Microsoft 365
LiveProductivity & CollaborationMicrosoft 365 connector — read-only, agentless
Scans SharePoint / OneDrive sharing, inventories Entra (Azure AD) app registrations, service principals and their consented scopes, and audits the tenant security posture (Security Defaults, Conditional Access, MFA coverage, app consent, admin roles).
What we scan
- SharePoint / OneDrive file and sharing metadata (never file contents)
- Entra app registrations, service principals, and their consented OAuth scopes
- Tenant security configuration: Security Defaults, Conditional Access, MFA registration, app-consent policy, and privileged role assignments
Read-only monitoring — nothing in your Microsoft 365 data changes unless you turn on auto-remediation and grant write access separately.
Security findings
26 detection rules run on every Microsoft 365 scan. Each finding ships with a plain-language explanation, the evidence behind it and remediation steps.
- CRITICALPublic exposure
Public link with edit/owner access
- CRITICALExternal access
External principal holds ownership
- CRITICALIdentity
A material share of users have not registered for multi-factor authentication
Users who have never registered an MFA method cannot be challenged for a second factor, so any policy requiring MFA silently fails for them. Aim for near-complete registration.
- HIGHPublic exposure
Public link share (link-only)
- HIGHPublic exposure
Public + web-discoverable share
- HIGHExternal access
External access to sensitive data
- HIGHExternal access
External collaborator with edit access
- HIGHOver permission
Sensitive resource editable org-wide
- HIGHOver permission
Broad group access to sensitive data
- HIGHAI agent
Service account with broad write access
- HIGHAI agent
AI agent with access to sensitive data
- HIGHAI agent
AI agent with edit/owner access
- HIGHExternal access
Access granted to a look-alike (typosquat) domain
- HIGHIdentity
Security Defaults are off and no Conditional Access baseline is enforced
A tenant with Security Defaults disabled and no enabled Conditional Access policy has no baseline MFA/identity protection — a single phished password can sign in unchallenged.
- HIGHAccess
Legacy authentication is not blocked
Legacy authentication protocols (IMAP, POP, SMTP AUTH, older Office clients) cannot enforce MFA and are the vector for the majority of password-spray compromises. An enabled Conditional Access policy should block them.
- HIGHAccess
No enabled Conditional Access policy requires multi-factor authentication
Without an enforced policy requiring MFA, users authenticate with a password alone. Report-only and disabled policies do not enforce anything.
- HIGHApplications
Users can consent to third-party apps themselves
When user consent is left enabled, any employee can grant a third-party app (including an AI assistant) access to their mailbox or files with one click — the primary shadow-AI / OAuth-phishing vector. Route consent through an admin review workflow instead.
- MEDIUMOver permission
Broad org-wide edit access (aggregate)
- MEDIUMOver permission
Resource with multiple owners
- MEDIUMStale access
Stale external read access
- MEDIUMStale access
Dormant privileged internal account
- MEDIUMMisconfig
Direct share breaks folder inheritance
- MEDIUMAccess
Anyone in the organization can invite external guests
When every member (not just admins or designated inviters) can invite B2B guests, external identities accumulate without review — a quiet expansion of the access boundary.
- MEDIUMSharing
SharePoint / OneDrive allows anonymous "Anyone" sharing links org-wide
When the tenant external-sharing capability permits "Anyone" links, any user can mint a no-sign-in URL to a document, and that URL leaks data the moment it is forwarded.
- MEDIUMAdmin
More Global Administrators than recommended
Global Administrator is the most powerful role in the tenant. Microsoft recommends keeping it to a small number (around 2–4, with break-glass accounts excluded). Every extra holder is a high-value phishing target with tenant-wide blast radius.
- MEDIUMMisconfig
Vendor AI-training data-contribution posture
Related guide
How to connect Microsoft 365
Step 1
Sign up or log in to 8200.dev
Step 2
Go to Connectors → Microsoft 365
Step 3
Click Connect and authorize via Microsoft 365's consent screen
Step 4
8200.dev scans automatically — results appear within minutes
Connect your first source in minutes — free, read-only, no sales call.