Cloud Audit Check reads your Microsoft 365 and Azure configuration, scores it against the Essential Eight, and hands you the evidence and fixes — the assessment a consultant charges thousands for, running automatically.
Contoso Pty Ltd
Microsoft 365 + Azure · today
Why teams switch to it
An ML0–ML2 verdict per strategy, scoped honestly to what a cloud audit can prove. Exactly what auditors and cyber-insurers ask for.
Identity, config, data, licensing — plus Azure Defender, network, storage and RBAC — in one score. Reuses your existing app registration.
Every finding names the actual accounts, policies, NSG rules and storage accounts — which user, which resource, which subscription.
Plain-English steps plus ready-to-run PowerShell or config, so remediation starts the moment the scan finishes.
Schedule monthly re-scans and get an email the moment your posture drifts — a dropped score, a disabled control.
Export a branded PDF or Word report — executive summary, maturity, roadmap and evidence — ready for the board or the insurer.
What we assess
Ten pillars in total — six for Microsoft 365, four for Azure — folded into one posture score and Essential Eight maturity.
Azure is optional and reuses the same app registration — just assign it read-only Reader + Security Reader on your subscription.
How it works
Grant read-only admin consent through Microsoft — and, for Azure, assign Reader on your subscription. No agents, no stored passwords, revoke anytime.
We read your Microsoft 365 and Azure configuration, fold in Microsoft Secure Score, and evaluate hundreds of controls in under a minute.
Get your score, Essential Eight maturity, evidence-linked findings and a prioritised roadmap — then re-run to prove each fix landed.
Read-only by design
Only read-only permissions — approved in Microsoft’s own admin-consent screen, and revocable anytime. We change nothing in your tenant, and we never read your emails or files.
Identity, Conditional Access, roles, apps, domains, Secure Score, per-user MFA, and Intune device compliance.
Detects inbox rules that forward mail externally — reads the rule, never a single message.
Reader + Security Reader on your subscription for Defender, network, storage, and RBAC checks.
Built for MSPs
Manage up to three client tenants from one console, ranked by risk, and deliver reports your clients think you built yourself.
Portfolio · 3 clients
Ranked by risk — see the client who needs you first.
Pricing
One free audit shows your score. Pro and MSP unlock the full assessment, reports, and continuous monitoring.
Free
See where you stand
$0 forever
Pro
For a single business
$149 /month
MSP
For MSPs & agencies
$399 /month
Prices in AUD. Annual billing saves two months. Compare plans →
Only read-only ones, approved in Microsoft’s admin-consent screen: read-only Microsoft Graph (identity, Conditional Access, roles, apps, Secure Score, per-user MFA, Intune compliance), MailboxSettings.Read (inbox forwarding rules only — never message content), and, for Azure, read-only Reader + Security Reader. We change nothing and can be disconnected anytime.
Never. We assess configuration and metadata only. The closest we get to mail is reading inbox-rule definitions to catch external forwarding — we never open a message, file, or chat.
On the MSP plan, reports carry your brand instead of ours — your logo and name on a polished PDF you send straight to your client, so the work looks like it came from you.
Under a minute of scan time, across Microsoft 365, Azure, and Microsoft Secure Score.
One tenant, your overall score, your top 5 risks, and an Essential Eight snapshot. Pro unlocks every finding, evidence, reports, maturity levels, Azure, and history.
Yes — hosted in Sydney. We store assessment results, never your content. See the Security page for the full detail.
Run your first Microsoft 365 & Azure audit free — read-only, no agents, results in minutes.