Read-only  ·  Runs on your workstation  ·  No agents

Know what changed.
Prove what you fixed.

EntraGUARD runs 323 implemented security controls against Microsoft 365, Entra ID, Azure and Active Directory — then turns the result into a report you hand a client under your own brand.

Sold once, at one fixed price. No subscription, no tenant cap, no revenue share.

audit comparison — contoso.com
A  03/14/2026B  06/20/2026
L1 Block legacy authentication protocols MICROSOFT ENTRA ID · CIS 1.2.4 COMPLIANT
L1 Require MFA for all administrative rolesREGRESSED MICROSOFT ENTRA ID · CIS 1.1.1 COMPLIANT
L2 Enable zero-hour auto purge for phishing MICROSOFT DEFENDER · CIS 2.1.6 WARNING
L1 Restrict guest access to directory objects MICROSOFT ENTRA ID · CIS 1.1.4 COMPLIANT
4 controls shown · 319 more in this audit
  • Never writes to a tenant
  • Nothing leaves your machine
  • 9 Microsoft services
  • CIS · NIST · ISO 27001 · ANSSI

The gap

A screenshot is not an audit trail.

Most Microsoft 365 reviews end the same way: a spreadsheet built by hand, a few portal screenshots, and no reliable way to answer the only question that matters three months later — did anything drift?

Manual review

Two days per tenant, and it ages instantly

Clicking through admin centers, copying settings into a sheet, formatting a document. The work is gone the moment a global admin changes one toggle.

Secure score

A number without a paper trail

Microsoft Secure Score moves for reasons you can't reconstruct or defend in an assessment. It isn't scoped per control, and it isn't yours to brand.

Enterprise platforms

Priced and built for one tenant

Posture management suites assume you own the environment. A consultant auditing eleven clients needs eleven isolated workspaces, not eleven subscriptions.

Coverage

323 controls. Every one of them runs.

No placeholders, no planned entries padding a marketing number. Each control in the catalog is backed by a live check against the Microsoft API, and returns a verdict with the objects it found.

85

Microsoft Entra ID

MFA, conditional access, privileged roles, guests, identity protection, device compliance

58

Active Directory

Domain policy, privileged groups, delegation, Kerberos, stale accounts, LAPS

54

Azure

RBAC, subscription owners, PIM, storage, networking, key vault, resource locks

31

Exchange Online

Mail flow rules, connectors, legacy protocols, forwarding, delegation, litigation hold

28

Microsoft Teams

External access, meeting policy, guest permissions, recording, app governance

22

Microsoft Defender

Safe Links, Safe Attachments, anti-phishing, impersonation, ZAP, quarantine

19

SharePoint

External sharing, anonymous links, unmanaged devices, custom script, site creation

17

Microsoft Purview

DLP coverage by workload, sensitivity labels, retention, insider risk, audit retention

9

OneDrive

Sync restrictions, retention after offboarding, file types, device policy

Each control carries a level — L1 for foundational, L2 for hardening — and the score weights them accordingly. A failed L1 costs three times a failed L2, because it should.

Framework mapping

Every control cites its source.

Auditors don't accept findings without a reference. Each control carries its CIS benchmark number, its NIST 800-53 family, its ISO 27001 annex clause — and where applicable, its ANSSI recommendation.

CIS Microsoft 365

277

controls mapped to the CIS benchmark

ISO 27001 A.8

215

technological controls

NIST AC

128

access control family

ISO 27001 A.5

103

organizational controls

NIST IA

40

identification & authentication

ANSSI

20

French national recommendations

Built for service providers

You audit other people's tenants. The tool should know that.

EntraGUARD was written for consultants and managed service providers first. Every client lives in its own workspace — separate connectors, separate history, separate reports — and you move between them in one click.

Isolation

One workspace per client

Connectors, audit history, saved baselines and report branding are stored per company. Nothing crosses over, and no dashboard ever mixes two clients' data.

White label

Your logo on the cover, not ours

Set your firm's name, website and logo once. Every exported report carries your identity in the header and footer — and the audited company's own logo on the executive cover page.

Reusable scope

Baselines you build once

Include or exclude any control, adjust its level, save it as a baseline — global across every client, or specific to one engagement. Eight framework templates ship with it. See the editor.

The product

A desktop application, not a portal.

