Dashboard
Start with what's on fire
The dashboard tiles the numbers that decide your day: failing controls, connection certificates about to expire, attestations coming up for renewal - over a live feed of recent changes.
Every number deep-links to the list behind it, and every list exports to PDF or CSV when someone asks for it in writing.
Looking after more than one tenant? The estate view rolls everything failing anywhere into a single list, each row deep-linking into the tenant it came from.
Assessments
Four independent baselines, side by side
Each baseline opens on an overview: status, a headline secure score with its trend, how many controls were tested, and how many are covered by an active attestation or accepted-risk acknowledgment.
400+ controls, 380+ of them automated
Four independent industry security baselines ship. Counting the newest version of each, that is 400+ controls: most run automatically, and the remainder resolve to a manual attestation. Your tenant picks the version it's assessed against, so an upgrade is a decision rather than a surprise.
Grouped by the products you run
Every control keeps its published identifier and its product grouping - Entra ID, Exchange Online, SharePoint Online, Microsoft Teams, Defender, Purview, Intune, Power Platform and Fabric - so a finding maps straight onto the admin center where you'd fix it.
Targeted re-check
Re-run a chosen subset of controls without touching the rest, so verifying one fix takes seconds. History records whether a run was full or targeted.
Manual attestation
Controls that can't be machine-decided resolve to a manual outcome. Record a dated attestation with a rationale and optional expiry; a sweep reminds you before it lapses.
Accepted risk
Acknowledge a gap you're carrying deliberately. It stays visible and marked rather than vanishing, applies to later assessments too, and the acknowledgment itself is audited.
Remediation & actions
Two speeds: now, or after approval
Low-risk remediations run straight through - queued, running, done - and only one live fix can exist per control, so parallel runs can't trip over each other.
Anything disruptive takes the gated path instead: preview, pending approval, approved, then run. It needs a configurable quorum of admin approvals, expires if nobody decides in time, and can carry a break-glass exclusion list.
Actions are parameterized bulk operations on the same rails. The preview materializes one row per candidate; approvers review the list and can exclude individual rows before promoting it. Actions include: prune or disable inactive Entra ID users, tighten public Microsoft 365 group visibility, block sign-in on Exchange Online shared mailboxes, copy group membership between Microsoft 365 groups, and change SharePoint site sharing capability.
Everything waiting on a decision - actions and remediations alike - collects on one Approvals page, and eligible approvers get an email.
Reports
Operational reports
Separate from assessments - these are the questions you get asked on a Tuesday. Five of them, to give you the shape:
Entra ID MFA coverage
Every user against broadly scoped Conditional Access or security defaults, joined with what they've actually registered.
User sign-in activity
Who signed in, when, and who hasn't - the input to most inactive-account decisions.
Device OS support
Which devices are running an OS version that's still supported, and which have fallen off.
Exchange Online mailbox sizes
Mailbox growth across the tenant, before someone hits a quota on a Friday afternoon.
Intune certificate expiry
Certificates approaching expiry, so the renewal happens before the outage.
Send them to anyone
Email a finished report to recipients with no Admin Companion account. The link expires on both a time window and a download count, so it can't circulate forever.
Automation & records
Set the cadence, keep the receipts
Scheduling
Assessments, reports and actions each carry their own cadence - off, daily, weekly by day-of-week, or monthly - at a chosen time, with a pause switch. New schedules start off, so nothing runs on a timer unless you asked for it.
Audit log
A filterable log of membership changes, role grants, sign-on configuration edits and every remediation - with before/after values, the actor, and a correlation id. Exportable, with retention you configure.
Account activity
Separately from the change audit, your own sign-ins, sign-outs and security events are recorded with their own retention and export, visible to you as the account owner.
Exports everywhere
Report runs, assessment results, per-control evidence and the audit log all export to PDF or CSV, delivered through time-limited links that tidy up after themselves.
Connections & access
App-only, least privilege, no agents
A guided stepper connects your Microsoft 365 tenant app-only, using a certificate that Admin Companion can generate and rotate for you. A test probe then records which permissions were actually granted and which license features were detected.
Every control, report and action is gated on that result - you're only offered what the grant and the license can genuinely support, instead of a wall of checks that will fail for permission reasons.
Sign-in supports TOTP, passkeys and recovery codes, and you can bring your own OIDC or Entra ID identity provider with claim mappings and credential-expiry monitoring.
Entra ID & Intune
Conditional Access, admin roles, PIM, devices, groups, compliance.
Exchange Online
Transport, mailbox audit, sharing and OWA policies.
Defender & Purview
Anti-phish, Safe Links, DLP, sensitivity labels.
Teams & SharePoint Online
Meeting, messaging and sharing policy, tenant settings.
Power Platform
DLP policies, environment settings, tenant isolation.
Fabric & Power BI
Admin tenant settings behind the baseline controls.