Microsoft 365 security audit for MSPs
Microsoft 365 is where most small-business identity risk lives. Graften reads each client's tenant with read-only access the client's own admin approves, and turns what it finds into scores, risks and reports.
How the connection works
Graften uses delegated Microsoft Graph permissions through the client's own admin consent. It never stores a client's Microsoft 365 admin password. The client's Global Admin, or someone with sufficient delegated permissions, approves the connection once from Microsoft's consent screen, and you start audits from the client's record.
What gets inventoried
- Users and licensing
- Mailboxes (through Exchange Online)
- Conditional Access policies
- Admin roles
- Teams settings
Findings feed the client's health score and the Essential Eight, SMB1001, ISO 27001 and other framework mappings, so one audit supports several reports.
If something cannot be read, it says so. A control Graften could not measure shows as not assessed with the reason. It is never reported as a pass.
Common setup issues, handled honestly
- Conditional Access blocking the audit's own sign-in. Strict policies such as blocking legacy authentication or unfamiliar locations can block the audit connection. Add an explicit exclusion for Graften's audit service principal.
- Legacy public folders that were never migrated can cause partial Exchange Online collection. That is a finding to raise with the client, not a Graften fault.
- Removed legacy roles. If a tenant no longer has the deprecated ApplicationImpersonation role, the collector falls back to a reduced permission set automatically.
From audit to a service
Scheduled audits keep the score current, branded client portals and reports show it monthly, and the remediation roadmap turns gaps into billable work. See Essential Eight for MSPs for how the maturity picture is built.
Frequently asked questions
Does Graften need a client's admin password?
No. Access is through the client's own admin consent using delegated Microsoft Graph permissions.
Can I audit AWS and Microsoft 365 for the same client?
Yes. Multiple connections can sit under one client, and the audit results combine into a single client score.