It installs on Windows, authenticates to the tenants you choose, and keeps every byte of evidence on the machine you control.

EntraGUARD dashboard showing overall compliance and per-service scores

Posture at a glance

A weighted score per service, ranked from weakest to strongest, plus a trend line that carries each service's last known result forward — so a targeted re-audit never fakes a drop.

Comparison between two audits highlighting regressions and improvements

What changed since last time

Pick two runs. Regressions come first — controls that were compliant and no longer are. Improvements, additions and scope changes follow. This is the slide that renews an engagement.

Client list with per-company audit counts and scores

Your whole book of business

Every client in one table: last audit, current score, connectors configured. Sort it, search it, and open any engagement without touching another one's data.

Control catalog grouped by category with level badges

The catalog, open to inspection

Browse all 323 controls before you run anything. Each shows its category, level and framework mapping, so you can tell a client exactly what you will and won't be testing.

Connector configuration screen for Microsoft services

Connect only what you need

Each service has its own connector. Audit Entra ID alone on Monday and add Exchange next month — controls without a configured connector are skipped, and the app says so rather than failing quietly.

Scoping

Not every audit should run all 323 controls.

A first pass, an ISO 27001 certification file and a monthly re-check are three different questions. A baseline is how you decide in advance — and in writing — which controls a given engagement answers, so the scope is a deliberate decision rather than whatever the tool happened to test.

Baseline editor: control list with include checkboxes, referential column and per-control level override

The baseline editor

Include or exclude any control, and override its level where your judgment differs from the default. Three counters — active, excluded, re-levelled — show how far the scope has moved from the full catalogue, and modified only filters straight to what you changed. Nothing is committed until you save: an unsaved baseline is flagged as a draft.

Template gallery showing framework templates with the number of controls kept and how many are runnable

Eight templates to start from

Each template keeps the controls mapped to a framework and excludes the rest. The count is computed from the live catalogue rather than written into a brochure — and a second figure tells you how many of those controls are actually runnable given the connectors you have configured, so you know what a template will really cover before you commit to it.

Scope

Global, or specific to one client

A global baseline is your firm's house methodology, reused on every engagement. A client baseline covers the exception you agreed with one customer — the control they have formally accepted the risk on — without polluting anyone else's audit.

Levels

Severity is a judgment call, so it's editable

A control that is standard in a fifty-seat firm can be critical in a regulated one. Re-level it per baseline and the weighting in the score and the remediation ordering follow, with the count of re-levelled controls visible so a reviewer can see you did it.

Traceability

The baseline is recorded with the run

Applying a baseline to an audit stores which controls were in scope and at what level. Two audits run under the same baseline are directly comparable; a scope change shows up in the comparison instead of quietly distorting the score.

Templates in the box

CIS Microsoft 365 Benchmark

The most widely recognised baseline for a Microsoft 365 audit, and the one most clients have heard of.

277 kept173 runnable

CIS — level 1

The fundamentals only: recommendations applicable without notable functional impact.

128 kept79 runnable

Level 1 only

Level 1 controls across every framework. The sensible first pass on a tenant you have never audited.

144 kept85 runnable

ISO 27001 — technological controls

Annex A.8: configuration, encryption, logging, network protection.

215 kept117 runnable

ISO 27001 — organisational controls

Annex A.5: policies, access management, supplier relationships, compliance.

103 kept73 runnable

NIST — access control

The AC family: who accesses what, with which privileges, under which conditions.

128 kept89 runnable

NIST — identification and authentication

The IA family: MFA, phishing-resistant methods, credential management.

40 kept27 runnable

ANSSI

Controls mapped to ANSSI recommendations — a narrow scope, useful in a French regulatory context.

20 kept0 runnable

One honest detail the app states on that screen: ISO 27001 and NIST map to the entire catalogue, so a template built on either framework as a whole would filter nothing at all. Those two are therefore offered at control-family level, where they actually narrow the scope. Every template is a starting point — create a baseline from it, then edit it.

Running an audit

One click, then sixteen seconds.

The scope is already decided by the baseline, so starting an audit is a single button. What follows is not a progress bar you leave running over lunch: 194 controls across six Microsoft services, evaluated live, with each finding appearing the moment it is produced.

