Unlike the raw data table above it (which shows every team with owner counts and risk flags), the AI Analysis synthesises the governance data into a risk narrative: how many teams have no owner, how many are public, how many are potentially abandoned, and what the business risk of that state is.

The analysis requires the Teams Governance report to be loaded first — it reads from the cached governance data rather than making new Graph API calls. If Teams Governance has not been run in the current session, the card will prompt you to run it first. Results are cached per scan and regenerated after each rescan.

Teams Phone & Voice Pro

Found under Security & Compliance → Teams Phone, this tab combines a feature status view of your Teams calling configuration with an AI assessment of your voice deployment health. It assesses six areas: Teams Phone voice policies, meeting policies, guest access, external federation, meeting recording policy, and Teams Premium feature availability.

The AI Voice Configuration Analysis generates a risk level and narrative specific to your tenant's voice configuration. It is particularly useful for tenants that have purchased Teams Phone System licences (included in E5 or as an add-on) and want to confirm voice policies are correctly deployed to users. If Teams Phone is not licensed, the tab returns a clear explanation rather than an error. Results are cached per scan and regenerated after each rescan.

Viva Adoption Pro

A dedicated tab under Adoption & Change Management → Viva Adoption that analyses the health of your Microsoft Viva workload deployment. The tab only appears in the sidebar if the tenant plan includes at least one Viva workload (Viva Engage, Viva Learning, Viva Connections, Viva Amplify, Viva Goals, or Microsoft Loop).

For each detected Viva workload, the AI assigns an adoption grade (A through F) and a one-sentence insight explaining the grade. The tab also returns an overall adoption health level and a list of recommended actions to improve Viva rollout. If no Viva licences are detected, the tab displays a clear explanation rather than an error. Results are cached per scan and regenerated after each rescan.

Intune Health Report Pro

The Intune Health Report gives you a structured view of your device management posture across seven sections:

The report also generates a lost/stolen device scenario — a realistic AI-written description of what would happen if a device was lost today given your current BitLocker, PIN policy, remote wipe, and MAM configuration. No new Microsoft permissions are required — Intune scopes were already included in the M365Clarity connection.

Copilot Readiness Pro

Microsoft 365 Copilot has specific licence and configuration prerequisites that must be met before it can be deployed. The Copilot Readiness tab checks your tenant against every known requirement and gives you:

Copilot prerequisites checked include: appropriate licence SKU (M365 E3/E5 or Business Standard/Premium), MFA enforced, Entra ID configured, Exchange Online active, SharePoint and OneDrive enabled, Teams deployed.

Copilot & AI Pro

The Copilot & AI tab is a dedicated Pro view with three sections, switchable within the tab. It goes beyond readiness checking to show what you have, how well it is being used, and whether your tenant is safe for autonomous agents.

📋 What You Have

Detects your Copilot tier from your subscribed licences and shows a feature inclusion table across all Copilot capabilities:

Each feature in the table shows either ✓ Included at your current tier, or the plan required to unlock it.

📊 Adoption Health & ROI

Pulls live per-user Copilot usage data from Microsoft Graph (the last 30 days). Requires paid Copilot licences to be assigned in your tenant — the API only returns data for licensed users.

The adoption section shows:

Copilot ROI signal — a colour-coded card that answers the question your CFO or IT director is asking: are we getting value from the Copilot investment?

The card also shows cost per active user per month — if you have 5 licences at £30 each and only 3 are active, the real cost per active user is £50/month. This is the number that cuts through in a board conversation about whether Copilot is delivering value.

The per-app breakdown shows adoption rates for Teams, Word, Excel, PowerPoint, Outlook, OneNote, Loop, and Copilot Chat individually — sorted from highest to lowest. Apps with zero 30-day usage are flagged immediately.

M365Clarity records a monthly adoption snapshot each time you open this tab, building a 12-month trend over time.

Adoption data is only available if your tenant has paid Microsoft 365 Copilot licences (Copilot Premium) assigned to users. Copilot Basic (Chat only) usage is not exposed via Microsoft Graph reports APIs.

🤖 Agent 365 Readiness

Before deploying autonomous agents via Agent 365 or Copilot Studio, seven governance controls should be in place. This section checks each one against your existing scan data — no additional API calls required.

Controls checked:

Each control shows Pass, Review, or Fix with the actual finding from your scan. An overall Agent Readiness Score (0–100%) summarises your governance posture with a plain-language verdict.

Agent 365 is available as a standalone add-on or is included in Microsoft 365 E7 (which also includes Copilot Premium and the Entra Suite). You can run the readiness check at any tier — it is valuable even before you have Agent 365 licensed so you can prepare your governance posture in advance.

Workload Adoption Pro

The Workload Adoption tab shows how many of your licensed users are actively using each Microsoft 365 workload over the last 30 days. It fetches live data from the Microsoft Graph activity reports API using the Reports.Read.All permission, which is included in your standard M365Clarity consent.

Workloads covered:

Each workload shows a coloured bar: green (≥70% adoption), amber (40–69%), red (<40%). Low adoption workloads include a plain-language note suggesting training or licence right-sizing.

Workload adoption data is only available if your tenant is actively connected to M365Clarity and the Graph activity reports are enabled (on by default for most tenants). The report covers the previous 30-day window.

Per-user activity detail

Below the workload bars, click Per-user activity detail to expand a panel showing per-user inactive users and licence waste signals. This data is pre-fetched during every scan using eight Microsoft Graph v1.0 report endpoints and requires no additional permissions. The panel shows:

Privacy note: Some tenants enable Microsoft's "Display concealed user, group, and site names in reports" setting, which anonymises user names in activity reports. If this is enabled, M365Clarity will show a warning in the per-user detail panel with instructions to disable it. The setting is in Microsoft 365 admin centre → Settings → Org settings → Reports.

