Pricing

Two tiers, a 7-day Pro trial, and no credit card to start.

Built for small teams to set up themselves: pick a plan, sign in as your Microsoft admin, and scan. No demo to sit through, and no sales call to book.

Basic

Microsoft 365 security, for small teams.

$99/mo, per tenant

or $990/yr — 2 months free

Start Basic
  • Microsoft 365 scans & grade
  • Fix plan + step-by-step guidance
  • Microsoft 365 attack paths
  • Scheduled scans + change tracking
  • Read-only access you can verify
  • Up to 100 users
Recommended

Pro

Everything — Microsoft 365, Azure, and what’s exposed online.

$299/mo, per tenant

or $2,990/yr — 2 months free

Start 7-day free Pro trial
  • Everything in Basic, plus:
  • 51 Azure cloud checks + Azure attack paths
  • Vulnerability Watch — alerts for the tech you run
  • External scan — what's exposed online
  • Continuous Shodan monitoring — alerts when your exposure changes
  • Email alerts when a new flaw affects you
  • AI assistant — ask about your tenant in plain language (Beta)
  • Up to 500 users
Included with annual Pro

Quarterly Security Review

Pay for Pro yearly and we sit down with you up to four times a year — 45 minutes, scheduled when it suits you — and go through what changed, what it means, and the two or three things actually worth doing next quarter. You get the judgment part of a security firm without the retainer.

  • What changed since last quarter, and whether it mattered
  • A short, prioritized plan you can hand to whoever does the work
  • Straight answers on findings you've accepted or deferred
  • Written follow-up you can forward to your board or insurer

Monthly Pro and Basic don’t include reviews — but you can still email us any time, and we answer. If your Microsoft tenants are managed by an IT provider, your reviews come from them rather than us — that’s what they’re there for.

Compare every feature.

FeatureBasicPro
Microsoft 365 scans
Security score + grade
Fix plan + step-by-step guidance
Mark findings as accepted or handled
Microsoft 365 attack paths
Scheduled scans
Change tracking over time
Azure cloud checks (47)
Azure attack paths
Vulnerability Watch (alerts for the tech you run)
Email alerts when a new flaw affects you
External scan — what's exposed online
Continuous monitoring of your public IPs via Shodan (between scans)
AI assistant — ask about your tenant in plain language (Beta)
Read-only access you can verify
Quarterly Security Review (annual billing)
User cap (soft fair-use)100500

Managing client tenants?

MSPs and IT providers get one console across every client, volume pricing per client tenant, and onboarding help getting the first few connected. Your clients never need a login unless you want them to have one. Reach out for MSP setup and pricing →

Bigger, or a custom contract?

Above 500 users, need a PO, security review, or dedicated onboarding support? Talk to us →

FAQ

Questions we get a lot.

What happens after my 7-day trial ends?
Convert to Pro (no interruption — your data stays, scans continue), downgrade to Basic (you keep Microsoft 365 coverage but lose Azure, Vulnerability Watch, the external scan, and Azure attack paths), or cancel (your data stays for 30 days in case you change your mind, then is deleted). No surprise charges — we never bill without explicit consent.
Can I switch between Basic and Pro?
Yes, anytime, from the billing portal in your dashboard. Monthly plan changes apply immediately and are prorated both ways — upgrades charge only the difference for the rest of the period, and downgrades credit the unused portion of the old plan toward your next invoices, so you never pay for the same time twice. During your trial you can pick the plan you'll land on without affecting the trial itself. Changes involving a yearly plan take effect at your annual renewal — email [email protected] and we'll set it up.
Is the AI assistant included, or is it extra?
Included with Pro at no extra cost, and it’s in beta. You bring your own AI provider key, so the model usage is billed to you by your provider rather than marked up by us. It’s also off until you turn it on: it uses a second, separate Microsoft app registration that an admin has to consent to, so nothing goes near an AI model until someone deliberately enables it. Its reads are read-only, scoped to configuration metadata, and appear in your Entra sign-in logs under their own name — “Tenant Strike AI Assistant” — so you can see exactly what it looked at. See what it does and where your data goes. Basic doesn’t include it.
Do you keep watching between scans, or only when a scan runs?
Both, on Pro. The external scan is a point-in-time picture; continuous monitoring is what happens in between. We register the public IP addresses you provably own with Shodan Monitor, and get pushed a notification when something changes — a new service or port appears, a database opens to the internet, a TLS certificate expires, or a host starts showing as running known-vulnerable or end-of-life software. You get an email when it fires. We only register addresses you demonstrably control: resources read from your own Azure subscription, the A record for your primary domain, and hostnames under a domain you’ve verified. Addresses behind a CDN or on shared Azure infrastructure are deliberately left out — they’re shared with thousands of unrelated sites, so watching one would mean emailing you about a stranger’s server. It all happens outside your tenant, on what is already publicly visible — and the only thing we hand to Shodan is the IP addresses themselves. See exactly what we register and what we don’t.
What if I have more than 500 users?
The 500-user cap on Pro is a soft fair-use guideline. If you exceed it, we'll reach out to discuss an enterprise contract — we won't shut off your scans without warning. Or email us upfront if you already know you're above 500 and we'll work with you on pricing.
Do you offer annual billing?
Yes, self-serve: pick yearly at checkout or while on your trial — Basic is $990/yr and Pro is $2,990/yr, two months free versus monthly. Yearly plans renew annually; cancellations and plan changes take effect at your renewal date, and we don't refund mid-term (the 30-day guarantee on your first payment still applies — see the refund policy below). If your procurement process needs a quote, PO, or invoice with ACH instead of a card, email us and we'll arrange it.
What's your refund policy?
If you're within 30 days of your first payment — monthly or yearly — and Tenant Strike isn't a fit, email us — we'll refund the charge, no friction. After that, cancel anytime; we don't refund partial months or the remainder of a yearly term, but you keep access through the end of the period you paid for.
Can I cancel anytime?
Yes. One click in the dashboard. No phone calls, no retention scripts. Your data stays for 30 days post-cancellation in case you come back.
What data do you keep about my tenant?
Scan results, audit logs of every API call we made into your tenant, and your account / billing info. We never see or store the contents of your files, mailboxes, or chats — only configuration metadata. See the trust page for the full list of API calls + verified read-only manifests.
Will my price go up later?
Possibly, eventually — we keep adding to the product and list prices move with it. What we commit to is how: your price never changes inside a term you’ve already paid for, you get at least 60 days’ notice by email before any increase affects you, and you can cancel before it takes effect. No silent uplifts at renewal, and no increase that first shows up on an invoice. If you’re on a yearly plan, an increase can only ever apply from your next renewal.
Why is there no free tier?
A free tier we can't support well isn't a favor to anyone. The 7-day Pro trial gives you the full product, free, for long enough to decide. If $99/month doesn't fit your situation (non-profit, tiny shop, student), email us — we're flexible.
How do I prove the read-only claim?
You don't have to take our word for it. The trust page publishes the complete list of everything Tenant Strike reads from your tenant, generated automatically from our code on every release — and our build fails if anything that could make a change ever sneaks in. We also keep a live log of every call we make, so what we did is always checkable against what we claim. Full technical detail is on the trust page.

Start with a scan

See what your Microsoft cloud looks like from the outside.

7-day Pro trial, no credit card. Full Microsoft 365 and Azure coverage, Vulnerability Watch, and 290+ attack paths.