Audit in progress: overall percentage, per-service counters and controls being analysed with their status

You watch it work

A counter per service and one overall — 81 / 194 here — with the controls streaming past as they are evaluated. Each row carries its service, its level and its verdict, and a finding that needs explaining gets its sentence immediately: "7 service principals hold a directory role: these identities escape MFA and PIM, their justification must be documented." Nothing is buffered until the end.

Completed audit showing 100% done, compliance score, compliant, non-compliant and warning counts, and duration

And it tells you how long it took

Done: 51 % compliance, 64 compliant, 48 non-compliant, 82 warnings — in 16.1 seconds. The header keeps 194 / 323 controls enabled in view throughout, so a partial run can never be mistaken for a full one, and one click goes straight to the detail.

Audit detail: counters for controls, compliance, compliant, non-compliant and warnings, filters, HTML and PDF export, and an expanded control showing result, description, remediation and framework references

Then every control, one click deep

Five counters across the top, a search box and filters by referential and by level. Open a row and you get what an assessor has to write anyway: the observed state — "Microsoft Authenticator enabled (number matching enforced by Microsoft)" — what the control tests, the remediation as a portal path, and the references it satisfies: CIS Entra ID · NIST IA-2 · ISO 27001 A.8.5. Export is HTML or PDF, and the screen states that it covers the whole audit rather than the filtered view.

Audit history listing each run with its scope, score, counts and trend against the previous run

Every run is kept, with its scope

Date, number of controls evaluated, the services actually included, the score and the three counts — plus the movement against the previous run, already computed. A run over 19 controls sits next to one over 194 and is visibly not the same exercise, which is exactly what you want before you compare them.

Three outcomes

Compliant, non-compliant, or a judgment call

82 of those 194 results are warnings — a setting that isn't a failure but that an assessor should look at, like certificate-based authentication being disabled. A pass/fail tool has to round every one of those in some direction; here they stay visible as what they are.

Trend

Movement without arithmetic

Each history entry shows how it moved against the run before it — stable, up two points, down thirteen. You know whether last month's remediation worked before opening anything, and the full comparison is one button away.

Export

The whole audit, not the filtered view

HTML and PDF from the results screen, and the app states plainly that the export covers the entire audit rather than whatever your current filter shows — a small thing that stops a client receiving an accidentally truncated report.

Performance

Sixteen seconds is a setting, not luck.

Controls are evaluated in parallel. The right number at once depends on the workstation and on how much load the Microsoft APIs will tolerate — so instead of hard-coding a guess, the application exposes the setting and measures the correct value on the machine that will actually run the audits.

Performance settings: concurrent analysis thread slider and a parallelism benchmark comparing run times at 1, 2, 4, 8 and 16 threads
Settings › Performance — the thread slider and the on-device benchmark.
  1. Eight controls at a time, adjustable from one to sixteen

    The default suits most machines. Lower it on a constrained VM or a fragile tenant, raise it on a workstation with headroom — it takes effect on the next run, with nothing to reconfigure.

  2. Throttling is accounted for, not ignored

    The screen states the trade-off plainly: more threads means more load on the APIs and a real throttling risk. The network connectors — Graph, Azure, Exchange — self-limit regardless of where you put the slider, so a high setting degrades speed rather than breaking a client's tenant.

  3. A benchmark that runs on your hardware

    One click simulates an audit at each thread level and times it. On the machine in that screenshot: 0.99 s sequential, 0.34 s at eight threads — 2.9× faster — and slower again at sixteen. The curve is measured, not assumed, so the tool recommends eight instead of maxing the slider, and applies it for you.

This is the mechanism behind the sixteen-second run in the section above, and it is the kind of thing that decides whether an auditor uses a tool twice. Anyone who acquires the product gets the knob and the benchmark along with the rest of the source.

What you hand over

Four reports, four audiences.

The same audit produces the document each reader actually needs — from a one-page board summary to a line-by-line remediation plan an engineer can work through.

Executive summary

Cover page under your brand and the client's, overall posture, per-service breakdown, and the findings that matter to a board.

PDFHTMLXLSXCSVJSON

Detailed audit

Every control, its verdict, the objects concerned, and the reference it was tested against.

PDFHTMLXLSXCSVJSON

Framework compliance

The same results re-cut by CIS, NIST, ISO 27001 and ANSSI — the view an assessor asks for.

