Secure Score
Score, history, and recommended actions per connected tenant.
Microsoft Graph
SecurityScore.me uses read-only Microsoft Graph access to assess Microsoft 365 posture across customer tenants. Delegated permissions, multi-tenant consent, and least-privilege scopes designed for MSP operations.
Microsoft Graph is the API behind the Microsoft 365 admin surfaces. Reading posture through it is what makes a portfolio-wide assessment possible without a login per tenant.
The admin centers are built for a single tenant administrator clicking through screens. Graph exposes the same posture data programmatically, so one assessment can cover Secure Score, Conditional Access, Defender, and identity across many customer tenants.
That is the difference between a review you can run weekly across fifty clients and one you run once a year on the clients that asked.
SecurityScore.me requests delegated read-only permissions. It reads posture data and produces findings. It has no permission to change Conditional Access, roles, sharing, or any other tenant configuration.
Remediation stays with your team, in your normal change process, using Microsoft’s own tools.
Each customer tenant is connected through its own consent flow, scoped to that customer workspace. Connecting or disconnecting one customer does not touch any other.
Score, history, and recommended actions per connected tenant.
Policy configuration, conditions, and exclusions for identity posture.
Device posture and alerts where the customer is licensed.
Users, groups, authentication methods, privileged roles, and risky sign-ins.
External sharing settings and administrative role assignments.
Licence assignment and service context that frame the rest of the posture data.
The connection requests only the Graph permissions the assessment needs. The exact scopes are shown during tenant connection so you and the customer can review them before consenting.
Access is exercised only when assessments and scheduled re-checks run. MSP team access to a connected customer is governed by organization roles, and every connection, scan, and settings change is written to the activity log.
Consent for a customer tenant can be withdrawn from the Microsoft side or by removing the workspace. Once revoked, no further posture data is read for that customer.
The domains the Graph assessment covers.
Scheduled re-checks that reuse the Graph connection.
The structured review Graph data feeds.
Full platform context for Graph-based operations.
Request a demo.