No Microsoft passwords, ever
PosturaIQ authenticates to Microsoft through application consent. It never asks for, transmits, or stores a Microsoft user password, and it never requires a standing global administrator session.
Security & trust
How PosturaIQ handles Microsoft credentials, tenant isolation, least privilege, auditability, and honest reporting of what the platform has and has not done.
PosturaIQ authenticates to Microsoft through application consent. It never asks for, transmits, or stores a Microsoft user password, and it never requires a standing global administrator session.
The default grant is read-only. Write permission is a separate, explicit consent that an organization may decline permanently while still using the platform.
Microsoft credentials, tokens, and secrets are held on the backend only. No client-side code path can read them, and platform administration screens never display them.
Every read and write is scoped to the caller's organization on the server. Organization identifiers supplied by the browser are treated as selection hints and validated against membership before use.
Roles, entitlements, and platform administration privileges are resolved on the backend. The UI hides what a user cannot do; the backend is what actually enforces it.
Permission grants, assessment runs, remediation approvals and executions, entitlement changes, and administrative access are recorded as immutable audit events.
PosturaIQ platform administration is a distinct authorization domain. Being an administrator inside a customer organization grants no platform privileges, and platform staff access is itself audited.
PosturaIQ distinguishes between recommended, approved, executed, and validated. It will report that an operation is unavailable rather than imply an action it did not perform.
Current release
PosturaIQ states its own maturity plainly, because a security platform that overstates its capabilities is a risk to its customers.
Available
Not yet operational
These capabilities are represented in the architecture, permission model, and audit trail so they can be enabled without a redesign — and are labeled in the product until they are real.
PosturaIQ onboards organizations by invitation. Request access and a member of our team will review your environment and requirements.