How it works

From invitation to validated improvement.

How PosturaIQ connects to your Microsoft tenant, runs read-only assessments, and separates assessment access from remediation access.

  1. STEP 01

    Request access

    PosturaIQ is invite-only. You tell us about your organization and Microsoft environment; we review the request and issue an invitation if it is a fit. Submitting a request does not create an account, an organization, or a subscription.

  2. STEP 02

    Accept your invitation

    Your invitation is tied to a specific organization and role. Accepting it creates your user identity and your membership in that organization — nothing else.

  3. STEP 03

    Connect your Microsoft tenant

    An administrator in your tenant grants PosturaIQ read-only application consent. PosturaIQ never asks for, stores, or uses a Microsoft user password, and never requires a standing global administrator session.

  4. STEP 04

    Run an assessment

    Assessments run asynchronously in the background. You can close the browser. When results are processed, findings are created, updated, or resolved and posture is recalculated.

  5. STEP 05

    Work the findings

    Each finding explains what was observed, why it matters, what the recommended configuration is, and how to verify the result once changed.

  6. STEP 06

    Validate and monitor

    PosturaIQ re-queries the environment to confirm changes are in place, then tracks posture over time so improvement and regression are both visible.

Permission model

Assessment access and remediation access are never the same grant.

Reading configuration and changing configuration are separate decisions with separate consent. An organization can use PosturaIQ indefinitely with assessment access only.

Assessment access — read only

Sufficient for the full assess, prioritize, and guided-remediation experience. PosturaIQ cannot change anything in your tenant with these permissions.

  • Directory.Read.All

    Read directory objects, roles, and administrative assignments.

  • Policy.Read.All

    Read conditional access and authentication method policies.

  • SecurityEvents.Read.All

    Read Defender security posture signals and alerts.

  • Reports.Read.All

    Read usage and authentication reports used for coverage analysis.

  • Exchange.ManageAsApp (read scenarios)

    Read Exchange Online transport and mailbox security settings.

Remediation access — write, optional

Only required if your organization later chooses assisted remediation. Requires a separate, explicit consent, and is recorded as its own permission grant with its own audit trail.

  • Policy.ReadWrite.ConditionalAccess

    Create or update conditional access policies during approved remediation.

  • Policy.ReadWrite.AuthenticationMethod

    Adjust authentication method policy during approved remediation.

  • Organization.ReadWrite.All

    Apply tenant-level security configuration changes.

  • Exchange.ManageAsApp (write scenarios)

    Apply Exchange Online security configuration changes.

Assisted remediation execution is not operational in this release. The permission model, approval policy, and audit trail exist so it can be enabled without redesign.

Start with a clear posture baseline.

PosturaIQ onboards organizations by invitation. Request access and a member of our team will review your environment and requirements.