Harbour ITMenu

Powered by Office Sentry 2.2.0

You're in the demo. Three fictional clients with made-up people. Look around freely: nothing can be changed, and it all resets every night.Get Office Sentry

All clients

Compare any report across every client you look after.
What changed this month
Clients
3
that you look after
With failing checks
3
of 61 checks
No data yet
0
every client has data

Every check 61

Pass Fail: criticalFail: highFail: mediumFail: low Accepted risk Not checked

Download XLSXCSV
IdentityAdminsAccountsLicencesEmailAppsTenant settingsSharingGuestsGroupsDevicesHybrid identityStorage
Contoso Legal LLP 1131312 MFA is enforced for all users: Fail (medium, 1) · Enforced by Require MFA for all users, with 1 exclusion to review Legacy authentication is blocked: Fail (high, 1) · Legacy authentication is allowed Every active user has MFA registered: Fail (high, 4) · 4 users without MFA No unexpected changes to how domains sign in: Fail (high, 1) · 1 domain had sign-in settings changed in the last 30 days Nobody relies on a text or call as their only second factor: Fail (low, 3) · 3 people can only use a text or call as a second factor No risky sign-ins succeeded: Not checked · Sign-in risk needs Entra ID P2 No accounts are at risk in Entra ID Protection: Not checked · Risky users need Entra ID P2 Every admin has MFA registered: Fail (critical, 2) · 1 admin without MFA, and 1 whose registration isn't known Between 2 and 4 Global Administrators: Pass · 2 Global Administrators No guests hold admin roles: Fail (high, 1) · 1 guest with admin roles Apps with admin roles are reviewed: Fail (medium, 1) · 1 app with privileged roles Every admin is covered by an MFA policy: Fail (high, 1) · 1 admin not covered by MFA Admins use phishing-resistant sign-in methods: Fail (medium, 2) · 2 admins without a phishing-resistant method No inactive accounts: Fail (medium, 2) · 2 accounts inactive for 90+ days or never used No account reports to a blocked manager: Fail (low, 1) · 1 account reports to a blocked manager No licences on disabled accounts: Fail (medium, 1) · 1 disabled account still licensed No paid licences sit unassigned: Fail (low, 2) · 2 subscriptions with spare licences Every licence assignment works: Pass · Every licence assignment worked No subscriptions are about to lapse: Pass · 2 subscriptions checked; none is lapsing No mail is forwarded outside the organisation: Fail (high, 3) · 3 external forwards No inbox rules hide mail: Fail (high, 1) · 1 suspicious inbox rule Automatic forwarding to outside addresses is off: Pass · The default outbound policy blocks automatic external forwarding Shared mailboxes can't be signed in to: Pass · All 3 shared mailboxes block sign-in Mailbox auditing is on: Pass · Mailbox auditing is on for the organisation SMTP AUTH is turned off: Fail (low, 1) · SMTP AUTH is on for the organisation Mail domains require encrypted delivery (MTA-STS): Fail (low, 1) · 1 of 1 mail domain doesn't fully enforce MTA-STS Encrypted delivery failures are reported (TLS-RPT): Not checked · TLS-RPT is checked on mail domains that use MTA-STS, and none do yet Every domain has a working SPF record: Fail (low, 1) · 1 domain with SPF problems Every domain enforces DMARC: Fail (medium, 2) · 2 domains without DMARC enforcement DKIM signing is on for every mail domain: Fail (medium, 1) · 1 mail domain without DKIM Third-party apps hold only the access they need: Fail (high, 1) · 1 app with access to mail, files or the directory Users can't consent to apps on their own: Fail (medium, 1) · Users can consent to any app App secrets and certificates are current: Fail (low, 1) · 1 app registration with expiring or expired credentials Users can't create new tenants: Not checked · Microsoft didn't return this setting Users can't register apps: Fail (low, 1) · Any user can register an app Guests have limited directory access: Pass · Guests have limited access to directory objects (the default) People can't join the tenant just by verifying an email address: Not checked · Microsoft didn't return this setting Users have a way to get apps approved: Pass · Users can consent to most apps themselves, so admin consent requests are off (see the user consent check) Files can't be shared with anonymous links: Fail (medium, 1) · Anyone, including anonymous links No files are shared with anyone links: Fail (high, 3) · 3 files and folders shared with anyone Every site has at least two owners: Fail (high, 3) · 1 site with no owner, 2 sites with one owner Guests don't have full control