SharePoint Site Health Pro

The SharePoint Site Health tab is available under Teams & SharePoint → SharePoint Site Health in the sidebar. It reads per-site activity and storage data from the Microsoft Graph getSharePointSiteUsageDetail report (v1.0, D30 period) using the Reports.Read.All permission already included in your M365Clarity consent. Data is pre-fetched during every scan — the tab loads instantly.

For each SharePoint site the tab shows:

Sites are split into two views:

The summary section at the top shows total sites, abandoned site count, abandoned storage (in GB), and active site count.

SharePoint Site Health AI Governance Assessment

The tab automatically generates an AI governance assessment after the site data loads. The assessment uses Claude (AI_MODEL_FAST) grounded in your actual site counts and storage numbers — not generic advice. It returns:

Risk level thresholds:

The AI assessment does not reference individual site URLs in its narrative. Site names may contain confidential project or department names, so the narrative addresses patterns and totals only. The full site list with URLs is available in the Abandoned and Active tabs below the assessment.

Unlocked but Unused Pro

The Unlocked but Unused tab crosses two data sources to find features you are already paying for but have not switched on:

  1. M365 Feature Registry — M365Clarity's catalogue of Microsoft 365 features and which licence plans include them, built from daily scans of m365maps.com
  2. Your scan results — the RAG status of each feature in your actual tenant configuration

Any feature that is included in your plan but shows red (not configured), amber (partially configured), or unknown in your scan is surfaced as a gap. Features are grouped by workload (Teams, Entra ID, Purview etc.) and each has a direct link to Microsoft's documentation.

You can filter by status: All, Not Configured (red), or Partial (amber).

⚡ What Now — baseline config guides

Every gap card has a ⚡ What now button. Clicking it generates an AI-powered baseline adoption guide specifically for that feature, grounded in your tenant's plan, sector, and size — and aware of which adjacent features you already have configured.

Each guide includes: a plain-English summary of why the feature matters for your specific setup, an adoption tip tailored to your sector and organisation size, step-by-step setup instructions with direct links to the correct Microsoft admin centre pages, a verification step to confirm the baseline is working, and a rollback note in case you need to undo it.

What Now guides are different from the remediation guides available on the main tile grid. Remediation guides fix a misconfiguration — something you've tried to set up but done incorrectly. What Now guides start from scratch — they assume you haven't touched the feature yet and walk you through the recommended first-time setup.

What Now guides are AI-generated and advisory only. Always review the recommended settings before applying them, and verify against Microsoft's official documentation for your specific plan and region.
The feature registry grows daily as the M365Clarity cron scans m365maps.com for new diagrams and plan updates. The number of gaps surfaced will increase over time as the registry expands. This is expected behaviour — it is not a worsening of your configuration.

Cost Per Active User

Shows what you are paying per person who actually uses Microsoft 365, broken down by plan SKU. For each SKU: total licensed seats, active users (signed in within 90 days), inactive users, total monthly cost, and cost per active seat in GBP. The header shows your overall cost per active seat and total monthly spend at a glance. Tap to expand for the full per-SKU table, including the monthly cost attributable to inactive seats. Uses GBP list prices from M365Clarity's price table — if you are on a CSP or EA agreement, your contracted rate will differ. Active user count is based on sign-in data from your scan; inactive count is capped at 200 users per scan. Pro plan only. Find it at the top of the Licence Recommendations tab.

Scheduled scans Pro

Pro and MSP users can enable automated scanning per tenant. Choose from:

To configure: open tenant settings in the dashboard, select a frequency, and choose whether to receive an email when each scan completes. Scans run automatically in the background — no further action needed.

MSPs can set different schedules per client tenant — for example, daily for high-risk clients and weekly for stable ones.

Multi-Tenant users can also bulk-schedule all tenants at once using Schedule all weekly in the MSP Portfolio view. This sets weekly scans on every connected client tenant simultaneously.

Scheduled scans consume your Microsoft OAuth refresh token. If you revoke M365Clarity's permissions in your Microsoft account, scheduled scans will fail until you reconnect.

MSP portfolio dashboard Multi-Tenant

The MSP plan includes a portfolio dashboard that gives you a single view across all connected client tenants. From the portfolio view you can:

To access: click Portfolio View in the top navigation (visible to MSP users only), or go to /dashboard/portfolio.

To add a client tenant: click + Add Tenant from the portfolio view. A modal will ask for a client contact email address (the person at the client organisation who should receive a connection notification — not necessarily the admin account you'll sign in with) and an optional note to include in the notification. On confirm, you'll be redirected to Microsoft to authenticate with the client's credentials or as a delegated admin. Once connected, a notification email is automatically sent to the client contact email explaining what M365Clarity is, what data is read, and that access is read-only.

To remove a client tenant: click the red button on any tenant card in the portfolio. Confirm the removal in the dialog. The tenant is soft-deleted immediately — it disappears from your portfolio and scans stop. Historical scan data is retained and purged on schedule. The client's own M365Clarity account (if they have one) is unaffected.

PDF reports Pro

Any dashboard view — Overview, Executive Summary, Compliance, Priority Actions — can be exported as a PDF. Click the Export PDF button (where available) to open a print-ready version of the current view.

PDF reports are generated from your live scan data and include your tenant name, scan date, plan, and Feature Health Score. MSP users can generate client-ready reports for use in QBRs, audits, or board presentations.

Guest account audit Pro

The Guest Audit tab shows every external guest user in your Microsoft 365 tenant — people from outside your organisation who have been invited to access Teams, SharePoint, or other services.

For each guest, M365Clarity shows:

Guest accounts are a common finding in Cyber Essentials assessments and GDPR reviews. Stale or unused guest accounts increase your attack surface and may represent a data protection obligation to remove. Use the filter buttons to focus on stale or never-active guests.

To remove stale guests, go to Microsoft Entra ID → Users → Guest users in the Azure portal. M365Clarity is read-only and cannot remove guests on your behalf.

