283 automated controls
Two independent industry security baselines ship — 159 controls in the newest version of one, 124 in the other — and your tenant picks the version it's assessed against, so an upgrade is a decision rather than a surprise.
Dashboard
The dashboard tiles the numbers that decide your day: failing controls, connection certificates about to expire, attestations coming up for renewal — over a live feed of recent changes.
Every number deep-links to the list behind it, and every list exports to PDF or CSV when someone asks for it in writing.
Looking after more than one tenant? The estate view rolls everything failing anywhere into a single list, each row deep-linking into the tenant it came from.
Assessments
Each baseline opens on an overview: status, a headline secure score with its trend, how many controls were tested, and how many are covered by an active attestation or accepted-risk acknowledgment.
Two independent industry security baselines ship — 159 controls in the newest version of one, 124 in the other — and your tenant picks the version it's assessed against, so an upgrade is a decision rather than a surprise.
Every control keeps its published identifier and its product grouping — Entra ID, Exchange Online, SharePoint Online, Microsoft Teams, Defender, Purview, Intune, Power Platform and Fabric — so a finding maps straight onto the admin center where you'd fix it.
Re-run a chosen subset of controls without touching the rest, so verifying one fix takes seconds. History records whether a run was full or targeted.
Controls that can't be machine-decided resolve to a manual outcome. Record a dated attestation with a rationale and optional expiry; a sweep reminds you before it lapses.
Acknowledge a gap you're carrying deliberately. It stays visible and marked rather than vanishing, applies to later assessments too, and the acknowledgment itself is audited.
Remediation & actions
Low-risk remediations run straight through — queued, running, done — and only one live fix can exist per control, so parallel runs can't trip over each other.
Anything disruptive takes the gated path instead: preview, pending approval, approved, then run. It needs a configurable quorum of admin approvals, expires if nobody decides in time, and can carry a break-glass exclusion list.
Actions are parameterised bulk operations on the same rails. The preview materialises one row per candidate; approvers review the list and can exclude individual rows before promoting it. Shipped today: prune or disable inactive Entra ID users, tighten public Microsoft 365 group visibility, and block sign-in on Exchange Online shared mailboxes.
Everything waiting on a decision — actions and remediations alike — collects on one Approvals page, and eligible approvers get an email.
Preview built — 34 candidates matched. 2 of 3 approvals recorded.
Reports
Separate from assessments — these are the questions you get asked on a Tuesday.
Every user against broadly scoped Conditional Access or security defaults, joined with what they've actually registered.
Who signed in, when, and who hasn't — the input to most inactive-account decisions.
Which devices are running an OS version that's still supported, and which have fallen off.
Mailbox growth across the tenant, before someone hits a quota on a Friday afternoon.
Certificates approaching expiry, so the renewal happens before the outage.
Email a finished report to recipients with no Admin Companion account. The link expires on both a time window and a download count, so it can't circulate forever.
Automation & records
Assessments, reports and actions each carry their own cadence — off, daily, weekly by day-of-week, or monthly — at a chosen time, with a pause switch. New schedules start off, so nothing runs on a timer unless you asked for it.
A filterable log of membership changes, role grants, sign-on configuration edits and every remediation — with before/after values, the actor, and a correlation id. Exportable, with retention you configure.
Separately from the change audit, your own sign-ins, sign-outs and security events are recorded with their own retention and export, visible to you as the account owner.
Report runs, assessment results, per-control evidence and the audit log all export to PDF or CSV, delivered through time-limited links that tidy up after themselves.
Connections & access
A guided stepper connects your Microsoft 365 tenant app-only, using a certificate that Admin Companion can generate and rotate for you. A test probe then records which permissions were actually granted and which license features were detected.
Every control, report and action is gated on that result — you're only offered what the grant and the license can genuinely support, instead of a wall of checks that will fail for permission reasons.
Sign-in supports TOTP, passkeys and recovery codes, and you can bring your own OIDC or Entra ID identity provider with claim mappings and credential-expiry monitoring.
Conditional Access, admin roles, PIM, devices, groups, compliance.
Transport, mailbox audit, sharing and OWA policies.
Anti-phish, Safe Links, DLP, sensitivity labels.
Meeting, messaging and sharing policy, tenant settings.
DLP policies, environment settings, tenant isolation.
Admin tenant settings behind the baseline controls.