of sites: Fail (high, 1) · 1 guest with full control of 1 site People outside can only view shared files: Fail (medium, 1) · 1 file or folder outside people can edit Only admins and members can invite guests: Fail (low, 1) · Anyone, including guests, can invite guests No old, unaccepted guest invitations: Pass · No stale guest invitations No guest owns a team or group: Pass · No guest owns any of 9 teams and groups Every team and Microsoft 365 group has an owner: Fail (medium, 4) · 4 teams and groups without an owner Only chosen people can create teams and groups: Pass · Only admins and members of Group creators can create teams and groups Unused groups and teams expire: Pass · Unused teams and groups expire after 365 days Managed devices meet compliance policies: Fail (medium, 3) · 3 of 20 managed devices not compliant Company computers are encrypted: Fail (high, 2) · 2 of 19 computers not encrypted Windows computers still get security updates: Fail (high, 11) · 3 of 19 Windows computers past end of support Joined computers are managed by Intune: Fail (low, 1) · 1 of 20 joined computers not in Intune Managed devices check in with Intune: Fail (low, 2) · 2 devices haven't checked in for 30+ days No old devices left in Entra ID: Fail (low, 1) · 1 of 22 device records unused for 90+ days Directory sync is running: Not checked · Cloud-only tenant: directory sync isn't turned on Password hash sync is on: Not checked · Cloud-only tenant: directory sync isn't turned on Admin accounts are cloud-only: Pass · Cloud-only tenant: no accounts are synced from on-premises AD SharePoint storage isn't nearly full: Pass · 28% of about 1.18 TB used (1 TB + 10 GB × 18 licences) No mailbox is nearly full: Fail (medium, 3) · 3 mailboxes at or over 90% of quota No OneDrive is nearly full: Pass · None of 19 OneDrives is over 90% of its quota
Northwind Traders 1131312 MFA is enforced for all users: Fail (medium, 1) · Enforced by Require MFA for all users, with 1 exclusion to review Legacy authentication is blocked: Fail (high, 1) · Legacy authentication is allowed Every active user has MFA registered: Fail (high, 14) · 14 users without MFA No unexpected changes to how domains sign in: Fail (high, 1) · 1 domain had sign-in settings changed in the last 30 days Nobody relies on a text or call as their only second factor: Fail (low, 3) · 3 people can only use a text or call as a second factor No risky sign-ins succeeded: Not checked · Sign-in risk needs Entra ID P2 No accounts are at risk in Entra ID Protection: Not checked · Risky users need Entra ID P2 Every admin has MFA registered: Fail (critical, 2) · 1 admin without MFA, and 1 whose registration isn't known Between 2 and 4 Global Administrators: Pass · 2 Global Administrators No guests hold admin roles: Fail (high, 1) · 1 guest with admin roles Apps with admin roles are reviewed: Fail (medium, 1) · 1 app with privileged roles Every admin is covered by an MFA policy: Fail (high, 1) · 1 admin not covered by MFA Admins use phishing-resistant sign-in methods: Fail (medium, 2) · 2 admins without a phishing-resistant method No inactive accounts: Fail (medium, 4) · 4 accounts inactive for 90+ days or never used No account reports to a blocked manager: Fail (low, 1) · 1 account reports to a blocked manager No licences on disabled accounts: Fail (medium, 1) · 1 disabled account still licensed No paid licences sit unassigned: Fail (low, 2) · 2 subscriptions with spare licences Every licence assignment works: Pass · Every licence assignment worked No subscriptions are about to lapse: Pass · 2 subscriptions checked; none is lapsing No mail is forwarded outside the organisation: Fail (high, 4) · 4 external forwards No inbox rules hide mail: Fail (high, 1) · 1 suspicious inbox rule Automatic forwarding to outside addresses is off: Pass · The default outbound policy blocks automatic external forwarding Shared mailboxes can't be signed in to: Pass · All 3 shared mailboxes block sign-in Mailbox auditing is on: Pass · Mailbox auditing is on for the organisation SMTP AUTH is turned off: Fail (low, 1) · SMTP AUTH is on for the organisation Mail domains require encrypted delivery (MTA-STS): Fail (low, 1) · 1 of 1 mail domain doesn't fully enforce MTA-STS Encrypted delivery failures are reported (TLS-RPT): Not checked · TLS-RPT is checked on mail domains that use MTA-STS, and none do yet Every domain has a working SPF record: Fail (low, 1) · 1 domain with SPF problems Every domain enforces DMARC: Fail (medium, 2) · 2 domains without DMARC enforcement DKIM signing is