What can we demonstrate?
Tenant posture
See the protections supported by current evidence, the gaps, and what still needs verification. Give leadership a clear view of where the organisation stands.
Independent Microsoft 365 assurance
Know which protections are in place, what needs attention and whether improvements show up in the evidence. Clear answers for owners. Practical next steps for IT. Read-only access to your tenant.
Tenant posture
Northstar & Co.
Example assessment
Read-only monitoring
Confirmed
12
checks already working
Next actions
3
clear things to do
To confirm
4
need more evidence
Passkeys
17
people registered
Read-only by designKinervo observes. It cannot change tenant settings.
Microsoft approvalAccess is granted on Microsoft's own consent screen.
A report you can sendClear for owners, useful for the people fixing the issue.
Revoke any timeRemove the enterprise app directly in Entra.
For business owners and the IT teams they trust.
You already invest in Microsoft 365 and IT support. Kinervo helps you check the result: which protections are evidenced, which gaps need a decision and what changed after the work. Your IT team stays in control of every change.
Answers you can use
Three focused reports connect your current position to the next improvement. Each keeps confirmed results and missing evidence visible.
What can we demonstrate?
See the protections supported by current evidence, the gaps, and what still needs verification. Give leadership a clear view of where the organisation stands.
What should happen next?
Give your IT team a prioritised list with the affected accounts, practical guidance and the evidence needed to check the result.
Who needs stronger sign-in?
Understand passkey readiness, registered methods and observed sign-in use. See who needs help without confusing registration with enforced protection.
Explore an example before connecting your tenant.The sample uses fictional company data and the same layout as your private assessment.
Evidence coverage
See supported checks across these areas. The results show what Microsoft returned, when it was checked and where the evidence is limited.
Your IT team controls the changes
Kinervo identifies the gap and explains the next step. Your authorised IT team makes the change. A later assessment checks whether the relevant evidence now meets the control.
Registered methods, observed use and password-only exposure.
Policy state, exclusions and the coverage the evidence supports.
Standing roles and high-impact accounts.
Applications and permission grants.
Forwarding and suspicious inbox rules.
SPF, DKIM and DMARC across company domains.
Returned sign-in risk and configuration-change indicators.
Visible device and service protections.
Coverage depends on Microsoft licences, approved permissions and successful collection. Each report distinguishes assessed results from checks needing more evidence. These areas do not imply exhaustive coverage of every workload.
How it works
You see what is requested before anything is approved. Nothing connects automatically.
Enter one work email. No card or software to install.
Your administrator sees every read-only permission before approving.
Review your private assessment. Ongoing reporting covers Tenant posture, Outstanding actions and Phishing resistance.
Not the administrator? Your IT provider can review the same plain-English scope before any Microsoft approval takes place.
Simple commercial model
Start with a read-only assessment of your own Microsoft 365 environment. Continue only if the monitoring and simple reports earn their place.
€0
No card. No automatic charge.
€199/month
Choose after the free period. Cancel any time.
Your first report
Start with a work email. Every request is reviewed before a Microsoft approval is prepared. Your administrator stays in control of access.
Request your free assessment
One field now. Nothing connects automatically.
Straight answers
The important questions should be answered before anyone reaches a Microsoft consent screen.
Kinervo's access to your Microsoft 365 tenant is read-only. It cannot create a policy, change a setting, remove an account or remediate a finding. Your administrator approves access in Microsoft, can inspect it in Entra, and can revoke it directly. Kinervo stores the evidence, reports and follow-up records needed to provide the service in its own portal.
No. The service reads security configuration and the operational evidence needed for the assessment, such as policy state, role assignments, sign-in and audit information, and mailbox forwarding configuration. It cannot read the content of email, files or Teams messages.
You can send the approval step to the person who is—often your IT provider. They receive the same plain-English explanation and the exact read-only permission list before approving anything.
Microsoft exposes different evidence at different licence levels. Kinervo reports the boundary honestly: passed, failed, needs a licence, needs manual verification or could not be verified. Missing visibility is never presented as a pass.
Yes. The initial assessment, private report and first 14 days of monitoring are included without a card. Ongoing monitoring is €199 per month only if you choose to continue.
Your IT provider remains responsible for changes. Kinervo gives you both an independent view of the returned Microsoft 365 evidence, a shared list of priorities, and later assessments to check whether improvements are visible. You can keep the people and tools you already use.
It shows how the assessed controls compare with the checks Kinervo applies, at the time evidence was collected. Licence limits, collection gaps and items needing manual review remain visible. A passing check is evidence about that control; it is not a certification, a guarantee against a breach or a complete review of every system in your organisation. Kinervo does not provide incident containment or a 24/7 response team.
Your tenant. Clearly explained.
Free assessment, read-only access, no card. The report is yours either way.