Monitoring

Continuous Microsoft 365 security monitoring for MSPs

A clean assessment stops being true the first time an administrator changes something. Continuous monitoring is the schedule that re-checks each tenant, detects what changed, and gets the ones that matter to the right person. SecurityScore.me runs it across the whole portfolio.

What gets monitored, and how often

Monitoring is a set of scheduled checks per customer workspace, each comparing the current result against the previous run.

Microsoft 365 re-assessment

The full posture assessment runs again on a schedule: Secure Score, Conditional Access, Defender, identity signals, sharing, and admin configuration. A control that changed state since the last run becomes a finding.

Each run is compared against both the tenant’s baseline and its previous result, so the output is "what moved" rather than a fresh wall of settings to re-read every time.

Identity checks

Conditional Access policy state, new exclusions, MFA registration, and privileged role changes, because identity is where regressions appear fastest and matter most.

A policy that was enforced last week and is report-only this week, or an account added to an exclusion, is the kind of change that never generates a portal notification and is exactly what monitoring is for.

External asset scans

DNS and email authentication, exposed services, and web checks for the customer’s registered domains and websites, so a firewall rule opened this week is caught this week.

Passive subdomain discovery runs alongside, so a host that appears between reviews is picked up rather than waiting for someone to tell you it exists.

Certificate expiry

TLS certificates across every customer domain and every discovered subdomain, with tiered warnings so renewals are scheduled rather than scrambled.

Expiry is entirely predictable and still causes outages, because across a portfolio no single person owns the renewal calendar. A rollup with lead-time and urgent tiers puts that back in view.

Turning change into action

Detecting a change is only useful if it reaches someone. Routing is configured per customer and per team so monitoring does not become noise.

Notification policies

Decide which monitoring events generate a notification, based on severity and event type, so a new critical finding is treated differently from an informational change.

The same mechanism decides what stays silent. Routine informational changes are recorded in the activity log and the findings queue without paging anyone.

Alert groups

Assign recipients so the technician who owns a customer, or the customer contact, gets the events for that customer rather than every event for every client.

Groups map to how the MSP is actually structured: a pod that owns a set of customers, an on-call rota, or a single escalation address for critical findings only.

Keeping the signal high

Because alerts are scoped by severity and by customer, the volume stays low enough that people still read them. An alert stream nobody opens is the same as no monitoring.

Monitoring at portfolio scale

One organization view
Every customer’s monitoring status and open alerts in a single ranked list, not fifty separate dashboards.
Per-customer schedules
Scan frequency and notification policy set independently for each workspace to match the customer’s risk and change rate.
Consistent across tenants
The same checks run everywhere, so a finding in one tenant is directly comparable to the same finding in another.
Activity log
Organization events recorded for operational review and auditability.
Needs attention

From onboarding to steady state

Connect and baseline

Delegated read-only Graph consent, register domains and websites, run the first assessment.

Configure monitoring

Set scan schedules, notification policies, and alert groups for the customer.

Run and triage

Scheduled checks raise changed findings; alerts route to the owner while the change is fresh.

Report the period

Customer reports show what monitoring caught and resolved since the last review.

Related pages

Frequently asked questions

Next steps

Set up continuous Microsoft 365 monitoring