Graften / Microsoft 365 audit

Microsoft 365 security audit for MSPs

Microsoft 365 is where most small-business identity risk lives. Graften reads each client's tenant with read-only access the client's own admin approves, and turns what it finds into scores, risks and reports.

How the connection works

Graften uses delegated Microsoft Graph permissions through the client's own admin consent. It never stores a client's Microsoft 365 admin password. The client's Global Admin, or someone with sufficient delegated permissions, approves the connection once from Microsoft's consent screen, and you start audits from the client's record.

What gets inventoried

Findings feed the client's health score and the Essential Eight, SMB1001, ISO 27001 and other framework mappings, so one audit supports several reports.

If something cannot be read, it says so. A control Graften could not measure shows as not assessed with the reason. It is never reported as a pass.

Common setup issues, handled honestly

From audit to a service

Scheduled audits keep the score current, branded client portals and reports show it monthly, and the remediation roadmap turns gaps into billable work. See Essential Eight for MSPs for how the maturity picture is built.

Frequently asked questions

Does Graften need a client's admin password?

No. Access is through the client's own admin consent using delegated Microsoft Graph permissions.

Can I audit AWS and Microsoft 365 for the same client?

Yes. Multiple connections can sit under one client, and the audit results combine into a single client score.

Related guides

See it on one of your own clients

Connect a client, run an audit and see what is measured and what is not. 14-day full-access trial.

Start free trial

No credit card required · See pricing