> ## Documentation Index
> Fetch the complete documentation index at: https://docs.msportal.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Microsoft 365 Posture

> Give clients a clear, plain-language view of how their Microsoft 365 environment is protected and managed

The Posture page answers the questions clients actually ask: Is MFA on for everyone? Is our email safe? Are our devices protected? Did anything bad happen? It turns Microsoft 365 security and management data into scorecards and findings written in plain business language, making it a natural surface for QBRs and for clients who sign in to the portal themselves.

## Accessing Microsoft 365 Posture

1. Click **Microsoft 365** in the sidebar
2. Select the **Posture** tab

<Note>
  The Posture tab only appears when the CIPP integration is connected. See [Configure CIPP Integration](/user-guides/integrations/enable-cipp-integration) to set it up.
</Note>

## Prerequisites

1. **CIPP Integration** - Connected in Settings, with the first sync completed
2. **Tenant Mapping** - Microsoft 365 tenants mapped to companies during integration setup
3. **Permissions** - Read Microsoft 365 permission

## Posture Scorecards

The top of the page shows one headline card per domain, followed by detailed cards listing every metric in that domain. Each metric shows a value, a short explanation of why it matters, and a color-coded status indicator.

<CardGroup cols={2}>
  <Card title="Account Security" icon="user-check">
    Who can sign in, and how well those sign-ins are protected
  </Card>

  <Card title="Email Protection" icon="envelope-circle-check">
    Defenses that keep phishing, impersonation, and data leaks out of mailboxes
  </Card>

  <Card title="Device Health" icon="laptop">
    Whether the computers and phones used for work meet the security policy
  </Card>

  <Card title="Threats and Incidents" icon="shield-halved">
    What was detected, what was blocked, and what is being handled
  </Card>

  <Card title="Managed For You" icon="hand-holding-heart">
    Protections the service provider actively maintains on the client's behalf
  </Card>
</CardGroup>

### Metrics by Domain

| Domain                    | Metrics                                                                                                                                          |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Account Security**      | People protected by MFA, Admins without MFA, Sign-in protection policies, Unused accounts still active                                           |
| **Email Protection**      | Domains protected from impersonation (SPF, DKIM, and DMARC), Mailboxes forwarding outside the company, Email filtering layers active             |
| **Device Health**         | Devices meeting security policy, Devices under management                                                                                        |
| **Threats and Incidents** | Open security incidents, Active security alerts, Credentials exposed in third-party breaches, Threat emails intercepted, Failed sign-in attempts |
| **Managed For You**       | Security standards enforced, Device security policies, Email routing and protection rules, Microsoft 365 service issues                          |

### Reading the Metrics

* **Counts lead, percentages follow.** Coverage metrics display as "17 of 18 · 94%" so small environments read accurately.
* **Color coding.** Green means healthy, yellow and orange mean attention is warranted, red means action is needed. Informational metrics (counts of protections in place) carry no color judgment.
* **No data yet.** A metric shows "No data yet" until its source data has synced. A metric never shows a zero it cannot back up.
* **Data as of.** The timestamp above the scorecards shows when the data was last synchronized.

<Tip>
  Click a metric row to jump to the related findings in the table below. For example, clicking **People protected by MFA** filters the findings to the specific people who still need MFA.
</Tip>

## Items Needing Attention

Below the scorecards, the findings table lists the specific items behind the numbers. It shows exceptions only, never full inventory dumps, so every row is something worth looking at.

| Finding type                          | What it lists                                                            |
| ------------------------------------- | ------------------------------------------------------------------------ |
| **People without MFA**                | Licensed, active people not yet protected by multi-factor authentication |
| **External email forwarding**         | Mailboxes forwarding to addresses outside the company                    |
| **Suspicious inbox rules**            | Mailbox rules that warrant review                                        |
| **Devices needing attention**         | Devices that do not meet the security policy                             |
| **Email domain protection**           | Domains missing SPF, DKIM, or DMARC protection                           |
| **Security incidents**                | Open security incidents and their status                                 |
| **Exposed credentials**               | Work credentials found in third-party breaches                           |
| **Unused accounts**                   | Active accounts with no recent sign-ins                                  |
| **Outdated sign-in methods**          | Accounts using legacy sign-in protocols                                  |
| **Admin access**                      | Accounts holding administrative roles                                    |
| **Shared mailboxes allowing sign-in** | Shared mailboxes with direct sign-in enabled                             |
| **Critical software weaknesses**      | Critical vulnerabilities detected on devices                             |

Click any row to open the details panel with the full context for that finding.

### Reviewing Findings

Users with the manage Microsoft 365 permission can mark a finding as reviewed when it is expected or already handled, for example a sanctioned external forward or a scanner account that uses an older sign-in method.

<Steps>
  <Step title="Open the Finding">
    Click the finding row to open its details panel.
  </Step>

  <Step title="Add Context">
    Optionally add a short note explaining why the item is expected.
  </Step>

  <Step title="Mark as Reviewed">
    Click **Mark as reviewed**. The finding is removed from the client view and no longer counts against the posture metrics.
  </Step>
</Steps>

Reviewed items appear muted in the table for your team, along with the note, and can be reopened at any time with **Reopen finding**.

<Note>
  Company users never see reviewed items. Keeping known-good exceptions reviewed keeps the page focused on what genuinely needs attention.
</Note>

## Company Scoping

The page follows the company selector. Select a single company to present its posture, or view the aggregate across your selected scope. Company users who sign in to the portal automatically see only their own organization, without company columns or filters.

## Best Practices

* **Review new findings before a QBR.** Mark sanctioned exceptions as reviewed so the client conversation stays focused on real gaps.
* **Lead with the wins.** The Threats and Incidents and Managed For You cards show the work being done on the client's behalf: threats intercepted, standards enforced, policies maintained.
* **Use metric click-through.** Jumping from "Admins without MFA" straight to the named accounts turns a number into an action item.

## Troubleshooting

| Issue                                            | Solution                                                                                                            |
| ------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------- |
| Posture tab not visible                          | Connect the CIPP integration in **Settings > Integrations**                                                         |
| Page shows "posture data is not available yet"   | Wait for the first synchronization to complete and confirm tenants are mapped to companies in the integration setup |
| A metric shows "No data yet"                     | That dataset has not synced yet; data appears automatically once it does                                            |
| Numbers look different after switching companies | Metrics always reflect the current company selection                                                                |

## Related Resources

<CardGroup cols={2}>
  <Card title="Configure CIPP Integration" icon="cloud" href="/user-guides/integrations/enable-cipp-integration">
    Connect and map the data source that powers this page
  </Card>

  <Card title="Microsoft 365 Secure Score" icon="shield-check" href="/user-guides/microsoft-365/index">
    Track Microsoft Secure Score and remediation actions
  </Card>

  <Card title="M365 Licenses" icon="id-card" href="/user-guides/microsoft-365/licenses">
    Monitor license usage and spend
  </Card>

  <Card title="M365 Users" icon="users" href="/user-guides/microsoft-365/users">
    Browse Microsoft 365 user accounts
  </Card>
</CardGroup>