PDFHTMLXLSXCSVJSON

Remediation plan

Failures ordered by weight, with the portal path and PowerShell command for each fix.

PDFHTMLXLSXCSVJSON
Export settings: report type selector and toggles for CSV, JSON, Excel, HTML and PDF output formats
Report type and format are separate decisions. The four reports above are the four types on that screen; the five formats are independent toggles, so whichever report you choose comes out in whichever formats you have enabled. Turn off what your practice never sends and the export buttons stop offering it. CSV and Excel are for the audit that ends in a spreadsheet, JSON for feeding a SIEM or an automation, HTML and PDF for what the client actually receives.

How an engagement runs

First audit in an afternoon.

Add the client

Create the company record. Its name is what appears on every report you export for them.

Connect the services

Register a read-only application in the tenant — the app walks you through it — or point it at an existing one. Add Active Directory over LDAPS if the client runs a hybrid estate.

Choose the scope

Run the full catalog, or apply a baseline: CIS level 1 for a first pass, ISO 27001 technological controls for a certification file, or your own saved selection.

Run it and deliver

The audit executes read-only against the APIs. Export the report your client needs, under your brand, and keep the run in history for the next comparison.

Security & privacy

The audit tool shouldn't be the weak link.

You're asking a client for access to their identity platform. Here is exactly what happens to it.

Read-only

Every check is a read. The application holds no write permission and changes no setting in any tenant — a client can verify it on their own consent screen.

On your machine

No vendor backend, no telemetry, no upload. Audit results, findings and reports are written to your workstation and go nowhere else.

Encrypted secrets

Client secrets and service account passwords are encrypted with Windows DPAPI, scoped to your user account. A copied settings file is unreadable elsewhere.

Retained evidence

Audit history is kept for three years — a full ISO 27001 certification cycle — so you can show a trajectory, not just a snapshot.

Under the hood

Written for the engineer who has to approve it.

The person who decides whether an audit happens is rarely the person who commissioned it. It is the client's IT or security lead, who will want to know what gets installed, what it is allowed to touch, and what happens on a tenant considerably larger than a demo.

Windows desktop Microsoft Graph API Azure Resource Manager OAuth 2.0 client credentials Certificate authentication LDAP / LDAPS Windows DPAPI Local storage, no backend HTML · PDF · XLSX · CSV · JSON

Delivery

An executable, not a platform

A Windows desktop application. There is no server to stand up, no agent to deploy on endpoints or domain controllers, no inbound firewall rule and no service account running permanently somewhere. It runs under the consultant's own session, for as long as the audit takes, and then it stops.

Data path

Workstation to Microsoft, and nowhere else

Outbound HTTPS to Microsoft endpoints and, for on-premises audits, LDAP or LDAPS to a domain controller. Results are written to a local store on the machine that ran the audit. There is no vendor backend in the path, so there is no third party to add to a client's processor register.

Execution

Parallel, throttling-aware, deterministic

Controls are evaluated concurrently with a configurable thread count, and the Graph, Azure and Exchange connectors self-limit regardless of that setting, so an aggressive configuration slows the audit instead of tripping API throttling on a client's tenant. The same baseline evaluates the same controls in the same order every time.

Scale

Tested where it matters

Run against production tenants with several thousand users, where collections have to be paged rather than fetched in one call and where a naive implementation either times out or silently truncates. Directory size changes how long the paging takes; it does not change which controls run or what they conclude.

Partial coverage

Missing connector, honest result

Audit only Entra ID today and add Exchange next month. Controls with no configured connector are reported as out of scope and counted as such, never as failures — the compliance score is computed on what was actually evaluated, and the run states how many controls that was.

Credentials

Encrypted, per user, per client

Certificates, client secrets and service account passwords are encrypted with Windows DPAPI scoped to the user account, stored per client workspace. A settings file copied to another machine is unreadable, and one client's credentials are never loaded while auditing another.