Licence utilisation Pro

The Licences tab shows how many seats you have assigned vs how many are actually in use — broken down per Microsoft 365 SKU.

Licence prices are estimated from publicly available Microsoft pricing and are approximate. Actual costs will vary based on your agreement, any negotiated discounts, and currency fluctuations. Use the figures as a guide for conversations with your Microsoft partner or reseller — not as an invoice.

To reduce unused licences, go to Microsoft 365 Admin Centre → Billing → Licences.

See also the Licence Waste Detection tab for a user-level view showing which specific people have active licences but have not signed in recently.

Licence Waste Detection Pro

The Licence Waste tab identifies licensed users who have not signed in to Microsoft 365 in the last 90 days. These are accounts that are costing money but may no longer be needed — leavers whose accounts were not disabled, contractors who finished, or accounts that were created but never used.

For each inactive user, M365Clarity shows:

At the top of the tab, an estimated monthly and annual cost is shown for all inactive accounts combined. Prices are based on the average licence cost across your active subscriptions and are approximate.

Azure AD P1 required. Sign-in activity data is only available from Microsoft Graph if your tenant has Azure AD P1 (Entra ID P1) licences. If no inactive user data appears after a fresh scan, this licence may not be assigned to your tenant.

To review or remove inactive accounts, go to Microsoft 365 Admin Centre → Users → Active Users. M365Clarity is read-only and cannot remove or disable accounts on your behalf.

Cyber Essentials Readiness Pro

The Cyber Essentials tab maps your Microsoft 365 configuration against the five UK Government Cyber Essentials controls. It gives you a readiness score and a pass/fail status for each control, based on your actual scan data.

The five Cyber Essentials controls checked:

A Download Report button on the tab generates a standalone HTML report. Open it in a browser and use Print → Save as PDF to create a shareable PDF document.

This is a readiness indicator, not a formal Cyber Essentials certification. Cyber Essentials certification covers your entire IT infrastructure — not just Microsoft 365 — and must be formally assessed by an accredited certifying body. Visit ncsc.gov.uk/cyberessentials for official certification information.

The Compliance tab continues to show CE alongside ISO 27001 and NIST CSF for a combined view. The Cyber Essentials tab provides a more focused view with the downloadable report.

Admin account review Pro

The Admin Accounts tab checks the number of Global Administrator accounts configured in your tenant and compares it against best practice.

Recommended range: 2–4 Global Admins.

The tab lists the display name and email address of each Global Administrator account. Cyber Essentials Plus and ISO 27001 assessors typically review admin account hygiene during assessments.

SLA tracking Pro

The SLA tab tracks how long each open finding has been present in your tenant — from the first time M365Clarity detected it.

Default SLA targets:

Findings that have exceeded their SLA target are flagged in red with a "SLA BREACHED" badge. A progress bar shows how far through the SLA window each finding is.

SLA tracking requires at least two scans — the first scan establishes the baseline, subsequent scans track how long issues have persisted. If a finding is fixed and then reappears in a later scan, the SLA clock resets.

Use the filter buttons to view all findings, only breached ones, or filter by severity.

Scan comparison Pro

The Compare tab lets you select any two completed scans for the same tenant and see a before-and-after diff.

The comparison shows:

This is useful for demonstrating remediation progress to stakeholders, tracking the impact of a change window, or identifying unintended regressions after a configuration change.

Click the Print / Save as PDF button within the Compare tab to export the diff as a PDF — useful for audit evidence or client reporting.

Ticket export Pro

The Tickets tab lets you convert scan findings into actionable tickets for your IT helpdesk or ITSM system.

Export formats

Direct email sending

You can also send findings directly from M365Clarity to your IT helpdesk email address. Each selected finding is sent as a separate pre-formatted email. Emails are sent via M365Clarity's transactional email service (Brevo) from noreply@m365clarity.com to the email address on your account. The helpdesk can reply directly to you — M365Clarity is not in the reply chain.

Ticket emails are sent from noreply@m365clarity.com, not from your Microsoft 365 account. M365Clarity cannot send emails on your behalf.

Remediation tracking Pro

When you click Mark as resolved on a feature in the Priority Actions tab, you can add an optional note (e.g. ticket reference) and a target due date. The due date is stored and visible in the resolved items list, making it easier to track remediation progress across your team. Resolved items persist across scans so you can see your remediation history over time.

The Priority Actions tab shows Claude's ranked list of configuration gaps, ordered by business impact and implementation effort. Each action card has a Mark as resolved button. Clicking it opens an optional note field — useful for adding a ticket reference or brief description of what was done. Once marked, the action moves to a Resolved section at the bottom with a strikethrough. A progress bar at the top of the tab shows how many actions you have completed out of the total. Resolved status persists across sessions and devices. You can undo a resolution at any time.

What if my organisation has multiple Microsoft 365 plans?

Many organisations have more than one Microsoft 365 licence plan assigned at the same time. This is more common than you might think — for example:

How M365Clarity handles this

M365Clarity checks every active licence subscription in your tenant and builds a combined picture. Here is how the process works:

Step 1
Read your licences
M365Clarity asks Microsoft for the list of every subscription your organisation has — like reading the label on a box to see what's included.
Step 2
Skip inactive plans
Expired or suspended subscriptions are ignored — only plans that are currently active and assigned count.
Step 3
Build a combined features list
Every feature available in any of your active plans is added to the scan. If you have two plans that both include Microsoft Teams, Teams only appears once — no duplicates.
Step 4
Identify the primary plan
The most advanced plan you hold is used as the headline — so if you have both Business Basic and Business Premium, your scan is shown as a Business Premium scan.
Step 5
Show you the full picture
Results cover all features from all your plans. If you have a mixed environment, your plan label will show as "Business Premium + 1 other plan" so you can see at a glance that multiple subscriptions are in play.

A real-world example

Say your organisation has:

M365Clarity will scan features from both plans. Your office workers' features and your IT admins' advanced identity features are all included. You will see the full set of things configured (or not configured) across your whole environment — not just one half of it.

