AuthMargin
Free Microsoft 365 security assessment

Find the security gaps hiding in Microsoft 365.

Run a read-only assessment of your tenant and get prioritized findings, affected users and apps, supporting evidence, and recommended fixes.

No credit card. Microsoft administrator consent is required for the read-only Audit connection.

Read-only Audit ModeNo tenant changes during assessmentMicrosoft authentication and consentExplainable findings with evidence
Read onlyassessment permission set
No changesto tenant configuration
Tenant isolatedauthorization boundary
Customer controlledMicrosoft admin consent
Useful before you buy

Know what to fix first.

The free assessment turns Microsoft 365 evidence into a short, defensible action list. You see value in your own environment before choosing a paid plan.

01

Prioritized risks

Start with the exposures that carry the most privilege, reach, and blast radius—not an unranked configuration export.

02

Affected users and apps

See the accounts, permissions, policies, and applications connected to each finding.

03

Evidence and next steps

Understand why the issue matters, what AuthMargin observed, and the recommended corrective action.

A safer first step

Connecting a tenant should not require blind trust.

AuthMargin separates read-only assessment access from Protect permissions. The free journey requests Audit Mode only, keeps Microsoft as the system of record, and never performs a tenant change.

What happens when you start
  1. Sign in with Microsoft.
  2. An administrator reviews the read-only Audit permissions.
  3. AuthMargin collects supported Microsoft Graph evidence.
  4. Your dashboard shows prioritized findings and explicit evidence gaps.
Protect Mode is a separate, optional connection and is not requested for the free assessment.
More than a one-time scan

Turn the first finding into an operating rhythm.

The assessment is the entry point. Paid plans add the controls that help internal IT teams and MSPs investigate, remediate, verify, and monitor change safely.

Prioritized evidence

Every risk stays connected to its affected scope, evidence source, freshness, and Microsoft license context.

Safe remediation

Protect Mode is separate and opt-in. Supported changes require exact targets, safeguards, approval, and verification.

Continuous drift

Rapid Watch checks high-value identity, OAuth, policy, application, and device changes between full assessments.

MSP operations

Portfolio views, tenant isolation, technician workflows, and staged baselines support authorized multi-tenant work.

Compare plans after the assessment →
Start with your own tenant

Find the Microsoft 365 risks worth your attention.

Run the read-only assessment now, or inspect the synthetic sample first. No credit card is required for the initial assessment.