Independent Microsoft 365 assurance

Confidence in Microsoft 365. Evidence to back it up.

Know which protections are in place, what needs attention and whether improvements show up in the evidence. Clear answers for owners. Practical next steps for IT. Read-only access to your tenant.

No cardMicrosoft consentPrivate reportRevoke any time
Illustrative preview
Kinervo · Microsoft 365 tenant posture

Tenant posture

Northstar & Co.

Example assessment
Read-only monitoring

Confirmed

12

checks already working

Next actions

3

clear things to do

To confirm

4

need more evidence

Passkeys

17

people registered

What the checks showEvidence first
Strong sign-in methods are availableConfirmed
Email spoofing protection is in placeConfirmed
Help remaining administrators register passkeysNext
Review the newly detected forwarding ruleNext
What to do next3 actions
Require strong sign-in for administrators
Review one external forwarding rule
Confirm four checks with missing evidence
Tenant posture · Outstanding actions · Phishing resistance

Read-only by designKinervo observes. It cannot change tenant settings.

Microsoft approvalAccess is granted on Microsoft's own consent screen.

A report you can sendClear for owners, useful for the people fixing the issue.

Revoke any timeRemove the enterprise app directly in Entra.

For business owners and the IT teams they trust.

You already invest in Microsoft 365 and IT support. Kinervo helps you check the result: which protections are evidenced, which gaps need a decision and what changed after the work. Your IT team stays in control of every change.

Answers you can use

A shared picture for leadership and IT.

Three focused reports connect your current position to the next improvement. Each keeps confirmed results and missing evidence visible.

What can we demonstrate?

Tenant posture

See the protections supported by current evidence, the gaps, and what still needs verification. Give leadership a clear view of where the organisation stands.

What should happen next?

Outstanding actions

Give your IT team a prioritised list with the affected accounts, practical guidance and the evidence needed to check the result.

Who needs stronger sign-in?

Phishing resistance

Understand passkey readiness, registered methods and observed sign-in use. See who needs help without confusing registration with enforced protection.

Explore an example before connecting your tenant.The sample uses fictional company data and the same layout as your private assessment.

Open the sample

Evidence coverage

Understand the protections that matter.

See supported checks across these areas. The results show what Microsoft returned, when it was checked and where the evidence is limited.

Your IT team controls the changes

Kinervo identifies the gap and explains the next step. Your authorised IT team makes the change. A later assessment checks whether the relevant evidence now meets the control.

Identity & MFA

Registered methods, observed use and password-only exposure.

Conditional Access

Policy state, exclusions and the coverage the evidence supports.

Admin privilege

Standing roles and high-impact accounts.

Apps & consent

Applications and permission grants.

Mailbox risk

Forwarding and suspicious inbox rules.

Domain protection

SPF, DKIM and DMARC across company domains.

Sign-ins & audit

Returned sign-in risk and configuration-change indicators.

Device & service posture

Visible device and service protections.

Coverage depends on Microsoft licences, approved permissions and successful collection. Each report distinguishes assessed results from checks needing more evidence. These areas do not imply exhaustive coverage of every workload.

How it works

From one request to a useful answer.

You see what is requested before anything is approved. Nothing connects automatically.

01

Request your assessment

Enter one work email. No card or software to install.

02

Review the read-only scope

Your administrator sees every read-only permission before approving.

03

Get the clear version

Review your private assessment. Ongoing reporting covers Tenant posture, Outstanding actions and Phishing resistance.

Not the administrator? Your IT provider can review the same plain-English scope before any Microsoft approval takes place.

Simple commercial model

See the value before deciding.

Start with a read-only assessment of your own Microsoft 365 environment. Continue only if the monitoring and simple reports earn their place.

Assessment + trial

Start here

€0

No card. No automatic charge.

  • Control results with evidence boundaries
  • Private plain-English report
  • Technical evidence for your IT provider
  • 14 days of read-only monitoring
Request assessment

Ongoing monitoring

€199/month

Choose after the free period. Cancel any time.

  • Recurring checks of available sign-in signals
  • Alerts for important suspicious indicators
  • Scheduled configuration reassessment
  • Tenant posture, Outstanding actions and Phishing resistance reports on demand
Request assessment

Your first report

Start with the evidence from your own tenant.

Start with a work email. Every request is reviewed before a Microsoft approval is prepared. Your administrator stays in control of access.

  • No tenant setting can be changed
  • A visual report, not a data dump
  • Approve and revoke directly in Entra
  • No card and no automatic charge

Request your free assessment

One field now. Nothing connects automatically.

No password, card or tenant access is requested here. A Microsoft approval is prepared only after personal review.

Microsoft approvalRead-onlyPrivate report

Straight answers

Trust is part of the product.

The important questions should be answered before anyone reaches a Microsoft consent screen.

Can Kinervo change anything in Microsoft 365?

Kinervo's access to your Microsoft 365 tenant is read-only. It cannot create a policy, change a setting, remove an account or remediate a finding. Your administrator approves access in Microsoft, can inspect it in Entra, and can revoke it directly. Kinervo stores the evidence, reports and follow-up records needed to provide the service in its own portal.

Does Kinervo read email or files?

No. The service reads security configuration and the operational evidence needed for the assessment, such as policy state, role assignments, sign-in and audit information, and mailbox forwarding configuration. It cannot read the content of email, files or Teams messages.

What if I am not the Microsoft 365 administrator?

You can send the approval step to the person who is—often your IT provider. They receive the same plain-English explanation and the exact read-only permission list before approving anything.

Will every check work on every Microsoft 365 licence?

Microsoft exposes different evidence at different licence levels. Kinervo reports the boundary honestly: passed, failed, needs a licence, needs manual verification or could not be verified. Missing visibility is never presented as a pass.

Is the assessment really free?

Yes. The initial assessment, private report and first 14 days of monitoring are included without a card. Ongoing monitoring is €199 per month only if you choose to continue.

We already have an IT provider. Where does Kinervo fit?

Your IT provider remains responsible for changes. Kinervo gives you both an independent view of the returned Microsoft 365 evidence, a shared list of priorities, and later assessments to check whether improvements are visible. You can keep the people and tools you already use.

What does an assessment prove?

It shows how the assessed controls compare with the checks Kinervo applies, at the time evidence was collected. Licence limits, collection gaps and items needing manual review remain visible. A passing check is evidence about that control; it is not a certification, a guarantee against a breach or a complete review of every system in your organisation. Kinervo does not provide incident containment or a 24/7 response team.

Your tenant. Clearly explained.

See where you stand. Know what to do next.

Free assessment, read-only access, no card. The report is yours either way.

Request my free assessment