Accessing Microsoft 365 Posture
- Click Microsoft 365 in the sidebar
- Select the Posture tab
The Posture tab only appears when the CIPP integration is connected. See Configure CIPP Integration to set it up.
Prerequisites
- CIPP Integration - Connected in Settings, with the first sync completed
- Tenant Mapping - Microsoft 365 tenants mapped to companies during integration setup
- Permissions - Read Microsoft 365 permission
Posture Scorecards
The top of the page shows one headline card per domain, followed by detailed cards listing every metric in that domain. Each metric shows a value, a short explanation of why it matters, and a color-coded status indicator.Account Security
Who can sign in, and how well those sign-ins are protected
Email Protection
Defenses that keep phishing, impersonation, and data leaks out of mailboxes
Device Health
Whether the computers and phones used for work meet the security policy
Threats and Incidents
What was detected, what was blocked, and what is being handled
Managed For You
Protections the service provider actively maintains on the client’s behalf
Metrics by Domain
Reading the Metrics
- Counts lead, percentages follow. Coverage metrics display as “17 of 18 · 94%” so small environments read accurately.
- Color coding. Green means healthy, yellow and orange mean attention is warranted, red means action is needed. Informational metrics (counts of protections in place) carry no color judgment.
- No data yet. A metric shows “No data yet” until its source data has synced. A metric never shows a zero it cannot back up.
- Data as of. The timestamp above the scorecards shows when the data was last synchronized.
Items Needing Attention
Below the scorecards, the findings table lists the specific items behind the numbers. It shows exceptions only, never full inventory dumps, so every row is something worth looking at.
Click any row to open the details panel with the full context for that finding.
Reviewing Findings
Users with the manage Microsoft 365 permission can mark a finding as reviewed when it is expected or already handled, for example a sanctioned external forward or a scanner account that uses an older sign-in method.1
Open the Finding
Click the finding row to open its details panel.
2
Add Context
Optionally add a short note explaining why the item is expected.
3
Mark as Reviewed
Click Mark as reviewed. The finding is removed from the client view and no longer counts against the posture metrics.
Company users never see reviewed items. Keeping known-good exceptions reviewed keeps the page focused on what genuinely needs attention.
Company Scoping
The page follows the company selector. Select a single company to present its posture, or view the aggregate across your selected scope. Company users who sign in to the portal automatically see only their own organization, without company columns or filters.Best Practices
- Review new findings before a QBR. Mark sanctioned exceptions as reviewed so the client conversation stays focused on real gaps.
- Lead with the wins. The Threats and Incidents and Managed For You cards show the work being done on the client’s behalf: threats intercepted, standards enforced, policies maintained.
- Use metric click-through. Jumping from “Admins without MFA” straight to the named accounts turns a number into an action item.
Troubleshooting
Related Resources
Configure CIPP Integration
Connect and map the data source that powers this page
Microsoft 365 Secure Score
Track Microsoft Secure Score and remediation actions
M365 Licenses
Monitor license usage and spend
M365 Users
Browse Microsoft 365 user accounts