Skip to main content
Open Cloud > Posture > Current Posture to review synchronized Microsoft 365 management and security information from CIPP. This view is separate from Microsoft Secure Score and Google’s calculated checks. Audience: Company users with Microsoft 365 read access and MSP staff. The CIPP feature, integration, company mapping and synchronized data must be available. Company users ask their MSP to manage access and connections.

Open your company’s posture

  1. Open Cloud > Posture and choose Current Posture when available.
  2. Select one company in the top bar. Global View or several selected companies produces Select a company instead of combined scorecards.
  3. Expand Your Microsoft 365 posture if it is collapsed.
  4. Read the five headline measures and their detailed metrics, then review Items needing attention.
  5. Check Data as of and each finding’s timestamps before deciding what needs follow-up.
Current Posture does not aggregate several companies into one scorecard. Company users are restricted to their company. A missing Current Posture link can reflect feature or integration availability. An empty-data message is different from a successful check with no findings.

Understand the five areas

Each headline shows one metric, not a combined grade for every metric in that area. Coverage shows counts and a rounded percentage, such as 17 of 18 · 94%. A metric with unavailable evidence or no usable coverage denominator shows No data yet; its headline can show a dash. Colors are display thresholds: coverage is green from 75%, yellow from 50%, orange from 25%, otherwise red. Exception counts are green at zero; unused-account and external-forwarding counts allow one or two as yellow, while most other nonzero exception counts are red. Informational counts carry no health judgment. Green does not mean perfect coverage or prove there are no security issues.

Interpret what was counted

  • MFA coverage uses active, licensed member accounts and the supplied registration, per-user MFA, Security Defaults or enforced Conditional Access signals. It is not proof that every sign-in was challenged. The admin metric uses a different scope, so the counts need not match.
  • Domain protection requires stored SPF pass, DKIM enabled and DMARC present signals together, excluding onmicrosoft.com domains. It does not establish the strength of every policy.
  • Device compliance uses the stored compliance status. Device counts depend on collected CIPP datasets, not every possible endpoint inventory.
  • External forwarding checks the destination against known company Microsoft domains, as well as the provider signal. An unexpected result can need domain/mapping review.
  • Incidents and alerts use the stored status. Other count labels describe collected records; a standards or policy count does not prove every item is correctly enforced. These are not live monitoring totals or a guaranteed fixed reporting period.
Data as of is the latest relevant stored synchronization timestamp, not a guarantee that every dataset refreshed together. A partial sync or another dataset’s success can leave a seemingly available count with incomplete company evidence. Check missing or surprising values with the MSP. An empty list or zero must not be treated as proof that no incident occurred. MSP-reviewed findings are excluded from the overview’s calculations. For coverage metrics, this can change both the numerator and denominator. A changed percentage after review does not mean a provider security setting changed.

Follow up

Company users start with the Home AI Assistant. Include the company, metric or finding, timestamps and concern. MSP staff should verify the source before acknowledging an exception or changing configuration.

FAQs

Open Cloud > Posture > Current Posture when the CIPP feature and integration make it available. Select one company.
No. The current page requires one selected company. Global or multi-company scope shows Select a company.
No. Current Posture uses CIPP management and security datasets. Microsoft Secure Score and Google calculated checks are separate views.
No. Each area has one designated headline metric. Read its other metrics separately.
No. Green starts at 75% in the current display thresholds. Read the numerator, denominator and actual evidence.
No. It is the latest relevant stored timestamp. Datasets can have different ages or incomplete coverage.
Reviewed resources are excluded from calculations, which can change the numerator and denominator. Review does not itself change Microsoft configuration.
No. It means the metric has no usable evidence or coverage denominator. Ask the MSP to check the source and synchronization.
No. Counts reflect stored, scoped data and review exclusions. Confirm the relevant time period and source coverage with the MSP.
Ask the MSP to manage integration setup and permissions. Start with the Home AI Assistant if you need help with a finding.