Read-only Microsoft 365 monitoring

The weekly Microsoft 365 security brief you’ll actually read.

Kinervo keeps watch over your Microsoft 365 setup and turns the evidence into one clear story: what improved, what changed, what needs attention and why. It never changes your tenant.

  • No card
  • Microsoft consent
  • Private report
  • Revoke any time
Illustrative preview

Read-only by designCannot change tenant settings

Microsoft approvalConsent stays in Microsoft's flow

A report you can sendClear for owner and useful for IT

Revoke any timeRemove the app directly in Entra

The deliverable

One report. Four questions answered.

You should not have to translate a security dashboard. Every Kinervo brief is designed to be understood in two minutes and useful for the rest of the week.

01Where do we stand?

A posture score with context

See the overall position, the areas pulling it down and the evidence behind each result.

02What happened?

Important signals, already sorted

Available sign-in indicators are surfaced for review without presenting silence as proof of health.

03What changed?

Security changes made visible

See when important protections move between checks—and whether they improved or regressed.

04What do we do next?

Priorities in business language

The owner sees the decision while the IT provider gets the evidence behind it.

See the real report renderer, not a marketing mock-up.The sample uses fictional company data but the same layout as a private assessment.

Open the sample

Evidence coverage

The places real tenant risk hides.

Kinervo checks the configuration and activity available through Microsoft Graph and public domain records. Licence and evidence limits stay visible.

IA

Identity & MFA

Registration, authentication strength and password-only exposure.

CA

Conditional Access

Policy coverage, exclusions, state and protection gaps.

AP

Admin privilege

Role assignments, standing access and high-impact accounts.

AC

Apps & consent

Enterprise applications and permission grants that expand access.

MR

Mailbox risk

Forwarding and inbox-rule controls reassessed from fresh evidence.

DP

Domain protection

SPF, DKIM and DMARC posture across verified domains.

SI

Sign-in signals

Hourly indicators where the tenant exposes the required feed.

DS

Device & service posture

The protections visible to the tenant's licences and services.

Results remain separate: pass, fail, warning, licence-limited, manual-check and not-verified. A lack of evidence is never counted as proof of safety.

How it works

From one email to a useful answer.

The assessment is designed for minimal effort and maximum transparency.

  1. 01

    Enter your work email

    One field. No card and no software to install. Your company domain prepares the right Microsoft approval step.

  2. 02

    Approve read-only access

    Your administrator sees every permission on Microsoft's own consent screen. Kinervo can inspect; it cannot edit.

  3. 03

    Receive the clear version

    Your private assessment report arrives after collection, followed by a weekly brief during the included trial.

Not the administrator? Send the approval step to your IT provider from the next screen—no need to restart.

Simple commercial model

See the value before deciding.

Start with a free read-only assessment of your own Microsoft 365 tenant. Continue only if the monitoring and weekly proof earn their place.

Assessment + trial

Start here

€0

No card. No automatic charge.

  • 20 signed control outcomes
  • Private plain-English report
  • Technical evidence for your IT provider
  • 14 days of read-only monitoring
Start free

Straight answers

Trust is part of the product.

The important questions should be answered before anyone reaches a Microsoft consent screen.

Can Kinervo change anything in Microsoft 365?

No. Kinervo is intentionally read-only. It cannot create a policy, change a setting, remove an account or remediate a finding. Your administrator can revoke access directly in Entra.

Does Kinervo read email or files?

No. The service reads approved security configuration and operational evidence, not the contents of email, files or Teams messages.

What if I am not the Microsoft 365 administrator?

You can send the approval step to your IT provider, with the same permission list and plain-English explanation.

Will every check work on every licence?

Microsoft exposes different evidence at different licence levels. Kinervo labels licence limits, manual checks and unverified results separately instead of counting them as passes.

Is the assessment really free?

Yes. The initial assessment, private report and first 14 days of monitoring are included without a card. Monitoring continues only if you choose it.

Your tenant. Clearly explained.

See the gaps. Track the evidence. Prove the progress.

Free assessment, read-only access, no card. The report is yours either way.

Run my free assessment