Made in Australia · ASD Essential Eight aligned

Know your Essential Eight maturity in minutes — not a $5,000 audit.

Cloud Audit Check reads your Microsoft 365 and Azure configuration, scores it against the Essential Eight, and hands you the evidence and fixes — the assessment a consultant charges thousands for, running automatically.

Read-only consentNo agents to installAustralian data residency

Contoso Pty Ltd

Microsoft 365 + Azure · today

ML1
65
Microsoft 365
68
Azure
54
Multi-factor authenticationGAP
Restrict admin privilegesML2
Patch operating systemsML1
Critical3 members without MFA · jsmith, payroll, admin2
Mapped toASD Essential EightMicrosoft Secure ScoreISO 27001SOC 2Defender for Cloud

Why teams switch to it

The consultant’s report — automated, and always current

A real Essential Eight maturity level

An ML0–ML2 verdict per strategy, scoped honestly to what a cloud audit can prove. Exactly what auditors and cyber-insurers ask for.

Microsoft 365 and Azure, together

Identity, config, data, licensing — plus Azure Defender, network, storage and RBAC — in one score. Reuses your existing app registration.

Evidence, not vague findings

Every finding names the actual accounts, policies, NSG rules and storage accounts — which user, which resource, which subscription.

Fix-it, not just flag-it

Plain-English steps plus ready-to-run PowerShell or config, so remediation starts the moment the scan finishes.

Continuous, not one-off

Schedule monthly re-scans and get an email the moment your posture drifts — a dropped score, a disabled control.

Board-ready in one click

Export a branded PDF or Word report — executive summary, maturity, roadmap and evidence — ready for the board or the insurer.

What we assess

Hundreds of checks across two clouds

Ten pillars in total — six for Microsoft 365, four for Azure — folded into one posture score and Essential Eight maturity.

Microsoft 365

Identity
MFA coverage, Conditional Access, admin sprawl, legacy auth, per-user MFA gaps.
Tenant configuration
Secure defaults, external sharing, mail security (SPF/DMARC), Teams & guest access.
Data & permissions
Oversharing, app consent, OAuth grants, SharePoint exposure.
Licensing
Security features you pay for but have not switched on.
Integrations
Connected apps, unverified publishers, and the permissions they hold.
Analyst readiness
Audit logging and sign-in visibility for when something goes wrong.

Microsoft Azure

Defender for Cloud
Plan coverage and secure score across your subscriptions.
Network
NSGs exposing RDP/SSH or database ports to the internet.
Storage
Public blob access, HTTPS-only, minimum TLS, disk & SQL encryption.
Identity & RBAC
Subscription owner sprawl, classic admins, Key Vault protection.

Azure is optional and reuses the same app registration — just assign it read-only Reader + Security Reader on your subscription.

How it works

From consent to a maturity level in three steps

1

Connect

Grant read-only admin consent through Microsoft — and, for Azure, assign Reader on your subscription. No agents, no stored passwords, revoke anytime.

2

Scan

We read your Microsoft 365 and Azure configuration, fold in Microsoft Secure Score, and evaluate hundreds of controls in under a minute.

3

Act

Get your score, Essential Eight maturity, evidence-linked findings and a prioritised roadmap — then re-run to prove each fix landed.

Read-only by design

What access do we need?

Only read-only permissions — approved in Microsoft’s own admin-consent screen, and revocable anytime. We change nothing in your tenant, and we never read your emails or files.

Read-only — we assess configuration, never modify itNo mailbox or file content — everSecrets encrypted at rest, hosted in Sydney
See the full permission list →
ReadRead-only Microsoft Graph

Identity, Conditional Access, roles, apps, domains, Secure Score, per-user MFA, and Intune device compliance.

ReadMailbox settings (rules only)

Detects inbox rules that forward mail externally — reads the rule, never a single message.

ReadRead-only Azure (ARM)

Reader + Security Reader on your subscription for Defender, network, storage, and RBAC checks.

Built for MSPs

Every client’s posture — under your brand

Manage up to three client tenants from one console, ranked by risk, and deliver reports your clients think you built yourself.

Multi-tenant console
Every client tenant side by side — scores, critical findings, and drift, in one portfolio view.
White-label reporting
White-label means the report carries your brand, not ours — your logo and name on a polished PDF you hand straight to the client.
Drift alerts across clients
Get an email the moment any client’s score drops or a control is switched off, so you catch problems before they do.
More for MSPs →

Portfolio · 3 clients

Beacon Health0 critical74
Waratah Constructions1 critical58
Pilbara Mining Co3 critical47

Ranked by risk — see the client who needs you first.

Pricing

Start free. Upgrade when it earns its place.

One free audit shows your score. Pro and MSP unlock the full assessment, reports, and continuous monitoring.

Free

See where you stand

$0 forever

  • 1 Microsoft 365 tenant
  • Overall security score
  • Your top 5 risks
  • Essential Eight snapshot
Start free
Most popular

Pro

For a single business

$149 /month

  • 1 tenant
  • Every finding with evidence
  • Essential Eight maturity level
  • Microsoft 365 + Azure checks
  • Board-ready PDF & Word reports
  • History, trends & scheduled scans
Start Pro

MSP

For MSPs & agencies

$399 /month

  • Up to 3 client tenants
  • Multi-tenant portfolio console
  • White-label reporting
  • Drift alerts across clients
  • Priority support & onboarding
Start MSP

Prices in AUD. Annual billing saves two months. Compare plans →

Common questions

What permissions do you need?

Only read-only ones, approved in Microsoft’s admin-consent screen: read-only Microsoft Graph (identity, Conditional Access, roles, apps, Secure Score, per-user MFA, Intune compliance), MailboxSettings.Read (inbox forwarding rules only — never message content), and, for Azure, read-only Reader + Security Reader. We change nothing and can be disconnected anytime.

Do you read our emails or files?

Never. We assess configuration and metadata only. The closest we get to mail is reading inbox-rule definitions to catch external forwarding — we never open a message, file, or chat.

What does “white-label” mean?

On the MSP plan, reports carry your brand instead of ours — your logo and name on a polished PDF you send straight to your client, so the work looks like it came from you.

How long does an audit take?

Under a minute of scan time, across Microsoft 365, Azure, and Microsoft Secure Score.

What does the free tier include?

One tenant, your overall score, your top 5 risks, and an Essential Eight snapshot. Pro unlocks every finding, evidence, reports, maturity levels, Azure, and history.

Is my data kept in Australia?

Yes — hosted in Sydney. We store assessment results, never your content. See the Security page for the full detail.

Know your Essential Eight maturity today.

Run your first Microsoft 365 & Azure audit free — read-only, no agents, results in minutes.