What each connector is granted

Connector Authenticates as Rights required Write access
Microsoft Entra ID An application registered in the client tenant, authenticating by certificate. Provisioning can be automatic, or the registration can be created by hand; a client secret is supported but discouraged, because secrets expire. Directory.Read.AllPolicy.Read.AllRoleManagement.Read.AllReports.Read.AllAuditLog.Read.All
Five read scopes, granted once, visible on the client's consent screen.
None
Microsoft 365 workloads The same Entra ID application — Exchange Online, Teams, SharePoint, OneDrive, Defender and Purview checks reuse it. No additional grant, and no second credential to store or rotate. None
Azure The same application, assigned through Access control (IAM) on the subscription or management group. The built-in Reader role. Nothing else — not Contributor, not Security Admin. None
Active Directory A domain account, reaching a domain controller over LDAP (389) or LDAPS (636). Standard read access. No Domain Admin, no delegation, no privileged group membership — and if the domain controllers have no certificate for LDAPS, that is itself one of the findings. None

The column that matters is the last one. Not “write access we promise not to use” — write access that was never requested, which is why a client can verify the claim on their own consent screen in about fifteen seconds rather than taking your word for it.

For auditors & assessors

Evidence, not opinion.

An assessment stands or falls on whether someone else can re-run it and reach the same conclusion. EntraGUARD was built around that constraint: every verdict carries the control it came from, the objects it looked at, and the date it was taken.

Traceability

Every finding names its objects

A non-compliant control doesn't just say "fail". It lists the accounts, mailboxes, policies or resources that caused it, timestamped and attributed to the tenant it was read from — the level of detail a working paper actually needs.

Reproducibility

Same baseline, same result

Scope is declared as a baseline and stored with the run. A second assessor applying the same baseline to the same tenant evaluates the same 323 checks in the same order, and any difference is a real change in the environment.

Independence

Read-only, so it can't disturb what it measures

The tool holds no write permission, so running an audit never alters the environment under assessment and never competes with the client's own change process. The consent screen is the proof.

Framework view

Re-cut by CIS, NIST, ISO 27001 and ANSSI

The same run produces a compliance view per framework, with the clause reference on each control — so a certification file, a client questionnaire and a gap analysis all come out of one execution.

Working papers

CSV and JSON, not just PDF

Results export as structured data for sampling, for a GRC platform, or for whatever spreadsheet your methodology already runs on. Nothing has to be retyped out of a report.

Continuity

Three years of history

Runs are retained for a full ISO 27001 certification cycle, so a surveillance audit can be answered with a trajectory — what was found, what was fixed, and when — instead of a fresh snapshot.

Why now

The demand isn't a trend. It's a calendar.

Microsoft 365 and Entra ID are the identity layer for most organisations, credentials are how most intrusions now begin, and a run of regulations has turned “we take security seriously” into “show us the evidence.” None of those three reverses next year, which is what separates a market from a wave.

The install base

Everyone is a candidate

Entra ID is the front door to mail, files, Teams and increasingly to the cloud infrastructure behind them. Auditing identity means auditing the thing everything else depends on — and there is no vertical to specialise into, because the tenant is the same shape at a law firm, a hospital and a manufacturer.

The attack path

Intrusions start with a valid login

Incident reporting has converged on the same finding for several years running: attackers increasingly sign in rather than break in. That moves identity configuration out of IT hygiene and into the first question an insurer, a board or a forensic team asks after an incident — and the first one asked before it.

The obligation

Evidence, on a deadline

NIS2, DORA, ISO 27001:2022, SOC 2, CMMC, HIPAA. Different scopes and different regulators, one shared requirement: documented, repeatable proof that access controls are configured the way you say they are. A screenshot pasted into a Word document stopped being an answer.

The bottleneck

Demand is not the constraint

The organisations being asked mostly cannot answer for themselves, so they ask their MSP or their consultancy — who answer by hand, in a spreadsheet, over two days per tenant. What limits this market is not appetite. It is the number of people who can produce the evidence, which is exactly what a tool changes.

NIS2EU Directive 2022/2555

Member states had to transpose it by October 2024; national enforcement has been ramping since. It pulls in far more mid-sized entities than the directive it replaced, and requires risk management measures to be demonstrable rather than declared.

DORAEU Regulation 2022/2554

Applicable since January 2025 to EU financial entities and, critically, to their ICT service providers. Access control and authentication sit squarely inside the resilience requirements.

ISO 27001:2022Annex A.5 and A.8

Certificates issued against the 2013 version had to migrate by October 2025. The 2022 Annex A puts configuration, access management and logging explicitly in scope — the exact ground a tenant audit covers.

CMMCUS Department of Defense

Phased into defense contracts from 2025, flowing down the supply chain to companies with no security team at all. Access control and identification and authentication account for the largest share of the requirements.

