Features

What MSPs get in SecurityScore.me

A compact overview of the platform: multi-customer posture, Microsoft 365 and Entra assessment, domain and website checks, findings, reporting, and optional Security Operations.

Capability overview

Seven areas that cover the product

Short summaries first. Use Platform for architecture and Solutions for MSP workflows.

MSP workspace

Run every managed customer from one organization.

  • Multi-customer workspaces
  • Microsoft tenants, domains, and websites per customer
  • Filters and saved views
  • Owner, admin, analyst, technician, and viewer roles

Microsoft 365 and Entra

Read-only posture assessment across connected tenants.

  • MFA and privileged-role signals
  • Conditional Access and security defaults
  • Guest access and licensing context
  • Secure Score and sync health
  • Identity risk where permissions and licensing allow

Domain and website security

Non-invasive external checks in the same customer context.

  • DNS, DNSSEC, MX, SPF, DMARC, MTA-STS, TLS-RPT, and CAA
  • HTTPS, TLS, HSTS, CSP, and security headers
  • Cookies, CORS, security.txt, and technology fingerprints

Findings and monitoring

Prioritize posture issues and track meaningful change.

  • Severity-ranked findings with evidence and recommendations
  • Scheduled monitoring and drift awareness
  • Source health that avoids false-safe empty results
  • Customer-ready printable reports for reviews and QBRs

Security Operations

Optional MSP-only workspace for operational Microsoft signals.

  • Defender alerts and incidents
  • Entra risky users and sign-ins
  • Acknowledgement, assignment, notes, escalation, and SLA
  • Outbound customer updates, without a customer portal

Critical CVEs

Exposure context from detected technologies, kept separate from incidents.

  • Technology fingerprinting
  • NVD, CISA KEV, and EPSS context
  • Freshness, confidence, and safe rescan
  • Separate from active security incidents

Safeguards

Built for read-oriented, non-destructive assessment.

  • Read-only Microsoft permissions
  • Approved assets only and SSRF protections
  • No automatic remediation
  • No exploit execution

How the layers stay separate

Posture findings, Security Operations alerts, and Critical CVE exposure are distinct product layers. See how they fit together on the platform page.

Explore

Next steps

See these capabilities in your MSP workflow

Request a demo or explore solutions built around service delivery.

Features | SecurityScore.me