What M365Clarity does not check

M365Clarity checks what is available to your organisation based on your subscriptions — it does not check which individual users have been assigned which licence. For example, if only 5 of your 50 users have been assigned Microsoft 365 Business Standard, M365Clarity will still show all Business Standard features as available to scan, because the subscription exists on the tenant.

This is intentional — configuration decisions (like whether MFA is enforced, or whether external sharing is enabled) are tenant-wide settings, not per-user ones.

Upgrading your plan

You can upgrade from Free to Pro or from Pro to MSP (Multi-Tenant) at any time — no support ticket required.

Free → Pro: Click Get Pro in the top navigation or from any locked feature. You will be taken to a Stripe checkout page. After payment, your account is upgraded immediately.

Pro → MSP: Go to Settings → Upgrade to MSP. A card is shown at the bottom of the Settings tab for Pro users with a direct link to Stripe checkout. After payment, your account is upgraded to MSP tier and the portfolio dashboard becomes available.

Cancellation: Go to Account → Manage Billing to open the Stripe Customer Portal. You can cancel, downgrade, or update your payment method at any time. Cancellation takes effect at the end of your current billing period.

Exchange Online checks

M365Clarity assesses 14 Exchange Online elements across four areas:

Email authentication and anti-spoofing: DKIM Email Signing (including DMARC and SPF detection), External Email Warning Tag, and External Email Forwarding Blocked. These three checks cover the most common email spoofing and data exfiltration vectors.

Anti-malware and phishing: Exchange Online Protection Policies (spam and malware filter configuration), Exchange Anti-Spam Policy, Exchange Quarantine Policy, Safe Attachments (Defender for Office 365), Safe Links (Defender for Office 365), and Advanced Anti-Phishing Policy. Safe Attachments and Safe Links require Microsoft Defender for Office 365 Plan 1 or above — they will show as not licensed on Business Basic, Business Standard, or Office 365 E1 plans.

Access and authentication: Modern Authentication — Exchange (verifies that basic authentication is disabled) and Mailbox Auditing (confirms audit logging is enabled for all mailboxes).

Archiving and compliance: Exchange Online Archiving (In-Place Archive status) and Advanced Message Encryption (requires Office 365 E3 or above).

Exchange Online checks are visible in the Security & Compliance → Exchange Posture tab and also appear in the main feature scan results under the Collaboration category.

Microsoft Purview checks

M365Clarity assesses 25 Microsoft Purview elements across four categories. These are evaluated against your live tenant configuration and reflected in the Executive Summary's Purview compliance snapshot.

Data protection: Data Loss Prevention Policies (standard and endpoint), Sensitivity Labels and Auto-Labelling Policies, Azure Information Protection, Exact Data Match classification, Information Barriers, Advanced Message Encryption, and Adaptive Policy Scopes.

Audit and oversight: Unified Audit Logging, Audit Log Retention Policy, Audit (Premium), Purview Audit for Copilot Interactions, and Compliance Manager Assessments.

Retention: Retention Policies, Retention Labels, and Microsoft 365 Backup for Exchange Online, SharePoint, and OneDrive.

Risk and eDiscovery: Insider Risk Management, Communication Compliance, eDiscovery Standard, eDiscovery Premium, and Legal Hold configuration.

Purview elements requiring Microsoft Purview compliance add-ons (eDiscovery Premium, Insider Risk, Communication Compliance) will show as not licensed on plans below Microsoft 365 E5 or Purview Compliance. The checks that are available on your plan are evaluated automatically — no configuration required.

AI features reference

Score Delta — Why did your score change? Pro

Every time you scan, M365Clarity compares your results to your previous scan and explains what changed. Features that improved or degraded are grouped by category (Identity, Compliance, Threat Protection etc.) with an AI-written plain-English explanation. Find it in the History tab.

Admin Account Hardening Report Pro

Checks every Global Administrator in your tenant across four signals: MFA registration status, Privileged Identity Management (PIM) eligibility, on-premises sync status, and last sign-in date. Each admin is assigned a risk score and ordered highest risk first. Find it in the Admin Accounts tab.

Guest Risk Scoring Pro

Every guest account in your tenant is scored by risk — whether they have never signed in, how long since their last sign-in, and whether they are from an external domain. Results are sorted highest risk first with a High Risk filter. Find it in the Guests tab.

Licence Activation Gap Pro

Identifies users who have been assigned Microsoft 365 licences but have never activated a single Office app on any platform. Built from the Microsoft 365 activation report — the clearest signal of wasted licence spend. Find it in the Licence Recommendations tab.

Pre-Renewal Briefing Pro

When your renewal date is within 90 days, M365Clarity generates a full pre-renewal briefing from your scan data: licences and features to drop (with estimated savings), gaps worth adding, cost optimisation actions, and an executive summary you can share with your CFO or board. Find it in the Licence Recommendations tab.

Once the briefing is generated, you can also generate a Partner Briefing Draft — a plain-text email grounded in your active licences, inactive user count, and the drop/add recommendations from the briefing. The draft includes an appendix listing inactive users by name and last sign-in date so your partner knows exactly which accounts to review. Hit "Generate draft", personalise the partner name and sign-off, then use "Copy to clipboard" or "Open in Mail" to send it from your own email address.

Licensing intent queue: If you've saved licensing intents from the AI chat (via the 💼 chip), they appear in a "Licensing changes queued" panel at the top of the Licence Recommendations tab. Each intent shows the date it was captured and an in-window / outside-window indicator. Intents outside the 3-month window are not included in the next brief — you can re-confirm them via the chat if still relevant. Use the Remove button to discard any that are no longer needed.

Mark as sent: Once you've sent the brief to your partner, tap "Mark brief as sent" in the draft section. This closes the current renewal cycle — all queued intents are archived, the intent queue clears, and any new intents you capture will belong to the next renewal cycle. MSP users can see a history of past brief cycles (date dispatched, intents included) under Tenant Settings for each client.