SOC 2 · HIPAAongoing, and tightening

Neither is new, but the evidence bar keeps rising: anyone selling software to a US enterprise is asked for CC6 and CC7 evidence, and any organisation touching health data is asked for its technical safeguards in writing.

Deliberately absent from this section: a market-size forecast. Anyone can buy one, nobody can verify it, and every line above can be checked against a published text instead. The point is not that the market is large — it is that the obligations have dates on them, and the people being asked still answer by hand.

For resellers & consultancies

Buy it once, then sell it as your own product.

Most Microsoft-focused resellers and consultancies sell licenses, migrations and managed services, then subcontract the security review. Here you are not becoming someone's reseller — you are buying the product and adding an audit line to your own catalog, priced however you want.

Your price list

You decide what an audit is worth

Charge per audit, per tenant, per quarter, or fold it into an existing retainer. Nobody sets a floor, nobody sets a ceiling, and no part of what you invoice comes back to us.

Your economics

One capex line, then pure margin

A single fixed cost paid once, against revenue that repeats on every engagement. The tenth audit you sell costs you nothing to deliver beyond your engineer's time.

Your organisation

Deploy it as widely as you like

Every consultant, every office, every legal entity in the group. There is no seat count to declare and no license server to check in with.

Your methodology

Bend the product to how you work

With the source code you can add your own controls, restructure the report to match your existing deliverables, or export straight into the GRC platform your practice already runs on.

Your clients

No vendor behind you

We never appear in front of your clients, because after the sale there is no relationship to appear in. No co-branding to negotiate, no deal registration, nobody to lose the account to.

Your differentiation

A product your competitors don't have

Competing firms bid the same subcontracted review at the same day rate. A tool carrying your own name, producing evidence in a day, is a different conversation in a tender.

Your sales machinery

You issue the licence keys. We never see your clients.

Selling the product under your own name only works if you can hand a key to a customer without asking anyone's permission. The generator that produces those keys is part of what you buy — a separate tool you keep, alongside the activation screen your customers see.

Licence generator: client name, validity in days, maximum tenants, generate, copy or save to license.key

The generator, delivered with the product

A client name, a validity in days — 365 for a year, 3650 for ten — and a tenant ceiling. Generate, copy, or write it straight out as license.key. Every commercial decision you make is expressed in those three fields, which means your price list can be whatever you want it to be: annual, multi-year, metered by tenant, or a fortnight's trial for a prospect.

Activation screen showing licence status with client name, expiry date, allowed tenants and identifier, plus a field to paste a new key

What your customer does with it

Paste, activate, done — operational immediately, with no restart. From then on the status card states plainly who the licence belongs to, when it expires, how many tenants it allows and its identifier, so a support call starts with facts rather than questions. Nothing here carries our name.

Your terms

Duration and tenant count, per key

The two fields that decide what a licence is worth are yours to set on every sale. A one-year, five-tenant key for a small consultancy and a ten-year unlimited one for a group are the same amount of work: fill in two boxes.

Your ceiling

Unlimited for you, metered for them if you want

The tenant cap exists so you can meter what you sell — 9999 is unlimited in practice, and that is what your own key looks like. Whether your customers get the same or a counted allowance is a pricing decision, not a product limitation.

Your pipeline

No activation goes through us

You generate keys on your own machine. We are not in the loop, which means no waiting on our office hours to close a deal, and no list of your customers sitting in someone else's records.

Your trials

A demo key costs you nothing

Issue a fourteen-day key to a prospect and let them audit their own tenant. It expires by itself, so there is no licence to chase and no reason to be cautious about handing out evaluations.

Price & ownership

One price. One transaction. It's yours.

There is no licensing ladder, no tenant count to declare, no renewal and no revenue share. You buy EntraGUARD once, at a fixed price that is the same for everyone. After that you rebrand it, modify it, price it and run it exactly as your organisation decides — we have no say in it and take nothing further.

One-off · perpetual · unlimited

€00,000

Paid once. Nothing is owed afterwards — no annual fee, no royalty, no per-client charge, no reporting obligation.