on for every mail domain: Fail (medium, 1) · 1 mail domain without DKIM Third-party apps hold only the access they need: Fail (high, 1) · 1 app with access to mail, files or the directory Users can't consent to apps on their own: Fail (medium, 1) · Users can consent to any app App secrets and certificates are current: Fail (low, 1) · 1 app registration with expiring or expired credentials Users can't create new tenants: Not checked · Microsoft didn't return this setting Users can't register apps: Fail (low, 1) · Any user can register an app Guests have limited directory access: Pass · Guests have limited access to directory objects (the default) People can't join the tenant just by verifying an email address: Not checked · Microsoft didn't return this setting Users have a way to get apps approved: Pass · Users can consent to most apps themselves, so admin consent requests are off (see the user consent check) Files can't be shared with anonymous links: Fail (medium, 1) · Anyone, including anonymous links No files are shared with anyone links: Fail (high, 3) · 3 files and folders shared with anyone Every site has at least two owners: Fail (high, 3) · 1 site with no owner, 2 sites with one owner Guests don't have full control of sites: Fail (high, 1) · 1 guest with full control of 1 site People outside can only view shared files: Fail (medium, 1) · 1 file or folder outside people can edit Only admins and members can invite guests: Fail (low, 1) · Anyone, including guests, can invite guests No old, unaccepted guest invitations: Pass · No stale guest invitations No guest owns a team or group: Pass · No guest owns any of 9 teams and groups Every team and Microsoft 365 group has an owner: Fail (medium, 4) · 4 teams and groups without an owner Only chosen people can create teams and groups: Pass · Only admins and members of Group creators can create teams and groups Unused groups and teams expire: Pass · Unused teams and groups expire after 365 days Managed devices meet compliance policies: Fail (medium, 6) · 6 of 37 managed devices not compliant Company computers are encrypted: Fail (high, 4) · 4 of 36 computers not encrypted Windows computers still get security updates: Fail (high, 25) · 5 of 36 Windows computers past end of support Joined computers are managed by Intune: Fail (low, 1) · 1 of 37 joined computers not in Intune Managed devices check in with Intune: Fail (low, 3) · 3 devices haven't checked in for 30+ days No old devices left in Entra ID: Fail (low, 1) · 1 of 39 device records unused for 90+ days Directory sync is running: Not checked · Cloud-only tenant: directory sync isn't turned on Password hash sync is on: Not checked · Cloud-only tenant: directory sync isn't turned on Admin accounts are cloud-only: Pass · Cloud-only tenant: no accounts are synced from on-premises AD SharePoint storage isn't nearly full: Pass · 41% of about 1.31 TB used (1 TB + 10 GB × 32 licences) No mailbox is nearly full: Fail (medium, 3) · 3 mailboxes at or over 90% of quota No OneDrive is nearly full: Pass · None of 36 OneDrives is over 90% of its quota
Fabrikam Dental Group 1121512 MFA is enforced for all users: Fail (medium, 1) · Enforced by Require MFA for all users, with 1 exclusion to review Legacy authentication is blocked: Fail (high, 1) · Legacy authentication is allowed Every active user has MFA registered: Fail (high, 27) · 27 users without MFA No unexpected changes to how domains sign in: Fail (high, 1) · 1 domain had sign-in settings changed in the last 30 days Nobody relies on a text or call as their only second factor: Fail (low, 4) · 4 people can only use a text or call as a second factor No risky sign-ins succeeded: Not checked · Sign-in risk needs Entra ID P2 No accounts are at risk in Entra ID Protection: Not checked · Risky users need Entra ID P2 Every admin has MFA registered: Fail (critical, 2) · 1 admin without MFA, and 1 whose registration isn't known Between 2 and 4 Global Administrators: Pass · 2 Global Administrators No guests hold admin roles: Fail (high, 1) · 1 guest with admin roles Apps with admin roles are reviewed: Fail (medium, 1) · 1 app with privileged roles Every admin is covered by an MFA policy: Fail (high, 1) · 1 admin not covered by MFA Admins use phishing-resistant sign-in methods: Fail (medium, 2) · 2 admins without a phishing-resistant method No inactive accounts: Fail (medium, 7) · 7 accounts inactive for 90+ days or never used No account reports to a blocked manager: Fail (low, 1) · 1 account reports to a blocked manager No licences on disabled