Platform

One lifecycle, from configuration evidence to validated improvement.

Assess, prioritize, remediate, validate, and monitor Microsoft 365 security configuration across Entra ID, Exchange Online, SharePoint, Teams, and Defender.

01

Assess

PosturaIQ inspects Microsoft security configuration against a versioned control catalog. Each assessment is retained as its own record, so history is never overwritten.

  • Read-only application consent, scoped to the workloads in review
  • Versioned control definitions with assessment-time snapshots
  • Asynchronous execution — no browser session needs to stay open
02

Prioritize

Findings are ranked by severity, workload, and the number of affected objects, and tracked as new, persistent, reopened, resolved, or accepted risk.

  • Severity and workload weighting resolved server-side
  • Finding lifecycle preserved across assessments
  • Accepted-risk decisions recorded with an audit trail
03

Remediate

Guided remediation is available today: the desired configuration, the implementation steps, and how to verify the result. Assisted remediation is architected and clearly labeled as not yet operational.

  • Guided remediation for every finding in the catalog
  • Approved remediation definitions with parameter schemas
  • Separate Microsoft permission level required before any change
04

Validate

A finding is only resolved when the intended configuration is confirmed in the environment. Validation is modeled as evidence, not as an assumption.

  • Per-finding validation method defined in the catalog
  • Validation evidence stored alongside the finding instance
  • Continuous validation planned as an entitlement-gated capability
05

Monitor

Posture is compared across assessments so teams can see improvement, regression, and newly introduced configuration risk.

  • Posture history retained per assessment
  • Since-last-assessment change summary
  • Drift detection planned for continuous monitoring

Coverage

Microsoft 365 first, with room for the rest of the Microsoft estate.

PosturaIQ's initial technical focus is Microsoft 365 security posture. Additional Microsoft workloads are on the roadmap and are labeled as planned until they are operational.

Microsoft Entra ID

In scope

Identity, conditional access, privileged roles, and authentication methods.

Exchange Online

In scope

Mail flow, transport rules, auditing, and mailbox protection settings.

SharePoint Online

In scope

External sharing, access controls, and site governance configuration.

Microsoft Teams

In scope

External access, federation, meeting policies, and app permissions.

Microsoft Defender

In scope

Threat policies, safe links and attachments, and alerting configuration.

Microsoft Purview

Planned

Information protection, retention, and data loss prevention posture.

Azure

Planned

Subscription, network, and resource security posture.

Start with a clear posture baseline.

PosturaIQ onboards organizations by invitation. Request access and a member of our team will review your environment and requirements.