Security Incident Readiness Score Pro

A five-pillar security readiness model (Detect, Protect, Recover, Identity, Compliance) that scores your tenant across 25 controls drawn from your existing scan results. Each pillar gets an individual score and grade. An AI narrative explains what the overall score means in plain English for an IT Director or CISO. Find it under Security & Compliance → Incident Readiness.

Backup & Recovery Readiness Pro

Assesses how recoverable your data is if ransomware or accidental deletion strikes. Shows the status of Microsoft 365 Backup for Exchange, SharePoint, and OneDrive individually, along with retention policies, audit trail coverage, and ransomware prevention controls. Includes an AI-generated ransomware scenario — what would actually happen to your data if hit today. Find it under Security & Compliance → Backup & Recovery.

Conditional Access Coverage Map Pro

Analyses every CA policy in your tenant to surface coverage gaps — scenarios where users, apps, or platforms have no active policy protecting them. Critical gaps (no enforced MFA-for-all, legacy auth not blocked) are flagged with severity levels. All policies are shown with their attribute chips (All users, All apps, Requires MFA etc.) and an enforced/report-only filter. Find it under Security & Compliance → CA Coverage Map.

Entra ID Application Audit Pro

Lists every third-party enterprise application and service principal with access to your tenant, scored by permission risk. High-risk permissions (Mail.ReadWrite, Files.ReadWrite.All, Directory.ReadWrite.All) are highlighted in red. Includes a search field and risk filter. Requires Application.Read.All consent — if this was not granted when you connected, reconnect your tenant to enable it. Find it under Security & Compliance → App Audit.

Defender AI Posture Pro

Found under Security & Compliance → Defender XDR, the Defender AI Posture card appears at the bottom of the Defender XDR tab. It synthesises 15 Defender feature results — including Secure Score, XDR active incidents, Safe Attachments, Safe Links, Advanced Anti-Phishing, Attack Simulation Training, Defender for Endpoint, Vulnerability Management, Cloud App Security, and Adaptive Protection — into a single risk level and plain-English narrative.

The assessment returns a risk level (low / medium / high / critical), a one-sentence headline, a board-level narrative, a breakdown of the top risks with severity labels, what is configured well, and prioritised recommended actions with effort ratings. Results auto-load from cache on tab open and are regenerated automatically after each rescan. Requires a Pro plan.

Entra ID Governance Posture Pro

Found under Identity & Access → Entra Governance, the AI Entra Governance Posture card synthesises 13 identity governance features: Privileged Identity Management (PIM), Access Reviews, Entitlement Management, Guest Access Review, Sign-in Risk Policy, Identity Protection, Lifecycle Workflows, Emergency Access Accounts, Conditional Access, CA enforcement vs report-only gap, Authentication Strengths, Enterprise App Permissions, and App Registrations Audit.

The output follows the same structure as Defender Posture — risk level, headline, narrative, top risks, positives, and recommendations. This is particularly valuable for tenants with Entra ID P1/P2 licences where standing privileged access and ungoverned guest accounts are common risks. Auto-loads from cache, regenerates after rescan.

Teams Governance Report Pro

Lists every Microsoft Teams in your tenant with owner count, visibility (public/private), age, and risk flags — no owner, public team, potentially abandoned. Results are sorted highest risk first. The report makes live Graph API calls when you open it, so it reflects the current state of your tenant rather than the last scan. Requires the Group.Read.All permission which is included in the standard M365Clarity consent. Find it under Security & Compliance → Teams Governance.

Scheduled automatic rescanning Pro

Pro and MSP users have a weekly scheduled scan automatically enabled on connection. The scan runs every Monday at 6am UTC using your stored refresh token — no manual action needed and no browser session required. If the scan detects configuration changes since the previous scan, you receive an email notification. You can change the frequency, preferred time, or disable the schedule entirely in Settings → Scan schedule.

PDF report — AI summaries included Pro

The PDF report (available via the PDF button at the top of the dashboard) now includes AI-generated summary sections alongside the full feature table: Priority Issues (all red features), Security Incident Readiness score and narrative, Backup & Recovery score and ransomware scenario, Conditional Access coverage score and gap list, and Admin Account Hardening flagged count. These sections only appear if you have already opened the relevant tabs in the current scan — the PDF pulls from cached results rather than making new API calls.

Frequently asked questions

Why not just use the free Microsoft admin dashboards?

Microsoft 365 comes with excellent tools — but they are spread across at least 15 separate admin portals, each with its own login, navigation, and data model. To get a complete picture of your tenant's security posture today, you would need to visit:

  • Microsoft 365 Admin Centre — licences, users, service health
  • Microsoft Entra Admin Centre — identity, Conditional Access, MFA, PIM, access reviews
  • Microsoft Defender XDR — Secure Score, threat protection, endpoint security
  • Microsoft Intune Admin Centre — device compliance, configuration profiles, BitLocker
  • Microsoft Purview Compliance Portal — DLP, sensitivity labels, retention, eDiscovery, communication compliance
  • SharePoint Admin Centre — sharing settings, site governance, external access
  • Teams Admin Centre — Teams policies, guest access, federation, app governance
  • Exchange Admin Centre — mail flow, anti-spam, DKIM, quarantine policies
  • Microsoft 365 Apps Admin Centre — Office deployment, update channels
  • Viva Insights / Adoption Score — usage analytics, adoption trends
  • Azure Portal — enterprise app registrations, OAuth permissions, network access
  • Microsoft Copilot Admin Centre — Copilot readiness, usage analytics
  • Microsoft Endpoint Manager — Autopilot, device enrolment
  • Microsoft Secure Score — aggregated security recommendations
  • Microsoft 365 Usage Reports — per-user activity, licence utilisation

Even experienced Microsoft 365 administrators find it difficult to hold the full picture in their head across all of these portals simultaneously. Settings interact with each other in ways the portals don't surface — a Conditional Access policy that looks correct in Entra may have a scope gap that only becomes obvious when cross-referenced with your MFA registration report and your external sharing settings.

