m365expertise MICROSOFT SECURITY EXPERTISE

EntraGUARD features

Below is every screen of EntraGUARD, in the order of a real engagement: steer, frame the scope, audit, deliver, operate. Click any screenshot to enlarge it.

Steer

The dashboard opens on the figure that matters: the weighted compliance score, then the breakdown that says where the effort belongs. Categories are sorted from weakest to strongest, and the trend curve shows the effect of remediation over time — as well as silent drift.

The dashboard: overall compliance and per-category breakdown
The compliance trend over time

Frame the scope

The catalog is grouped by category, with a level on every control. A baseline freezes the agreed scope: which controls are in, which are out, and why. Ten framework templates — ANSSI, ISO, NIST, CIS, NIS2, DORA — pre-select the right subset without typing anything.

The catalog, grouped by category
Framework templates, with the count of runnable controls
The baseline editor: included, excluded, re-levelled

Audit

The run is parallel and takes seconds. Each control returns a verdict and, above all, a named finding: not « non-compliant », but which objects are at fault. The history keeps every run with its scope, and comparing two audits separates what was fixed from what regressed.

An audit running, with the live stream of evaluated controls
The result of a control, with the objects observed and the remediation
Comparing two audits: what was fixed, what regressed

Attack simulator

Beyond compliance, EntraGUARD replays 35 known Entra ID & Microsoft 365 attacks in strictly read-only mode — no action is ever performed on the tenant. Each scenario is a kill-chain: step by step, the tool reports whether the path is viable, where it is broken, and returns a global exposure score out of 100 with the count of viable attack paths. Scenarios are grouped by kill-chain phase — initial access, persistence & escalation, configuration & exposure — and every attack links to its MITRE ATT&CK technique. Each run is kept in a dedicated history with its full detail, exportable as PDF.

The 35 attacks to replay, grouped by kill-chain phase
A simulation running: scenarios scroll as they are replayed
End of simulation: global exposure score and viable attack paths
A scenario detail: kill-chain, verdict, break point and remediation
The simulation history, with score and viable paths per run

Eight Microsoft 365 connectors

Entra ID is the control plane, but the risk spreads across the whole estate. One connector per source — Entra ID, Exchange Online, SharePoint, OneDrive, Teams, Defender, Purview, Intune — each opening read-only access through a dedicated application. A connector whose access has not been proven stays locked: an audit resting on an unreachable source would produce a falsely reassuring score.

The connectors: each source states its state
The read-only permissions granted to the audit application

Deliver

Four report types for four audiences — executive, detailed technical, prioritized remediation plan, and compliance by framework. Five file formats. The report carries your logo and your contact details, and the audited client's logo on the cover. See what each report contains, with extracts →

Choosing the report type and the formats

Operate

One record per audited client, with its own connector, its own history and its own report cover logo — two clients' data never mix. The application shows the licence holder's name, carried by the licence itself, so each report goes out under that name; the audited client's own logo sits on their report cover. The licence is verified offline, with no activation server to reach.

The portfolio of audited clients
What exactly does it check?
The catalog, the frameworks it draws on, and how deep it goes.
See the controls →