Six ways to find out whether your Microsoft 365 is actually secure — what each one costs, what it's genuinely good at, and where each one stops. Written by a vendor, which is why we've been specific about where we lose.
If you run a small business on Microsoft 365 and you want to know whether it's actually secure, there are about six real answers. Most articles comparing them are written by one of the six.
This one is too — we make Tenant Strike, which is on the list. So we've tried to make this the version we'd want to read if we were buying: specific about what each option costs, what it's genuinely good at, and where it stops. Including ours. If you finish this and pick a free tool, that's a reasonable outcome, and we'd rather you pick the right one than pick us badly.
Four of the six are free.
Microsoft Secure Score — free, already on
Secure Score is built into Microsoft 365. It grades how you've configured Microsoft's own security controls and gives you a percentage plus a list of recommended actions.
Good at: costing nothing, being already there, and giving a non-technical owner a number that moves. If you've never looked, this is the cheapest useful hour available to you.
Stops at: your tenant boundary. It can't see what your business exposes to the internet. It scores controls individually rather than showing how they chain. And Microsoft's own documentation notes that marking an action "resolved through third party" awards the points while Microsoft has "no visibility into the completeness of implementation" — so the number partly reflects what someone told Microsoft.
Pick it if: you're starting from zero. Everyone should look at this regardless of what else they use.
ScubaGear — free, from CISA
ScubaGear is a PowerShell tool from the US Cybersecurity and Infrastructure Security Agency. It queries your M365 configuration and compares it against CISA's published SCuBA baselines, covering Entra ID, Exchange Online, Defender, SharePoint, Teams and Power Platform.
Good at: being a defensible audit against a real published standard, for free. "We assess against CISA SCuBA baselines" is a sentence that carries weight with an auditor or an insurer.
Stops at: requiring a person. Someone needs PowerShell, module installs, tenant permissions, and the discipline to re-run it after settings drift. It's also tenant-scoped, so nothing outside Microsoft is in view, and its output is a pass/fail list rather than a judgement about what to fix first.
Pick it if: you have a technical person who will own it on a calendar.
Maester — free, open source
Maester is a testing framework for Microsoft 365 and Entra security configuration, built on Pester. You run tests — including ones you write — and get results.
Good at: flexibility and integration. If you want security config verified in a pipeline, or you want to write your own assertions about your own tenant, this is the right shape.
Stops at: assuming you're the kind of person who writes tests. That's not a criticism; it's the audience. For an office manager or a business owner, this is not the tool.
Pick it if: you're technical, you like frameworks, and you want config checks running automatically alongside your other tests.
CIPP — free / open source, built for MSPs
CIPP (the CyberDrain Improved Partner Portal) is a multi-tenant management portal widely used by Microsoft 365 MSPs. It covers a lot of ground across client tenants, including standards enforcement.
Good at: managing many tenants, and actually doing things — it applies settings, not just reports on them. For an MSP standardizing across clients, that's the whole job.
Stops at: being an MSP tool. It expects partner-tenant relationships and someone who runs it. And its power is also its risk profile: a tool that can change client tenants is a tool that can change client tenants.
Pick it if: you're an MSP who wants one console to manage and enforce across clients.
CoreView — commercial, enterprise
CoreView is a commercial Microsoft 365 management and governance platform — delegation, license management, operations, and security posture across a large estate.
Good at: scale and governance for organisations with a dedicated M365 team.
Stops at: your budget and your size. It's priced and scoped for enterprises. A 40-person business evaluating it is usually evaluating the wrong thing.
Pick it if: you're large enough that M365 administration is somebody's full-time job.
Tenant Strike — ours, $99/month
Since we're on the list: Tenant Strike is a read-only security posture scanner for Microsoft 365 and Azure, built for businesses without a security team. It connects in about five minutes with nothing installed, runs 130+ checks, adds an outside-in scan of what your domain exposes to the public internet, and correlates findings into the multi-step attack paths an intruder would actually use — so the fix list is ordered by what breaks a chain rather than by severity alone. Each fix is written in plain English with portal steps and a warning about what it might break. Basic is $99/month per tenant, Pro $299, priced per tenant rather than per user.
Good at: running without anybody remembering to run it, the outside-in view none of the free tools have, and being readable by someone who isn't a security specialist. It's read-only by design — every endpoint it reads is published and machine-verified on our trust page on every release.
Stops at: we don't change anything. That's deliberate, and it means we're not a replacement for a management tool like CIPP. We're not a compliance platform — we map to CIS, SOC 2, NIST 800-53 and MITRE ATT&CK, but we don't run your compliance program. We don't do containers or multi-cloud pipelines; this is not Wiz. And we cost money, which four things on this list don't.
Pick it if: nobody is going to run a script quarterly, or you need the outside-in half, or the person receiving the report needs to be told what to do rather than handed 200 findings.
The honest summary
| | Cost | Runs itself | Sees outside your tenant | Shows attack chains | For non-technical readers | |---|---|---|---|---|---| | Secure Score | Free | Partly | No | No | Yes | | ScubaGear | Free | No | No | No | No | | Maester | Free | If you wire it up | No | No | No | | CIPP | Free | Partly | No | No | No (MSP tool) | | CoreView | Enterprise | Yes | No | Partly | Yes | | Tenant Strike | $99+/mo | Yes | Yes | Yes | Yes |
The pattern worth noticing: the free tools are all excellent and all assume a technical person who will do the work repeatedly. That assumption is correct surprisingly often, and when it's correct you should take the free option.
It's wrong in a specific, common case — a business with no security staff, an IT provider who's busy, and nobody whose actual job is checking whether last quarter's fixes are still in place. That gap is why paid tools in this category exist, ours included. If it doesn't describe you, keep your money.
Start with Secure Score today either way. It's free, it's already on, and it costs you an hour.
AI-researched from public sources, human-reviewed on September 5, 2026. We label AI-assisted writing — see our trust page.
See your own risk
Want this for your own Microsoft cloud?
Tenant Strike runs 130+ read-only checks across Microsoft 365 and Azure and hands you a plain-English fix for every gap. Start a 7-day Pro trial — no credit card.