What M365Clarity does differently:

  • Single scan, unified view. One read-only connection to your tenant pulls data from all relevant APIs simultaneously. You get a single dashboard covering identity, security, compliance, devices, collaboration, and adoption — no portal switching.
  • Opinionated scoring. Microsoft's portals show you data. M365Clarity tells you whether that data represents a good or bad configuration — with a red/amber/green verdict and a plain-English explanation of why it matters.
  • Cross-feature analysis. Issues like CA scope gaps, licence waste, and guest access sprawl only become visible when multiple data points are combined. Each Microsoft portal shows its own slice — M365Clarity connects them.
  • Framework mapping. Your scan results are automatically mapped to Cyber Essentials, ISO 27001, and NIST CSF controls — something that would take hours to do manually against 15 portals.
  • AI-guided remediation. Every red or amber finding includes a specific, step-by-step setup guide generated from your actual tenant data — not generic documentation.
  • MSP-ready. For IT providers managing multiple tenants, M365Clarity provides a portfolio view across all clients from a single login — something that requires bespoke tooling or significant manual effort across Microsoft's native portals.

Microsoft's portals are free because they are designed for Microsoft's needs — to surface their products. M365Clarity is designed for the administrator who needs to know, quickly, whether their tenant is configured correctly and what to fix first.

Does M365Clarity monitor whether Microsoft 365 services are online?

No. M365Clarity is a configuration and adoption assessment tool, not a service monitoring platform. It scans your tenant once per scan and reports on how your Microsoft 365 environment is configured and how your users are adopting it — it does not continuously monitor uptime or service availability.

A green tile for Exchange Online, SharePoint, Teams, or any other core service means that service is included in your licence — not that it is currently online or performing normally. If Microsoft 365 is experiencing an outage, M365Clarity will still show those tiles as green because your licence has not changed.

For live service health and incident status, use the Microsoft 365 Service Health dashboard in your admin centre, or check status.office365.com.

Why is a feature showing as "Not Verified" (grey)?

Not Verified means M365Clarity attempted to check that feature but could not produce a reliable result. There are three possible reasons:

  • Microsoft does not expose this setting via the API — some settings are only visible in the admin portal and cannot be read programmatically. The tile will explain what to check manually.
  • A permissions error occurred during the scan — certain Graph API endpoints require specific roles beyond Global Administrator (for example, Exchange Administrator or Security Reader). The tile will say which role is needed.

Not Verified tiles are excluded from your Feature Health Score — they do not penalise your result.

Features your licence does not include are hidden from the main tile grid entirely — they appear in a collapsible section below the grid rather than as grey Not Verified tiles.

Why are some features not shown at all?

M365Clarity only shows a feature tile if the Microsoft Graph API can return data that allows a reliable, accurate assessment. Where this is not possible — for example, because the API endpoint exposes permission definitions rather than granted permissions, making false positives unavoidable — the feature is hidden rather than shown as a misleading grey card.

In these cases, the same security concern is typically covered by a different, more reliable check. For example, third-party application permissions are assessed via OAuth permission grants (what has actually been delegated to an app) rather than service principal definitions (which show permissions an app makes available to others, not permissions it has been given).

This is intentional — a smaller set of accurate results is more useful than a larger set containing misleading ones.

Why does my score change between scans even when I haven't changed anything?

Two things can change your score without any admin action on your part:

  • Microsoft changes a default setting — Microsoft occasionally updates tenant defaults, which can move a feature from green to amber.
  • Evaluator improvements — M365Clarity regularly refines how features are assessed. If an evaluator was previously producing false positives (flagging something as red when it was not actually a problem), a fix may move that feature from red to green on the next scan, improving your score.

If your score changes significantly without any known configuration change, check the scan results for any features that have changed status — the "Why this?" explanation on each tile will describe what was found.

Why does the scan say I need Global Administrator when I already am one?

Some Microsoft Graph API endpoints require specific administrative roles that are separate from Global Administrator, even though Global Administrator grants broad access to most services. The most common example is SharePoint and OneDrive settings — these require the SharePoint Administrator role to be assigned in Entra ID, in addition to Global Administrator.

To assign the SharePoint Administrator role: go to Entra admin centre → Roles & admins → SharePoint Administrator, add the account you connected with, then disconnect and reconnect your tenant in M365Clarity.

How accurate are the scan results?

M365Clarity reads directly from the Microsoft Graph API — every result is based on the actual configuration data Microsoft returns for your tenant, not estimates or assumptions. The accuracy of each result depends on:

  • API availability — if Microsoft does not expose a setting via the API, M365Clarity cannot assess it and will show Not Verified rather than guess.
  • Permission scope — if the account used to connect lacks a required role, the API returns a permission error. This shows as Not Verified with an explanation, not as a false red or green.
  • Licence — features that require a specific licence (E3, E5, Purview, etc.) will show Not Verified on plans that do not include them, rather than flagging them as misconfigured.

Where M365Clarity cannot confirm a result with certainty, it will always show Not Verified rather than produce a misleading red or green result.

Billing FAQ

For billing questions not covered below, email support@m365clarity.com. We endeavour to respond within 24 hours on business days.

How do I upgrade from Free to Pro or MSP?
Click Get Pro or Get MSP on the pricing page or from your Account page. You will be taken to a Stripe-hosted checkout page. After payment, your account is upgraded immediately.
Can I cancel anytime?
Yes. Go to Account → Manage Billing to open the Stripe Customer Portal. You can cancel, downgrade, or update your payment method at any time. Cancellation takes effect at the end of your current billing period — you retain access until then.
Can I upgrade from Pro to MSP?
Yes. Go to Account → Manage Billing and select the MSP plan. The price difference is prorated for the remainder of your billing period.
What payment methods are accepted?
All major credit and debit cards via Stripe. No PayPal or bank transfer currently.
Do you offer annual billing?
Not currently — all plans are billed monthly. Annual billing is planned for a future release.
What happens if my payment fails?
Stripe will retry the payment automatically. If payment cannot be collected after several attempts, your account will be moved to the Free plan until payment is updated. Your scan history is retained.
Is there a free trial of paid features?
The Free plan gives permanent access to the core feature scan. Paid features are available immediately on upgrade — no trial period, but you can cancel within the first month if the product is not right for you.

