Free Tools PowerShell audit tool

15 M365 misconfigurations. One script. Under 10 minutes.

Sentinel Scout runs a weighted audit across 15 security controls in your Microsoft 365 tenant. You get a score, your top failures, and a JSON record for your files.

What it checks

15 controls covering identity, data protection, and admin hygiene. Each is weighted by security impact.

Check ID Control Severity
SC-001Legacy authentication protocols enabledCritical
SC-002MFA not enforced for all usersCritical
SC-003Security defaults or Conditional Access absentCritical
SC-004Global Administrator count exceeds 2High
SC-005Privileged Identity Management not in useHigh
SC-006Microsoft Secure Score below 50%High
SC-007External sharing unrestricted in SharePointHigh
SC-008Audit logging disabled or retention under 90 daysHigh
SC-009Defender for Office 365 anti-phishing not configuredMedium
SC-010Safe Links and Safe Attachments not enabledMedium
SC-011Self-service password reset not configuredMedium
SC-012Guest user access not reviewed in last 90 daysMedium
SC-013App consent not restricted to adminsMedium
SC-014Sign-in risk policy absentLow
SC-015Named locations not defined for Conditional AccessLow

Prerequisites

  • PowerShell 7 or later
  • Microsoft Graph app registration with admin consent
  • Required scopes: Policy.Read.All, Directory.Read.All, AuditLog.Read.All, SecurityEvents.Read.All, Reports.Read.All
  • Global Reader or Security Reader role on the target tenant

Install and run

Free access. Enter your details to reveal the installation script and instructions instantly.

Example output

Sentinel Scout v1.0 — M365 Security Audit
Tenant: contoso.onmicrosoft.com
Run completed: 2026-04-07 09:14:22 UTC

Controls assessed : 15
Controls passed   : 9
Controls failed   : 6

Weighted score    : 61 / 100

Top 3 failures:
  [CRITICAL] SC-001 — Legacy authentication still enabled
  [CRITICAL] SC-003 — No Conditional Access policies found
  [HIGH]     SC-008 — Audit log retention set to 30 days

Full results written to: sentinel-scout-20260407-091422.json

72

Average weighted score for mid-market M365 tenants

The most common failure: legacy authentication still enabled. It appears in over 60% of tenants audited during WGC-M365 engagements.

Free tool vs WGC-M365 Health Check

Sentinel Scout (free) WGC-M365 Health Check
Weighted score across 15 controlsRemediation roadmap with priorities
Top failing controls identifiedLeadership-ready report
JSON output for your recordsImplementation support included
Free after a short enquiryPaid engagement. Book a call

Ready to close the gaps?

A WGC-M365 Health Check turns your Sentinel Scout results into a prioritised action plan.

Typical output: ranked findings, board-ready summary, and 30/60/90-day actions.

Disclaimer

Sentinel Scout produces indicative output based on read-only Graph API queries at the time of the run. It is not a formal security assessment and should not be used as evidence of compliance or certification. Results reflect configuration state at run time and may not capture all relevant controls for your organisation.