Coverage · AI Assistant · Beta

Talk to your Azure.

Ask about your Microsoft 365 and Azure tenant the way you'd ask a colleague. Answers come from your own scan results — with the findings they came from, so you can check the work.

Write permissions
0
Your provider, your key
BYOK
Live read-only tools
12

The problem

A list of findings is not the same as knowing what to do.

A scan hands you forty things that are wrong. Some matter this week, most don’t, and telling them apart is the job — one that assumes you already know what “legacy authentication” costs you, or why a guest account with an owner role is worse than it sounds.

Most people running a small company’s IT do not have that background, and should not need it. So you can just ask.

Talk to your AzureAsk about your tenant in plain language and get answers grounded in your own scan.AI Assistant demo · 53 sec

What you can ask

Plain language. No query syntax to learn.

  • Which of these findings should I fix first?
  • Does Dana have MFA turned on right now?
  • Why does this one matter — what would an attacker do with it?
  • Walk me through fixing the SharePoint sharing issue.
  • What changed in my tenant this week?
  • Which apps have access to my tenant, and what were they granted?

How it works

Grounded in your tenant, not in a model’s memory.

  1. 01

    It reads your scan

    Answers come from your own completed scan — the findings, their severity, the evidence behind them. Every claim cites the finding it came from, so you can open it and check.

  2. 02

    Optionally, your live tenant

    Turn on live access and it can also read current state through its own read-only app: who has MFA today, whether a fix has actually landed, what changed this week. Off by default.

  3. 03

    It checks Microsoft's docs

    Before giving you portal steps, it looks up Microsoft's current documentation. Menus and blades get renamed constantly, and a walkthrough from stale training data sends you somewhere that no longer exists.

Where your data goes

You already trusted us with read access. This is what we did with it.

“AI” next to “security scanner” is a fair thing to be suspicious about. Here is exactly what happens, in mechanisms you can verify rather than promises you have to take.

Your provider, your key

You bring your own OpenAI, Azure OpenAI, or Anthropic account. Your findings go to the model you chose, under your agreement with them. Tenant Strike never sends your data to an AI provider on its own behalf, and we never see your key after you save it.

Names replaced before sending

Email addresses, IP addresses and display names are swapped for placeholders before anything leaves our servers, and swapped back on your screen. The model reasons about the finding; it does not learn who your people are.

Read-only, and separately revocable

Every permission it holds ends in .Read. It cannot change a setting, a user, or a policy. Live tenant access runs through its own app registration you consent to separately — so its reads appear under their own identity in your sign-in logs, and revoking it does not stop your scans.

Every API call we make against your tenant is logged and shown back to you, the assistant’s separately from the scanner’s. See the read-only assurance page.

What it won’t do

It says “I couldn’t read that” instead of guessing.

The failure that matters in a security tool is not a wrong answer — it is a confident one. If a permission is missing or Microsoft throttles a request, the assistant tells you the read failed. It never reports a failed check as “all clear”, and it never states a number no tool returned.

It also cannot change anything, and is built so it cannot claim to have.

AI Assistant · Included with Pro · Beta

See what your tenant would tell you, if you could just ask it.

Included in Pro at no extra cost. Bring your own AI provider key — or leave the assistant off entirely and the scanner works exactly as before.