Security & data privacy

What data do you access?

M365Clarity requests the following Microsoft Graph read-only scopes:

We do not access the content of emails, files, Teams messages, or any user-generated content.

How are tokens stored?

Microsoft OAuth access and refresh tokens are encrypted with AES-256-GCM before being written to the database. The encryption key is stored separately from the data store. Tokens are decrypted only at scan time and never logged.

Where is data stored?

All data is stored in Cloudflare D1 (SQLite) in the WEUR region (Amsterdam, Netherlands). No data is replicated outside the EU. Cloudflare's infrastructure is ISO 27001 certified and SOC 2 Type II compliant.

Who has access to my data?

Only you. Data is scoped to your account and tenant. No M365Clarity team member has routine access to scan data. Access to production infrastructure requires multi-factor authentication.

Your data rights (GDPR / UK GDPR)

M365Clarity Limited is registered with the ICO (ZC173030) and complies with UK GDPR. You have the following rights:

M365Clarity does not store IP addresses. Rate limiting is handled in memory at the Cloudflare edge. No IP address is ever written to our database.

To exercise any of these rights or to make a complaint, contact: support@m365clarity.com. We endeavour to respond within 24 hours on business days.

Security team information pack

If your organisation's security or procurement team needs to assess M365Clarity before approving its use, this section covers the questions they are most likely to ask. You can also download a pre-formatted copy to share directly with your security team.

What does M365Clarity access in our Microsoft 365 tenant?

M365Clarity requests read-only access to the following Microsoft Graph API scopes. It cannot read, modify, or delete any data in your tenant — it can only retrieve configuration and usage metadata.

  • User.Read — the authenticated admin account's name and email address
  • Organization.Read.All — tenant name and licence subscription details
  • Reports.Read.All — aggregated usage and activity reports (anonymised by Microsoft by default)
  • SecurityEvents.Read.All — Microsoft Secure Score and security alert counts
  • Policy.Read.All — Conditional Access policies and other tenant policy configurations
  • Directory.Read.All — directory settings, group configurations, and user account metadata
  • ServiceMessage.Read.All — Microsoft 365 service announcements and Message Centre posts
  • Sites.Read.All — SharePoint site metadata (storage, activity dates) — no file content

M365Clarity does not access the content of emails, files, Teams messages, calendar events, or any user-generated content. It does not access OneDrive files, Exchange mailbox content, or Teams channel messages.

Where is our data stored and processed?

All data is stored in Cloudflare D1 (SQLite) located in the WEUR region (Amsterdam, Netherlands). No data is replicated outside the European Union. Processing runs on Cloudflare Workers at the same edge location.

M365Clarity Limited is a UK-registered company. Data storage within the EU means processing is covered by the EU GDPR and, for UK customers, the UK GDPR adequacy framework.

How are credentials and tokens protected?

Microsoft OAuth access and refresh tokens are encrypted with AES-256-GCM before being written to the database. The encryption key is stored separately from the data store using Cloudflare Workers Secrets, which are never logged or exposed in application code. Tokens are decrypted only at scan time in memory and are never written to logs, caches, or external services.

Token lifetimes follow Microsoft's standard — access tokens expire after approximately one hour, and refresh tokens are silently rotated on each use. If a token cannot be refreshed, the tenant is flagged and the user is prompted to reconnect.

What authentication mechanisms protect the M365Clarity application?

M365Clarity uses Microsoft OAuth 2.0 (delegated permissions) for tenant connections. User sessions are managed via server-side session tokens stored in Cloudflare KV with a 7-day TTL. Session tokens are passed as Bearer tokens in the Authorization header — never in cookies or query strings.

All API routes validate the session token server-side on every request. There is no client-side authentication state. Rate limiting is applied to all user-callable API endpoints at the Cloudflare edge.

The production infrastructure requires multi-factor authentication for access.

Who can access our scan data?

Scan data is scoped to the authenticated user account that connected the tenant. No other M365Clarity user can access your data. M365Clarity team members do not have routine access to customer scan data — production database access requires explicit authorisation and is logged.

Optional viewer access can be granted by the account owner to named email addresses. Viewers have read-only access to scan results and cannot trigger scans, modify settings, or access billing information.

Does M365Clarity use sub-processors or third parties?
  • Cloudflare — infrastructure, edge compute, database (D1), KV storage, and R2 object storage. Data centre: Amsterdam (WEUR). Cloudflare sub-processors →
  • Anthropic — AI language model processing for Priority Actions, Executive Summary, and other AI features. Scan data excerpts (configuration metadata only, no user-generated content) are sent to Anthropic's API for processing. Anthropic does not train on API data by default. Anthropic privacy policy →
  • Microsoft — Microsoft Graph API for data retrieval; Microsoft OAuth 2.0 for authentication.
  • Stripe — payment processing. M365Clarity does not store payment card data. All payment handling is managed by Stripe. Stripe privacy policy →
  • Postmark — transactional email delivery (scan notifications, weekly digests).

No scan data is shared with any sub-processor beyond what is necessary to deliver the service.

What is your data retention policy?
  • Scan results — retained for the lifetime of the account. When an account is deleted, all scan data is permanently deleted within 30 days by an automated process.
  • Error logs — retained for 90 days, then automatically purged.
  • AI usage logs — retained for 90 days.
  • Audit logs — retained for 90 days.
  • OAuth tokens — deleted immediately when a tenant is disconnected or when the account is deleted.
  • Account deletion — email and name are anonymised immediately on deletion. All associated data is purged within 30 days.

