How it works
From invitation to validated improvement.
How PosturaIQ connects to your Microsoft tenant, runs read-only assessments, and separates assessment access from remediation access.
- STEP 01
Request access
PosturaIQ is invite-only. You tell us about your organization and Microsoft environment; we review the request and issue an invitation if it is a fit. Submitting a request does not create an account, an organization, or a subscription.
- STEP 02
Accept your invitation
Your invitation is tied to a specific organization and role. Accepting it creates your user identity and your membership in that organization — nothing else.
- STEP 03
Connect your Microsoft tenant
An administrator in your tenant grants PosturaIQ read-only application consent. PosturaIQ never asks for, stores, or uses a Microsoft user password, and never requires a standing global administrator session.
- STEP 04
Run an assessment
Assessments run asynchronously in the background. You can close the browser. When results are processed, findings are created, updated, or resolved and posture is recalculated.
- STEP 05
Work the findings
Each finding explains what was observed, why it matters, what the recommended configuration is, and how to verify the result once changed.
- STEP 06
Validate and monitor
PosturaIQ re-queries the environment to confirm changes are in place, then tracks posture over time so improvement and regression are both visible.
Permission model
Assessment access and remediation access are never the same grant.
Reading configuration and changing configuration are separate decisions with separate consent. An organization can use PosturaIQ indefinitely with assessment access only.
Assessment access — read only
Sufficient for the full assess, prioritize, and guided-remediation experience. PosturaIQ cannot change anything in your tenant with these permissions.
Directory.Read.All
Read directory objects, roles, and administrative assignments.
Policy.Read.All
Read conditional access and authentication method policies.
SecurityEvents.Read.All
Read Defender security posture signals and alerts.
Reports.Read.All
Read usage and authentication reports used for coverage analysis.
Exchange.ManageAsApp (read scenarios)
Read Exchange Online transport and mailbox security settings.
Remediation access — write, optional
Only required if your organization later chooses assisted remediation. Requires a separate, explicit consent, and is recorded as its own permission grant with its own audit trail.
Policy.ReadWrite.ConditionalAccess
Create or update conditional access policies during approved remediation.
Policy.ReadWrite.AuthenticationMethod
Adjust authentication method policy during approved remediation.
Organization.ReadWrite.All
Apply tenant-level security configuration changes.
Exchange.ManageAsApp (write scenarios)
Apply Exchange Online security configuration changes.
Assisted remediation execution is not operational in this release. The permission model, approval policy, and audit trail exist so it can be enabled without redesign.
Start with a clear posture baseline.
PosturaIQ onboards organizations by invitation. Request access and a member of our team will review your environment and requirements.