← All release notes

The Microsoft 365 Security Connector is live

Until now the platform could tell you what the outside world can see about your business. It could not tell you anything about the place most of your risk actually lives: the Microsoft 365 tenant your staff sign into every morning.

That changes with this release. Connect your tenant and what Microsoft already knows about your security arrives in the same dashboard as everything else — in plain English, with the changes worth making put in order.

What's new

The Microsoft 365 Security Connector. A Microsoft 365 Global Administrator grants read-only access once, and from then on we read your tenant on a schedule and report what we find. Your Microsoft Secure Score and the settings behind it. Which of your staff have multi-factor authentication registered, and specifically which administrators do not. A 90-day trend, so you can see whether it is actually improving. And how you compare with organisations of a similar size.

Nothing you read is our opinion of your security. The scores, the recommended changes, the effort each one takes and the links to make them are Microsoft's own. What we add is the translation: which of them matter most in your tenant, what each one actually protects you from, and where to click to do it. There is no AI anywhere in this — it is Microsoft's data with a human-written explanation layer, reviewed line by line.

Every finding comes with a way to act on it. Each recommended change carries a deep link straight into the Microsoft admin centre page where you make it. If a change is not something you can do yourself, you can mark it as such, and it stops being asked of you.

Read-only, and you can prove it. We ask for two permissions — enough to read your security configuration and which sign-in methods your staff have registered, and nothing else. No write access of any kind. Microsoft's consent screen will show you three; the extra one is "Sign in and read user profile", which Microsoft adds itself for whoever is signing in. Your administrator can withdraw the whole thing at any time from the Microsoft 365 admin centre, without contacting us.

Send your results to your IT provider. Microsoft 365 results now have a share link, the same way scan reports do. What your vendor sees is the full page, unredacted — if you are asking somebody to fix these things, a partial view only generates a second document and a phone call. Two differences from scan sharing, both deliberate: the link expires after 14 days rather than eight weeks, and revoking a link kills it permanently rather than pausing it. This payload describes your internal configuration, so who can read it and for how long is the whole of the safety.

All-companies views. If your account covers more than one business, Microsoft 365, Websites and Compliance each now have an across-everything view. Three pages that used to dead-end on "choose a single company" now answer the question you were actually asking.

Team, per company. The Team page now answers "who can see this company", rather than making you take the account-wide roster and work it out in your head. The account-level view is still there under Settings.

A dashboard that leads with what you can act on. The dashboard used to open with a score. A score tells you how you are doing and nothing about what to do, so the top of the page is now the changes worth making. We also went through the website reports for readability — consistent headings, sections that are actually separate sections, and the shared version of a report now matches the one you see.

Getting access

The connector is included on every plan, including Free. There is nothing to buy and nothing to enable.

What your plan changes is how often we re-read your tenant: every four hours on Business, daily on Individuals, weekly on Free. Microsoft recalculates Secure Score roughly once a day, so a paying customer is never looking at a figure Microsoft has already superseded.

You will need a Microsoft 365 Global Administrator to grant the initial consent — it takes about a minute. If you are not that person in your business, the connector can be started by the colleague who is; they do not need to own the billing.

Two things it cannot tell you

We would rather you heard these from us than found them yourself.

It says nothing about your backups. Regular backups is one of the eight Essential Eight strategies, and Microsoft does not expose a signal we can read for it. That stays a question you answer yourself, with your own evidence, in an assessment.

Multi-factor authentication coverage needs an Entra ID P1 licence. That is included in Microsoft 365 Business Premium, and not in Business Standard or below. If your plan cannot supply it, the portal tells you so rather than showing you an empty section — but it is worth knowing before you connect. Everything else works on any plan.

It is also weaker on application control than on identity. What it is genuinely strong at is the identity picture: MFA, administrator accounts, and the configuration settings Microsoft itself scores you against.

Why it matters

Most small businesses have their security spread across two places that have never been looked at together. The website is public, testable by anyone, and the thing people worry about. The Microsoft 365 tenant is where the email, the files and the sign-ins actually are — and it is almost always configured once, at setup, by whoever did the setup, and never looked at again.

The second one is where the attacks land. Compromised email accounts and missing multi-factor authentication are not exotic; they are the ordinary way small businesses get hurt. Microsoft has been measuring this for you the whole time, in a console most owners have never opened.

This release puts both halves on one page, so "how are we doing?" has a single answer instead of two partial ones — and so that when an insurer, a client or a tender asks, you are not assembling it from scratch.


A note on what this is. The connector reports your Microsoft 365 configuration as Microsoft reports it to us, on a schedule. It is not continuous monitoring and we do not describe it as such. It does not change anything in your tenant, and it cannot — we hold no write access. If you would rather someone worked through the findings with you and made the changes, that is a consulting engagement, and it is a different thing from this.

Start monitoring your websites, free.