10110010011101001011001101101110101018200.devFrom Enterprise.Systems
Microsoft 365 logo

Microsoft 365

CanlıÜretkenlik ve İşbirliği

Microsoft 365 bağlayıcısı — salt okunur, aracısız

Scans SharePoint / OneDrive sharing, inventories Entra (Azure AD) app registrations, service principals and their consented scopes, and audits the tenant security posture (Security Defaults, Conditional Access, MFA coverage, app consent, admin roles).

Neleri tararız

  • SharePoint / OneDrive file and sharing metadata (never file contents)
  • Entra app registrations, service principals, and their consented OAuth scopes
  • Tenant security configuration: Security Defaults, Conditional Access, MFA registration, app-consent policy, and privileged role assignments

Yalnızca okuma izniyle izleme — otomatik düzeltmeyi etkinleştirip yazma erişimini ayrıca vermediğiniz sürece Microsoft 365 verilerinizde hiçbir şey değişmez.

Güvenlik bulguları

Her Microsoft 365 taramasında 26 algılama kuralı çalışır. Her bulgu; sade dille bir açıklama, arkasındaki kanıt ve düzeltme adımlarıyla birlikte gelir.

  • CRITICALPublic exposure

    Public link with edit/owner access

  • CRITICALExternal access

    External principal holds ownership

  • CRITICALIdentity

    A material share of users have not registered for multi-factor authentication

    Users who have never registered an MFA method cannot be challenged for a second factor, so any policy requiring MFA silently fails for them. Aim for near-complete registration.

  • HIGHPublic exposure

    Public link share (link-only)

  • HIGHPublic exposure

    Public + web-discoverable share

  • HIGHExternal access

    External access to sensitive data

  • HIGHExternal access

    External collaborator with edit access

  • HIGHOver permission

    Sensitive resource editable org-wide

  • HIGHOver permission

    Broad group access to sensitive data

  • HIGHAI agent

    Service account with broad write access

  • HIGHAI agent

    AI agent with access to sensitive data

  • HIGHAI agent

    AI agent with edit/owner access

  • HIGHExternal access

    Access granted to a look-alike (typosquat) domain

  • HIGHIdentity

    Security Defaults are off and no Conditional Access baseline is enforced

    A tenant with Security Defaults disabled and no enabled Conditional Access policy has no baseline MFA/identity protection — a single phished password can sign in unchallenged.

  • HIGHAccess

    Legacy authentication is not blocked

    Legacy authentication protocols (IMAP, POP, SMTP AUTH, older Office clients) cannot enforce MFA and are the vector for the majority of password-spray compromises. An enabled Conditional Access policy should block them.

  • HIGHAccess

    No enabled Conditional Access policy requires multi-factor authentication

    Without an enforced policy requiring MFA, users authenticate with a password alone. Report-only and disabled policies do not enforce anything.

  • HIGHApplications

    Users can consent to third-party apps themselves

    When user consent is left enabled, any employee can grant a third-party app (including an AI assistant) access to their mailbox or files with one click — the primary shadow-AI / OAuth-phishing vector. Route consent through an admin review workflow instead.

  • MEDIUMOver permission

    Broad org-wide edit access (aggregate)

  • MEDIUMOver permission

    Resource with multiple owners

  • MEDIUMStale access

    Stale external read access

  • MEDIUMStale access

    Dormant privileged internal account

  • MEDIUMMisconfig

    Direct share breaks folder inheritance

  • MEDIUMAccess

    Anyone in the organization can invite external guests

    When every member (not just admins or designated inviters) can invite B2B guests, external identities accumulate without review — a quiet expansion of the access boundary.

  • MEDIUMSharing

    SharePoint / OneDrive allows anonymous "Anyone" sharing links org-wide

    When the tenant external-sharing capability permits "Anyone" links, any user can mint a no-sign-in URL to a document, and that URL leaks data the moment it is forwarded.

  • MEDIUMAdmin

    More Global Administrators than recommended

    Global Administrator is the most powerful role in the tenant. Microsoft recommends keeping it to a small number (around 2–4, with break-glass accounts excluded). Every extra holder is a high-value phishing target with tenant-wide blast radius.

  • MEDIUMMisconfig

    Vendor AI-training data-contribution posture

Microsoft 365 nasıl bağlanır

  1. Adım 1

    8200.dev'e kaydolun veya oturum açın

  2. Adım 2

    Bağlayıcılar → Microsoft 365 bölümüne gidin

  3. Adım 3

    Bağlan'a tıklayın ve Microsoft 365 onay ekranı üzerinden yetkilendirin

  4. Adım 4

    8200.dev otomatik olarak tarar — sonuçlar birkaç dakika içinde görünür

İlk kaynağınızı dakikalar içinde bağlayın — ücretsiz, salt okunur, satış görüşmesi gerektirmez.