The catalog

Every check, in plain English.

Tenant Strike runs 135 read-only checks across Microsoft 365 and Azure — the settings attackers probe first, from MFA coverage and legacy authentication to open storage and what your tenant exposes to the public internet. Each check explains what it looks for and why it matters; a scan tells you where your tenant stands.

Identity

MFA enforcement, Conditional Access coverage, admin hygiene, legacy auth.

Email

DMARC / SPF / DKIM, Defender for Office, forwarding rules, transport policies.

Sharing & Collaboration

SharePoint / OneDrive / Teams external sharing, cross-tenant, anonymous links.

Apps & Consent

OAuth consent policies, risky Graph permissions, expiring secrets.

Devices

Intune compliance, BitLocker, Defender for Endpoint onboarding.

Azure

Servers, storage, databases, networking, access and backup across every subscription.

External Attack Surface

Shodan-enriched view of what your tenant looks like from the public internet.

See your own results

The catalog says what we look for. A scan says where you stand.

Connect read-only, scan in minutes, and get an A–F grade with a step-by-step fix for every gap. 7-day Pro trial, no credit card.