Microsoft 365 security questions, answered

Is my tenant actually secure? What will an auditor look for? Can AI really fix the gaps? Here are straight answers to the questions IT teams ask most about Microsoft 365, Intune, Defender, and Entra ID security, from scanning and compliance to the free simulation, the Claude MCP, and pricing.

See your security gaps, free

Getting started

Is Senserva free?

Much of it, yes. The advanced simulation and the You v. Claude game run free with no registration, no key, and no access to your tenant. Registering, also free, unlocks scans of your own environment: 3 tenants, up to 25 users each, in one verified scan. Need more for an evaluation? Request a full evaluation key, reviewed and verified. Education institution and nonprofit discounts are available.

See pricing and plans

How do I check my Microsoft 365 security settings?

Install Senserva, run the free advanced simulation to see how it works, no registration or key needed, then register free to scan your own tenant. It reads your configuration across Entra ID, Intune, Exchange, SharePoint, Teams, OneDrive, and Purview, ranks findings by Severity, maps them to compliance controls, and gives a validated remediation for each.

Try the security simulator

Do I need to install an agent or use a cloud service?

No. Senserva runs on Windows or Mac and reads your tenant through Microsoft's APIs. No agents, no cloud service, your data stays with you.

How Senserva runs, secure and private

Coverage and posture

What does Senserva check?

650+ checks across the Microsoft 365 stack: Entra ID identity (MFA, Conditional Access, PIM, risky users, FIDO2, app credentials), Intune device management, Exchange and email protection, SharePoint, OneDrive, Teams, Purview data governance, Azure RBAC, and Copilot / AI agent configuration.

See the full depth of coverage

Which Microsoft licenses do I need, and does Senserva work with what I have?

Senserva works with whatever you have licensed. At scan time it reads your subscribed SKUs and service plans from Microsoft Graph and automatically runs the checks your licensing supports, so coverage deepens as you add Microsoft Entra ID P1 and P2, Intune, Purview, and Defender. If a workload is not licensed or the scanning account cannot reach it, those checks are reported as skipped rather than failing the scan, so you always see what was and was not covered. For a full feature-to-license map, which license unlocks Conditional Access, PIM, DLP, and the rest, plus how to buy each SKU and roughly what it costs, see the Microsoft security licensing guide.

What is security posture management?

Security posture management is the ongoing practice of measuring how your environment is actually configured against security best practice and compliance baselines, then closing the gaps. Senserva does this continuously for Microsoft 365, ranking risks and helping you remediate them.

The Microsoft security landscape

How is this different from Microsoft Secure Score?

Secure Score gives you a single number and high-level tips. Senserva gives you the specific misconfigurations behind your posture, ranked by Severity, each with the underlying evidence, the control it maps to, and a fix, across far more than Secure Score covers. It is the fastest path to real Microsoft Secure Score improvement.

Senserva and Microsoft Secure Score

How do I audit Entra ID?

Run Senserva against your tenant for a full Entra ID security audit: it surfaces standing vs. eligible privileged roles, Conditional Access gaps and bypasses, break-glass hygiene, risky users and sign-ins, FIDO2 coverage, and risky applications and OAuth grants, each mapped to a control with a remediation step.

Entra ID security audit, in depth

Does Senserva audit Azure AD (Microsoft Entra ID) roles?

Yes. Azure AD is now Microsoft Entra ID, and Senserva audits directory and Azure role assignments in depth: privileged roles, eligible versus standing access through PIM, and specific roles such as Global Administrator and Information Protection Administrator. It also flags role assignment drift. Entra ID security audit and role assignment drift.

How do I fix Microsoft 365 misconfigurations?

Senserva does not just report. Its agentic remediation turns findings into reviewed fixes (for example PowerShell) you can ship with confidence, and the evidence updates on the next scan.

How AI remediation works

Compliance

What compliance frameworks does Senserva support?

Microsoft Cloud Security Benchmark (MCSB) v2 and CISA SCuBA are mapped natively in every report. It also covers Microsoft Zero Trust Assessment, Secure Score, EIDSCA, and Purview, and bridges to NIST 800-53, ISO 27001, SOC 2, HIPAA, PCI-DSS, CIS Controls, and MITRE ATT&CK through the Claude MCP layer. CMMC, NIST 800-171, and GCC support are targeted for Q3 2026.

Compliance and frameworks

Is Senserva a SCuBA compliance tool?

Yes. Senserva maps findings to CISA SCuBA baselines natively, so you can assess, prove, and remediate SCuBA posture across Microsoft 365 in one place.

SCuBA and MCSB compliance

AI and Claude MCP

What is the Claude MCP integration?

Senserva ships an MCP server so you can run the entire product from Claude. Ask, in plain language, which controls you fail or which Conditional Access gaps exist, and Claude answers from your real scan data and helps you remediate. You can use the full Senserva UI or the full Claude MCP interface over the same data, your choice.

Claude and the Senserva MCP

Is the AI trustworthy?

Senserva Trustworthy AI is built with guardrails so answers are grounded in your actual scan data, not guesses. The AI reasons over real findings and cites the evidence behind its recommendations.

AI-enhanced security reports

MSPs and scale

Does Senserva work for MSPs and multiple tenants?

Yes. Senserva is a multi-tenant Microsoft 365 security tool for managed service providers. Run MSP M365 security scanning and bulk tenant security audits across many customers, with unified, client-ready reporting. See how MSPs save time with Senserva.

Can a team share one database, or is it only local?

Both. By default Senserva keeps everything in a local database with no setup. When a team needs one source of truth, you can switch on a shared cloud database hosted in your own Azure, so several operators scan and review the same tenants, with safe concurrent scanning and per-tenant ownership for MSPs. Your data stays in your own Azure.

How the shared cloud database works

Company and pricing

Who makes Senserva?

Senserva, LLC, a Microsoft-first security company founded by Mark Shavlik (original Windows NT team, founder of Shavlik Technologies). Senserva is a Microsoft Intelligent Security Association (MISA) member, a 2024 Microsoft Security Excellence Awards finalist, and Senserva is listed on the Microsoft Security Store.

About Senserva

What happened to Shavlik Technologies?

Senserva is built by Senserva, founded by Mark Shavlik. He started Shavlik Technologies, whose HfNetChk (HFNetChk) engine powered the Microsoft Baseline Security Analyzer and whose NetChk patch products became a Windows administration staple. Shavlik went to VMware, then LANDESK, and the patch technology lives on at Ivanti today. Read the full Shavlik story.

How much does Senserva cost?

The demo and game are free with no key, and free registration unlocks scans of 3 of your own tenants, up to 25 users each, in one verified scan. The annual license removes the caps and starts at $5.99 per user, priced by tenant size with volume discounts. Education institution and nonprofit discounts are available, and MSPs can ask for a channel quote. Contact info@senserva.com.

See pricing and plans