- 6 min read
Every tool that checks your Microsoft 365 security, honestly compared
Six ways to find out whether your Microsoft 365 is actually secure — what each one costs, what it's genuinely good at, and where each one stops. Written by a vendor, which is why we've been specific about where we lose.
Read - 5 min read
ScubaGear is free and good. Here's when it isn't enough.
CISA publishes a free tool that checks your Microsoft 365 against federal security baselines. It's genuinely excellent — and there are three specific situations where it won't get you what you need.
Read - 6 min read
What your Microsoft Secure Score doesn't tell you
Secure Score is free, built in, and genuinely useful. It also can't see three things that decide whether you actually get broken into — and one of them is in Microsoft's own documentation.
Read - 2 min read
AI tools and admin access to Microsoft 365 don't mix
MSPs and IT admins want the power and efficiency of AI. Doing it the wrong way is a recipe for disaster. So we built ours read-only, with a human in the loop, walking you through the misconfigurations attackers actually look for.
Read - 4 min read
August 2026 Patch Tuesday: the flaw attackers use after they're already in
Microsoft fixed roughly 400 flaws on August 11. Only one is being used in real attacks, and on its own it can't get anyone in. What that means for you.
Read - 3 min read
When the hotel Wi-Fi is the attack
Microsoft has tied a campaign to Russian intelligence that takes over Wi-Fi at hotels and conference centers, then serves fake software updates and fake Microsoft sign-in pages. Three rules for anyone who travels.
Read - 4 min read
Conditional Access: the rulebook that decides when Microsoft asks for MFA
Conditional Access is the rulebook that decides when Microsoft 365 asks for a second check. What it is, whether you have it, and the baseline to ask for.
Read - 3 min read
The fake IT support chat in Teams (and the two settings that block it)
Attackers are posing as IT support inside Microsoft Teams. Two settings decide whether they can reach your staff — and both are wide open by default.
Read - 3 min read
Copilot and your files: the check to run before you turn it on
Copilot now comes built into Microsoft 365 small-business plans. Before you switch it on, find out what your employees can technically see.
Read - 4 min read
July 2026 Patch Tuesday: a small business action plan
Microsoft just fixed a record 570+ security flaws, two of them already used by attackers. Here's the short list that matters for a small business.
Read - 4 min read
Before you switch on Copilot, check what your team can already see
Copilot is now part of Microsoft 365 Business plans. It only shows people files they can already open — which is exactly the problem. Three checks first.
Read - 3 min read
The side door around MFA: lessons from 81 million break-in attempts
An attacker made 81 million login attempts against Microsoft 365 in two weeks — and got into businesses that had MFA. Here are the four gaps that let them in.
Read - 3 min read
Microsoft 365 prices went up on July 1: what your business gets for it
Microsoft 365 Business plans cost more as of July 1, 2026. What changed, the link protection you now get, and the one setting to check at renewal.
Read - 3 min read
No Password Required: The Kali365 Phishing Kit Hijacking Microsoft 365 Accounts
The FBI is warning about Kali365, a subscription phishing kit that steals Microsoft 365 access without ever touching your password — and walks right past MFA. Here's how the trick works and the one setting that blocks it.
Read - 3 min read
The 'Accept' button that hands over your mailbox: consent phishing, explained
A new wave of attacks skips passwords entirely: victims approve an innocent-looking app permission screen and hand criminals long-lived access to their Microsoft 365 mailbox and files. One setting shuts most of it down.
Read - 3 min read
"We have Microsoft 365, so we're covered" — and 4 settings that prove otherwise
Microsoft 365 is secure-capable, not secure-by-default. Out of the box, several settings are left wide open — and attackers know exactly which ones. Here are four to check this week.
Read - 4 min read
Stop scammers from emailing as your company — SPF, DKIM, and DMARC without the jargon
By default, anyone can send an email that looks like it came from your domain. Three DNS records — SPF, DKIM, and DMARC — fix that. Here is what they do and why they matter for your business.
Read - 3 min read
Shadow IT: the apps your team signed up for that you don't know about
Shadow IT is the software and accounts your employees adopt without telling anyone. Here is why it matters and four practical steps to get a handle on it without blaming your team.
Read - 3 min read
Security isn't 'set it and forget it' — and what 'drift' means for your business
Even a business that set up Microsoft 365 carefully will slowly slip out of shape. New employees, new apps, a quick fix that never got reverted — this gradual slide has a name, and it matters.
Read - 4 min read
Working with clients and contractors safely — guest access and external sharing in Microsoft 365
Microsoft 365 makes it easy to invite outsiders into Teams and share files externally. That's useful. But left on default settings, it can also leave your data wider open than you realise.
Read
See your own risk
Reading about it is one thing. Seeing your own gaps is another.
Start a 7-day Pro trial and get a plain-English security report for your Microsoft 365 and Azure — no credit card.