EntraGUARD features
Below is every screen of EntraGUARD, in the order of a real engagement: steer, frame the scope, audit, deliver, operate. Click any screenshot to enlarge it.
Steer
The dashboard opens on the figure that matters: the weighted compliance score, then the breakdown that says where the effort belongs. Categories are sorted from weakest to strongest, and the trend curve shows the effect of remediation over time — as well as silent drift.
Frame the scope
The catalog is grouped by category, with a level on every control. A baseline freezes the agreed scope: which controls are in, which are out, and why. Ten framework templates — ANSSI, ISO, NIST, CIS, NIS2, DORA — pre-select the right subset without typing anything.
Audit
The run is parallel and takes seconds. Each control returns a verdict and, above all, a named finding: not « non-compliant », but which objects are at fault. The history keeps every run with its scope, and comparing two audits separates what was fixed from what regressed.
Attack simulator
Beyond compliance, EntraGUARD replays 35 known Entra ID & Microsoft 365 attacks in strictly read-only mode — no action is ever performed on the tenant. Each scenario is a kill-chain: step by step, the tool reports whether the path is viable, where it is broken, and returns a global exposure score out of 100 with the count of viable attack paths. Scenarios are grouped by kill-chain phase — initial access, persistence & escalation, configuration & exposure — and every attack links to its MITRE ATT&CK technique. Each run is kept in a dedicated history with its full detail, exportable as PDF.
Eight Microsoft 365 connectors
Entra ID is the control plane, but the risk spreads across the whole estate. One connector per source — Entra ID, Exchange Online, SharePoint, OneDrive, Teams, Defender, Purview, Intune — each opening read-only access through a dedicated application. A connector whose access has not been proven stays locked: an audit resting on an unreachable source would produce a falsely reassuring score.
Deliver
Four report types for four audiences — executive, detailed technical, prioritized remediation plan, and compliance by framework. Five file formats. The report carries your logo and your contact details, and the audited client's logo on the cover. See what each report contains, with extracts →
Operate
One record per audited client, with its own connector, its own history and its own report cover logo — two clients' data never mix. The application shows the licence holder's name, carried by the licence itself, so each report goes out under that name; the audited client's own logo sits on their report cover. The licence is verified offline, with no activation server to reach.