  • The application, packaged and ready to distribute
  • Full source code and build chain
  • The 323-control catalog with its CIS, NIST, ISO 27001 and ANSSI mappings
  • Report templates and technical documentation
  • Complete rebranding: name, logo, icons, installer, domain
  • The licence generator, so you issue keys to your own clients
  • A transition period with the author

Yours in name

Nothing refers to us

Product name, logo, icon set, installer, in-app identity, documentation and every exported report carry your brand. Once delivered, the word EntraGUARD appears nowhere in what you ship.

Yours to modify

Source code, not a black box

Add controls, change the report layout, plug it into your GRC stack, extend the connectors, take it in a direction we never planned. Your engineers own the codebase and need no permission.

Yours to sell

You set the prices

Per audit, per tenant, bundled into a retainer, or given away to win the migration behind it — your commercial model, your contracts, your margin. We take no share of anything you invoice.

Yours to run

No limit to declare

Unlimited tenants, unlimited clients, unlimited engineers, unlimited installations, in as many offices or entities as you have. Nothing meters your use and nothing expires.

How it runs: a mutual NDA, a technical review so you see exactly what you are buying, one contract, then handover. Ongoing maintenance — Microsoft API changes, CIS revisions, new controls — is available as a separate annual contract if you want it, and entirely optional: the product you bought keeps working either way.

For investors & acquirers

What is actually being sold.

The market case is set out above. What is on the table here is a finished, shipping product positioned inside it: the asset is the control catalog, the framework mappings and the engine that runs them.

323

Implemented controls

Every one backed by a live API check — the catalog is the barrier to entry, and it took years of Microsoft-specific work

9

Microsoft services

Entra ID, Active Directory, Azure, Exchange, Teams, Defender, SharePoint, Purview, OneDrive

4

Frameworks mapped

CIS, NIST 800-53, ISO 27001 and ANSSI — the mapping layer is what makes the output sellable to auditors

0

Cloud infrastructure

Desktop delivery means no hosting cost, no data-processor liability and gross margin that doesn't degrade with volume

The market

Sold to the people who audit, not the people audited

MSPs, consultancies and audit firms buy the product outright and monetise it across their whole client portfolio — a single high-ticket transaction instead of a per-seat grind, with an optional annual maintenance contract behind it.

Defensibility

The catalog is the moat

Building 323 working checks across nine Microsoft APIs, then keeping them aligned with CIS revisions and Microsoft's own changes, is slow work that cannot be shortcut with a wrapper around Secure Score.

Expansion

Adjacent products already scoped

The same connectors and control model extend to guest lifecycle governance, continuous monitoring and a hosted multi-tenant portal — near-term additions rather than a second product to invent.

What transfers

Code, catalog, brand and domain

A transaction can cover the source code and IP, the control catalog and its framework mappings, the report templates, the EntraGUARD name and domains, and a defined transition period with the author.

Structures

Outright, majority, or a build partnership

Full acquisition, an equity stake with the founder continuing development, or a funded roadmap with exclusive distribution rights — the structure is open.

Diligence

Data room under NDA

Financials, customer detail, roadmap, architecture documentation and a technical walkthrough of the codebase are available to qualified parties once an NDA is in place.

Serious enquiries only, please — use the form below and select Investment or acquisition. An NDA can be executed the same week.

After the purchase

You own it outright. That doesn't mean you're on your own.

Nothing in the agreement obliges you to come back to us, and nothing in the product requires it — you have the source, the build chain and the documentation. But the engineers who wrote it are still available, and most buyers would rather have a change built in a week than staffed internally in a quarter.

Engineers at work in front of a wall of screens showing EntraGUARD audit views

Evolution requests

Ask for a change, get a build

A new control, another connector, a different report layout, an export one of your clients insists on. You could do it yourself — the code is yours — but the engineers who built the 323-control catalogue will do it faster, and hand it back as a build you can ship.

Documentation

A complete guide, and the technical set

An end-to-end application guide you can put your own cover on and hand to your consultants or your clients, plus what your engineers need: architecture, control catalogue, connector model, build and release process.

Web presence

A professional site for the product under your name

Exactly what you are reading. This page is the example: a one-page site built around the product, its screenshots and its argument — rebuilt under your brand, your name and your positioning, ready to publish.

Content

And a blog, if you want to be found

What makes a site like this rank is not the design but what sits behind it — the fourteen articles already published here are the example. We can write and structure the content — Microsoft 365 auditing, CIS benchmarks, Entra ID hardening — for a product that carries your name rather than ours.