All retention periods are enforced by an automated scheduled process running daily. There is no manual step required.

Is M365Clarity GDPR compliant?

Yes. M365Clarity Limited is registered with the UK Information Commissioner's Office (ICO registration number ZC173030) and complies with UK GDPR. Data is stored in the EU (Amsterdam) and processed under standard contractual clauses where applicable.

Users can export all their data as JSON, request deletion, or disconnect their tenant at any time from within the application. See the Your data rights section for full details.

M365Clarity does not store IP addresses. Rate limiting is handled at the Cloudflare edge without any IP logging in the application database.

Has M365Clarity undergone penetration testing or third-party security assessment?

M365Clarity has not yet undergone a formal third-party penetration test. The application is built on Cloudflare's infrastructure, which is ISO 27001 certified and SOC 2 Type II compliant. Cloudflare's security posture covers the underlying infrastructure layer.

The application layer follows OWASP security principles: all database queries use parameterised bindings (no string concatenation), all API routes validate session tokens server-side, user data is scoped per account with no cross-tenant access, and all external API calls are made over HTTPS with enforced timeouts.

If your organisation requires a completed penetration test or security questionnaire, please contact support@m365clarity.com to discuss.

What is the incident response process if a data breach occurs?

In the event of a confirmed data breach affecting personal data:

  • Affected customers will be notified within 72 hours of M365Clarity becoming aware of the breach, in accordance with UK GDPR Article 33.
  • Notification will be sent to the email address registered to the affected account.
  • The notification will describe the nature of the breach, the data affected, the likely consequences, and the measures taken or proposed to address it.
  • M365Clarity will notify the ICO as required.

To report a suspected security issue, email support@m365clarity.com with the subject line "Security Issue".

What Microsoft permissions are required and why?

M365Clarity requires the Global Administrator role to grant tenant-wide consent for the Microsoft Graph permissions listed above. This is a Microsoft requirement for delegated permissions that apply across the entire organisation — it does not grant M365Clarity any administrative access to your tenant.

Once consent has been granted, the connected account does not need to retain the Global Administrator role. The consent persists and the application continues to operate with read-only access. However, the connected account does need to remain active — if the account is disabled or deleted, the OAuth token will expire and the tenant will need to be reconnected.

The SharePoint Administrator role is additionally required to access SharePoint tenant-wide settings and site usage data. This role can be assigned to the connected account separately if SharePoint data is needed.

Can M365Clarity make any changes to our Microsoft 365 tenant?

No. All Microsoft Graph API permissions granted to M365Clarity are read-only. The application cannot create, modify, or delete any resource in your Microsoft 365 tenant. It cannot send emails, change policies, create users, modify group memberships, or alter any configuration.

This is enforced at the permission scope level by Microsoft — read-only scopes do not grant write access regardless of what the application requests.

What infrastructure and uptime commitments does M365Clarity provide?

M365Clarity runs on Cloudflare Workers and D1, which provide global availability across Cloudflare's network. Cloudflare's infrastructure SLA is 99.9% uptime. M365Clarity does not currently offer a formal SLA to customers beyond the underlying infrastructure guarantees.

Scheduled scans and AI features depend on Microsoft Graph API and Anthropic API availability respectively. Temporary unavailability of these services is handled gracefully — scans will fail cleanly and retry rather than producing incorrect results.

Troubleshooting

Tiles show "Unknown" or "Requires Admin Access"
This means M365Clarity could not retrieve data for that feature from Microsoft Graph. The most common cause is that your Microsoft OAuth token has expired. Go to Tenant Settings, disconnect the tenant, then reconnect using a Global Administrator account — this generates a fresh token. Run a new scan after reconnecting and the tiles should show real results. If you are already a Global Admin and still see these tiles, check that you ticked "Consent on behalf of your organisation" on the Microsoft permissions screen when connecting. If the checkbox was not ticked, disconnect and reconnect.
Some tiles show "Unknown" but I am a Global Admin and have just reconnected
Some features require specific Microsoft 365 plans or add-ons — for example, Defender for Business requires Business Premium or E3, Lifecycle Workflows requires E5 or Entra ID Governance, and Intune features require a device management licence. If your plan does not include those features, M365Clarity will show them as Unknown rather than remove them entirely. You can check which features your plan includes in the Feature Registry. If a feature should be available on your plan and is still showing Unknown, contact support@m365clarity.com with the feature name and your plan.
Scan returns empty or "Not Verified" for most features
This usually means you signed in without ticking "Consent on behalf of your organisation" on the Microsoft permissions screen. Disconnect the tenant from Account → Connected Tenants, reconnect, and make sure to tick the consent checkbox when prompted by Microsoft. You must be a Global Administrator for the tenant checkbox to appear.
Scan shows 0 features or gets stuck
This usually means your Microsoft tenant connection needs refreshing. Go to Tenant Settings, disconnect the tenant, then reconnect and run a new scan. If the issue persists, check that the M365Clarity app still has the required permissions in your Microsoft account (visit myapps.microsoft.com).
Priority Actions / Compliance / Executive Summary show an error
These features require a completed scan. Run a scan first, then click the tab. If a scan has completed and the error persists, try signing out and back in — this refreshes your session token.
Manage Billing says "no billing account found"
If your account was provisioned manually (e.g. for testing), it may not have a Stripe customer record. The system will create one automatically the first time you click Manage Billing. If the error persists, contact support@m365clarity.com.
My Microsoft token appears to have expired mid-scan
M365Clarity automatically refreshes expired tokens before each scan. If you see "Requires Admin Access" on tiles or features are not loading correctly, go to Tenant Settings, disconnect the tenant, and reconnect — this generates a fresh token set. Refresh tokens expire after 90 days of inactivity or if you revoke M365Clarity’s permissions in your Microsoft account.