What needs attention now
Open gaps ranked by importance, with the evidence and business impact beside each one.
Free · read-only · no card
A read-only view of what is strong, what is exposed, and what to fix first.
Start your assessment
Work email now. Read-only approval next.
Read-only by designKinervo observes. It cannot change tenant settings.
Microsoft approvalAccess is granted on Microsoft's own consent screen.
A report you can sendClear for owners, useful for the people fixing the issue.
Revoke any timeRemove the enterprise app directly in Entra.
Your deliverable
A visual, private report turns tenant evidence into a clear decision: what matters now, and what happens next.
Open gaps ranked by importance, with the evidence and business impact beside each one.
A simple refresh of what is confirmed, what needs attention and what could not be checked.
Important sign-in, mailbox and permission indicators pulled out of the background noise.
A short priority list for the owner, backed by enough detail for the IT provider.
Tenant posture
Northstar & Co.
Example assessment
Read-only monitoring
Confirmed
12
checks already working
Next actions
3
clear things to do
To confirm
4
need more evidence
Passkeys
17
people registered
What is assessed
Kinervo reports only what the tenant's permissions and licences allow it to verify. Anything unavailable is labelled—not silently counted as safe.
MFA and sign-in strength
Conditional Access coverage
Admin role exposure
App consent and permissions
Mailbox rules and forwarding
Sign-in and audit indicators
The safe path
You stay in control from the first field to the removal of access.
Enter a work email so Kinervo can prepare the correct organisation-specific Microsoft consent link.
A Global Administrator sees the full read-only permission list on Microsoft's own screen before accepting.
Collection runs automatically. Your private report link is delivered to the work email used at signup.
Kinervo can
Kinervo cannot
Before you approve
No. Kinervo has read-only permissions. It cannot edit a policy, disable an account, remove a rule or make any other tenant change.
Security configuration and the operational evidence needed for the report: identity protections, policies, roles, applications, audit and sign-in information, mailbox forwarding configuration and public domain-authentication records. It cannot read email, files or Teams message content.
The next step can be sent directly to your Microsoft 365 administrator or IT provider, with the permission list and a plain-English explanation.
Nothing is charged automatically because no card is taken. Monitoring stops unless you choose to continue at €199 per month.