Microsoft 365 security questions, answered before you connect.
Review permissions, data handling, tenant separation, pricing, MSP capabilities, and compliance evidence before granting access.
What is AuthMargin?
AuthMargin is a Microsoft 365 security posture and operations platform focused on explainable risk, evidence, remediation guidance, verification and repeatable security workflows.
Does the assessment change my tenant?
No. Audit Mode is read-only. AuthMargin keeps evidence collection separate from optional change workflows so a security assessment does not silently modify Microsoft 365 configuration.
What permissions does Audit Mode need?
Permissions are requested only for enabled assessment capabilities. AuthMargin documents the Microsoft permission, evidence category and relevant license dependency for supported checks.
Does AuthMargin store Microsoft passwords?
No. Customers authenticate with Microsoft. AuthMargin does not ask customers to provide or store their Microsoft 365 passwords.
What if a check requires a Microsoft license we do not have?
AuthMargin is designed to mark license-dependent checks clearly instead of presenting missing Microsoft capabilities as security failures.
Is this the same as Microsoft Secure Score?
No. Microsoft Secure Score can be one useful signal. AuthMargin is designed to add prioritized evidence, affected scope, investigation context and remediation guidance around the decisions administrators need to make.
Can I use AuthMargin without an MSP?
Yes. AuthMargin is designed for internal IT and security teams as well as managed service providers.
Is there an MSP plan?
Yes. The MSP plan is $299/month and includes up to 10 connected client tenants, multi-tenant portfolio views, recurring assessments, evidence history, and client-ready reporting. White-label report customization is not currently included.
What does AuthMargin cost?
Current pricing is $49/month for Business, $99/month for Pro and $299/month for MSP. See the Pricing page for the capabilities included in each plan.
Can AuthMargin run arbitrary PowerShell?
No. The Workbench is intentionally constrained to supported Microsoft 365 operations. It is not a general-purpose hosted shell.
Can AuthMargin lock us out?
Read-only Audit Mode cannot change tenant configuration. Where Protect capabilities are enabled, supported changes use explicit consent, impact preview, approval, verification, rollback safeguards, and protected emergency-account boundaries.
How does AuthMargin protect customer separation?
AuthMargin enforces tenant-aware authorization on the server side and is designed so one customer cannot access another customer's authorized tenant data.
Where is AuthMargin hosted?
AuthMargin is hosted on enterprise-grade cloud infrastructure with managed security and reliability controls. Specific infrastructure topology and implementation details are intentionally not published on the public site.
How is customer data protected?
AuthMargin is designed around least-privilege access, encryption, tenant isolation, bounded data retention and controlled evidence handling. Public documentation focuses on customer-facing safeguards rather than exposing internal architecture.
Does AuthMargin establish SOC 2, ISO 27001 or HIPAA compliance?
No. A tenant scanner cannot provide an independent SOC 2 attestation, ISO/IEC 27001 certification or a legal determination of HIPAA compliance. AuthMargin provides technical readiness/evidence views and remediation mapping for SOC 2, CIS Microsoft 365, NIST CSF 2.0, ISO/IEC 27001 and HIPAA Security Rule safeguards.
How will Microsoft compliance documents fit into AuthMargin?
AuthMargin separates Microsoft's cloud-service assurance from the customer's own tenant responsibilities. AuthMargin can reference appropriate Microsoft Service Trust Portal materials for authorized customers while keeping customer-specific tenant evidence separate. Restricted Microsoft audit reports should not be copied or redistributed by AuthMargin.
Can I evaluate AuthMargin before subscribing?
Yes. The public demo, FAQ, pricing, and trust pages are available before you connect a tenant or start a subscription.
Still deciding?
Use the synthetic demo first. It shows the operating model without touching a production tenant.
