The Microsoft 365 / Azure integration performs a read-only posture scan of your tenant and maps the results to your framework controls. It is the most complete of the cloud scanners and is available now. Connecting it does not store a per-tenant secret in Venvera: it uses Microsoft admin consent.
Connecting your tenant
From the Integrations hub, open the Microsoft 365 / Azure card and start setup. You are sent to the Microsoft admin-consent screen. A Global Administrator of your Microsoft 365 tenant must approve the request.
Microsoft returns you to Venvera. Venvera verifies that consent was granted for your tenant, tests connectivity, and records the integration as connected. No client secret from your tenant is kept.
Start a scan from the setup page. Progress and results appear on the Scans, Findings, and Resources sub-pages.
What the scan checks
The Microsoft Graph security scan runs a set of checks across your identity and collaboration posture, grouped below.
| Group | Examples of what is checked |
|---|---|
| Identity and MFA | Users without MFA, number of Global Admins above four, guest accounts, stale or inactive accounts, risky users, Secure Score |
| Conditional Access | Whether Conditional Access policies exist, legacy authentication blocking, Security Defaults |
| App security | Application registration hygiene and credential practices |
| M365 configuration | SharePoint external sharing, who can create Microsoft 365 groups |
| Email security | Mailbox auto-forwarding, SPF and DKIM records |
| Cross-tenant | Cross-tenant access and trust settings |
Defender for Cloud and resource discovery
Alongside the Graph checks, the scan pulls Microsoft Defender for Cloud recommendations and turns them into findings, and discovers your Azure resources through the Azure Resource Graph so they are inventoried against your controls.
Turning findings into evidence
Each finding is mapped by category to controls in your active frameworks. A finding that passed comes back as informational and can be attached to the mapped control as evidence, so a clean scan builds your evidence library for you.
The Azure / Microsoft 365 section
Once connected, Azure / Microsoft 365 appears under Platforms in the sidebar with a security dashboard, the framework requirements the scan evidences, a coverage map, the findings, the scan history and the Azure resources discovered through Defender for Cloud. See Azure / Microsoft 365 and Google Workspace security dashboards for how each check is judged and how requirement status is derived.