accounts: Fail (medium, 1) · 1 disabled account still licensed No paid licences sit unassigned: Fail (low, 2) · 2 subscriptions with spare licences Every licence assignment works: Pass · Every licence assignment worked No subscriptions are about to lapse: Pass · 2 subscriptions checked; none is lapsing No mail is forwarded outside the organisation: Fail (high, 5) · 5 external forwards No inbox rules hide mail: Fail (high, 1) · 1 suspicious inbox rule Automatic forwarding to outside addresses is off: Pass · The default outbound policy blocks automatic external forwarding Shared mailboxes can't be signed in to: Pass · All 3 shared mailboxes block sign-in Mailbox auditing is on: Pass · Mailbox auditing is on for the organisation SMTP AUTH is turned off: Fail (low, 1) · SMTP AUTH is on for the organisation Mail domains require encrypted delivery (MTA-STS): Fail (low, 1) · 1 of 1 mail domain doesn't fully enforce MTA-STS Encrypted delivery failures are reported (TLS-RPT): Not checked · TLS-RPT is checked on mail domains that use MTA-STS, and none do yet Every domain has a working SPF record: Fail (low, 1) · 1 domain with SPF problems Every domain enforces DMARC: Fail (medium, 2) · 2 domains without DMARC enforcement DKIM signing is on for every mail domain: Fail (medium, 1) · 1 mail domain without DKIM Third-party apps hold only the access they need: Fail (high, 1) · 1 app with access to mail, files or the directory Users can't consent to apps on their own: Fail (medium, 1) · Users can consent to any app App secrets and certificates are current: Fail (low, 1) · 1 app registration with expiring or expired credentials Users can't create new tenants: Not checked · Microsoft didn't return this setting Users can't register apps: Fail (low, 1) · Any user can register an app Guests have limited directory access: Pass · Guests have limited access to directory objects (the default) People can't join the tenant just by verifying an email address: Not checked · Microsoft didn't return this setting Users have a way to get apps approved: Pass · Users can consent to most apps themselves, so admin consent requests are off (see the user consent check) Files can't be shared with anonymous links: Fail (medium, 1) · Anyone, including anonymous links No files are shared with anyone links: Fail (medium, 2) · 2 files and folders shared with anyone Every site has at least two owners: Fail (high, 4) · 2 sites with no owner, 2 sites with one owner Guests don't have full control of sites: Fail (high, 1) · 1 guest with full control of 1 site People outside can only view shared files: Fail (medium, 2) · 2 files and folders outside people can edit Only admins and members can invite guests: Fail (low, 1) · Anyone, including guests, can invite guests No old, unaccepted guest invitations: Pass · No stale guest invitations No guest owns a team or group: Pass · No guest owns any of 9 teams and groups Every team and Microsoft 365 group has an owner: Fail (medium, 4) · 4 teams and groups without an owner Only chosen people can create teams and groups: Pass · Only admins and members of Group creators can create teams and groups Unused groups and teams expire: Pass · Unused teams and groups expire after 365 days Managed devices meet compliance policies: Fail (medium, 9) · 9 of 55 managed devices not compliant Company computers are encrypted: Fail (high, 6) · 6 of 54 computers not encrypted Windows computers still get security updates: Fail (high, 36) · 7 of 54 Windows computers past end of support Joined computers are managed by Intune: Fail (low, 1) · 1 of 55 joined computers not in Intune Managed devices check in with Intune: Fail (low, 5) · 5 devices haven't checked in for 30+ days No old devices left in Entra ID: Fail (low, 1) · 1 of 57 device records unused for 90+ days Directory sync is running: Not checked · Cloud-only tenant: directory sync isn't turned on Password hash sync is on: Not checked · Cloud-only tenant: directory sync isn't turned on Admin accounts are cloud-only: Pass · Cloud-only tenant: no accounts are synced from on-premises AD SharePoint storage isn't nearly full: Fail (medium, 6) · 88% of about 1.45 TB used (1 TB + 10 GB × 46 licences) No mailbox is nearly full: Fail (medium, 3) · 3 mailboxes at or over 90% of quota No OneDrive is nearly full: Pass · None of 54 OneDrives is over 90% of its quota

Results come from each client's latest collection, with the same checks as the monthly review. A failing or accepted check opens that client's findings for it. Pick a category to see its checks by name.