Find a record
- Read the detailed metrics under Your Microsoft 365 posture.
- Select an available clickable metric to narrow Items needing attention to its related finding type. Move to the findings table below if it remains outside the visible area.
- Type a name or identifying phrase in the Finding column filter. Search also checks available descriptions, identifiers, company/tenant text and status/severity.
- Use pagination to move through results. The initial page size is 25; available sizes are 10, 25, 50 and 100.
- Click the row or its detail arrow to open the right-hand panel.
Know which metrics open findings
Available metrics can open these related datasets:
A metric must have available evidence to be clickable. The other metrics, including managed devices, sign-in policies, active alerts, intercepted mail and failed sign-ins, do not open their raw records from this reader. A summary count can therefore exist without a matching detail list.
The full findings table can also contain Outdated sign-in methods, Admin access, Suspicious inbox rules, Shared mailboxes allowing sign-in and Critical software weaknesses. These are selected source categories, not a complete inventory. Some categories include the supplied records for review rather than only records proved malicious. For example, an Admin access row is not itself proof of unsafe access.
Read the detail panel
Review the name and description, Provider context, and Posture signal. Context can include Company, Tenant, Tenant domain, Category, Dataset and Enabled. Signal includes Status, Severity, Last synced and, when supplied, Observed in source. Status in the table can show the severity label instead of the underlying source status. Read the detail fields separately. Unknown or an absent description means insufficient supplied information, not a safe result. Provider record IDs, source endpoints and raw Source payload are restricted by integration-settings read access. They are not available to every reader. The panel is not a provider configuration editor. Close it with its close control or Escape.What this table does not offer
Current Posture has no CSV/PDF export, checkbox bulk actions, manual sorting, standalone Status/Severity dropdown or arbitrary date/history selector. Use Finding search and supported metric filters. The table’s Type and Status columns are labels, not filtering controls. The current per-company page has no Company column/filter. Company users start with the Home AI Assistant for help; include the finding and timestamps. MSP staff can review or reopen a finding when permitted.FAQs
Why does clicking a metric do nothing?
Why does clicking a metric do nothing?
Only metrics with available evidence and a supported finding dataset are clickable. Other metrics are summary-only.
Does Admins without MFA open only administrator accounts?
Does Admins without MFA open only administrator accounts?
No. It opens the same People without MFA dataset as the coverage metric. That list is not an exact drilldown of the admin count.
Why does a finding-type filter appear above the table?
Why does a finding-type filter appear above the table?
It came from a metric selection. Use Clear finding type filter on its badge to remove it; Clear Filters handles the table text filter separately.
Why are results empty after selecting a metric on a later page?
Why are results empty after selecting a metric on a later page?
Metric selection currently preserves the page number. Return to page one and select the metric again before concluding there are no matching findings.
Can I filter Type or Status using their column headings?
Can I filter Type or Status using their column headings?
No. The current reader offers Finding text search and supported metric-driven finding-type filters, not separate Type or Status dropdowns.
Can I export all Current Posture findings?
Can I export all Current Posture findings?
This table has no CSV or PDF export. Secure Score has a separate management-permission CSV workflow.
Does every row represent a confirmed threat?
Does every row represent a confirmed threat?
No. The table contains curated source categories and review items. Admin access or a suspicious-rule category alone is not proof of malicious activity.
Why can my MSP see source payload details that I cannot?
Why can my MSP see source payload details that I cannot?
Provider IDs, endpoints and payload details require integration-settings read access. Normal Company readers do not receive that management detail.