MSPs and IT admins want the power and efficiency of AI. Doing it the wrong way is a recipe for disaster. So we built ours read-only, with a human in the loop, walking you through the misconfigurations attackers actually look for.
AI tools and admin access to Microsoft 365 and Azure don't mix.
MSPs and IT admins want the power and efficiency of AI, and they should. But most integrations ask for far more than the job needs, and granting write access to a client tenant is a recipe for disaster.
The problem isn't AI. It's scale.
A Microsoft 365 and Azure tenant has thousands of settings, and they all have to be perfect. Conditional Access, sharing defaults, admin role assignments, legacy authentication, storage exposure, guest access, MFA registration gaps. Get 999 of them right and it counts for nothing if the thousandth is wrong, because attackers only need one way in.
IT teams are too lean for that. Not careless — outnumbered. There is no version of this where a two-person team manually reviews every setting across every tenant, every month, and catches everything.
That is exactly the work AI should be doing. It just can't come at the price of handing over the keys.
So we built it the other way round
The Tenant Strike AI Assistant has read-only permissions built in, not bolted on afterwards. It pinpoints the misconfigurations attackers actually look for, tells you why each one matters, and walks you through resolving it.
- Read-only by design. Every permission ends in
.Read. There's no write access to revoke, because none was ever requested. - A human stays in the loop. It advises, explains and walks you through the fix. You make the change, in your own admin centre.
- Its own identity. Separate app registration, short published scope list, consented and revoked on its own. It shows up in your service principal sign-in logs as "Tenant Strike AI Assistant", so you can see exactly what it read.
- Your model, your key. OpenAI, Azure OpenAI or Anthropic, on your own contract. Names, emails and IP addresses are swapped for placeholders before anything is sent.
- It admits what it couldn't read. A check that failed never comes back as "you're covered."
In beta, included with Pro.
See where they'd strike. Fix it first.
See your own risk
Want this for your own Microsoft cloud?
Tenant Strike runs 130+ read-only checks across Microsoft 365 and Azure and hands you a plain-English fix for every gap. Start a 7-day Pro trial — no credit card.