All of it is optional and quoted separately. The purchase price covers the product: none of these are gates you have to pay to get through, and the application works without a single one of them.

Questions we get

Before you commit.

Does it need Global Administrator?

No. The audit runs on read-only Microsoft Graph permissions. A Global Administrator is only needed once, to consent to the application registration — the same consent any read-only tool requires. After that, the audit account holds no privileged role.

How many tenants does it cover?

There is no limit, because there is nothing to meter. The application manages client companies side by side, each with its own connectors, history and branding, and the purchase covers as many as you ever open — one or five hundred.

Exactly which permissions are we granting?

Five read scopes on Microsoft Graph — Directory.Read.All, Policy.Read.All, RoleManagement.Read.All, Reports.Read.All and AuditLog.Read.All — plus the built-in Reader role if you audit Azure, and a standard read-only domain account for on-premises Active Directory. No write scope is requested anywhere, which your client can confirm on their own consent screen. The full table is here.

Does anything leave our network?

Only the API calls to Microsoft, made from your workstation. There is no vendor backend, no analytics, and no upload of findings. Reports are files on your disk until you choose to send them.

What if a client runs on-premises Active Directory?

It's covered — 58 controls over domain policy, privileged groups, delegation, Kerberos and stale accounts, queried over LDAP or LDAPS with a read-only service account.

Can we add our own controls?

Yes. The catalog loads from control packs, and you can import additional packs alongside the official ones. Custom checks can be defined declaratively against Graph, ARM or LDAP.

How long does an audit take to run?

Seconds, not hours. A 194-control run across six Microsoft services completes in about sixteen seconds on a normal workstation, because the controls are direct API reads rather than scripts spawning sessions. The time in an engagement goes into consenting the connectors and reading the findings, not waiting for the tool.

Does running controls in parallel risk throttling a client's tenant?

No. The connectors that talk to Graph, Azure and Exchange self-limit whatever you set the thread count to, so the worst case of an over-ambitious setting is a slower audit rather than a throttled tenant. The default is eight concurrent controls, adjustable from one to sixteen, and a built-in benchmark measures the optimum on your own machine.

Can we see it working before buying?

Yes, and you should. We run a full audit against one tenant of yours, with your engineers watching, and you keep the reports whatever you decide afterwards. For a purchase of this kind there is also a technical review of the codebase before signature.

Is there really only one price?

Yes. One figure, the same for a two-person consultancy and for a group with forty offices, covering the product, the source code and the right to exploit it commercially without restriction. There is no tier above it and nothing held back to sell you later. The only optional extra is an annual maintenance contract, and the product works without it.

Is the source code included?

Yes, in full, with the build and packaging chain, the control catalog and its framework mappings, the report templates and the technical documentation. You are not licensing a binary — your engineers can compile, modify and extend it without asking us anything.

How do our own clients activate it?

You generate the key yourself, with the licence generator that ships with the product: a client name, a validity in days and a maximum number of tenants. Your customer pastes it into the activation screen and the application is operational immediately, with no restart. We are not involved in any of it and never learn who your customers are.

Can we resell it to our own clients?

You can do better than resell it: you own it, so you sell your own product at your own price under your own name. There is no reseller agreement, no margin schedule and no revenue share, because after the purchase there is nothing linking your sales to us.

Is there any support after the sale?

Yes, and all of it optional. Our engineers take evolution requests on demand — new controls, new connectors, report changes — and we can supply a complete application guide, the technical documentation, a professional website for the product under your name, and the blog content behind it. Priced separately; the product needs none of it to work.

Are you open to investment or an acquisition?

Yes, and to structures short of a full sale — an equity stake, a funded roadmap, or exclusive distribution. Financials, architecture documentation and a code walkthrough are available under NDA. Ask through the form and say which structure interests you.

Get the terms

One price, and nothing hidden behind it.

Ask and you get the figure, the contract and what happens on handover — not a discovery call to qualify you first. Answers usually come the same business day.

  • The price, in writing, with the contract terms
  • A mutual NDA, signed the same week if you want one
  • A live audit on one of your own tenants before you decide
  • A technical review of the codebase before signature
  • Sample reports from a real audit, under your brand

Sent straight to us — no mail client needed.
Prefer to write directly? sales@entraguard.com