Every cloud platform you connect gets its own section in the sidebar under Platforms: Azure / Microsoft 365 and Google Workspace each have a security dashboard, the list of framework requirements the platform can evidence, a coverage map, the findings from the last scan and the scan history. The section answers one question for each connected tenant: which of our requirements does this platform prove today, and where is it letting us down?

A tour of the Azure / Microsoft 365 and Google Workspace sections: dashboard, requirements, map and findings. (65 seconds)

ℹ️
You need the integrations.view permission to open a platform section and integrations.edit to run a scan. The sections appear once the platform is connected; see Microsoft 365 / Azure Integration and Google Workspace Integration for the connection steps.

The security dashboard

Venvera Azure / Microsoft 365 security dashboard with check totals, security areas and a per-framework coverage table
The Azure / Microsoft 365 security dashboard - shown with sample data.

The top bar shows which tenant is connected (for example your onmicrosoft.com domain or your Workspace primary domain), when the last scan finished, and two actions: Connection opens the integration page and Run scan starts a fresh read-only scan. Below the title, six numbers summarise the last scan:

NumberWhat it counts
Checks passingChecks that the last scan evaluated and found in order, out of all checks in the catalogue for this platform.
Checks failingChecks with at least one open finding, split by the highest severity found.
Not evaluatedChecks the scanner could not judge: no completed scan yet, or the scanner skipped them (for example there are no Conditional Access policies to evaluate).
Open findingsFindings behind the failing checks. Click through to the findings list.
Requirements metFramework requirements whose mapped checks all pass.
Requirements at riskRequirements that are failing or only partially met.

The Security areas panel groups the checks by theme - Identity and access, Conditional Access, Applications and consent, Tenant posture, Data protection and sharing, Email security and Cross-tenant access for Microsoft 365; MFA, admin accounts, account lifecycle and devices for Google Workspace - and shows how many checks in each area pass. The Frameworks table lists every framework you have enabled with the number of requirements this platform can evidence, a coverage bar, and the count of met, partially met and failing requirements. Open jumps to the requirements list filtered to that framework.

How a check is evaluated

Venvera keeps a catalogue of checks per platform. Each check has a plain statement of what a pass means and a list of the framework requirements it evidences. After each scan the platform status engine turns findings into a verdict per check:

VerdictWhen it is given
FailThe check has an open finding that is not informational. The severity shown is the worst open finding.
PassFor failure-only checks (the Microsoft Graph scanner reports problems only) a completed scan with no finding is a pass. For graded checks (the Google Workspace scanner reports every check) an informational result is a pass. A finding you have marked as accepted or false positive also counts as a pass.
Not evaluatedNo completed scan yet, the scanner reported that it skipped the check, or a graded check was not part of the last scan.
💡
A check that is Not evaluated is neither good nor bad. Run a scan first; if it stays not evaluated, the dashboard tells you why (for example "skipped by the scanner").

Requirements

Venvera platform requirements list showing framework requirements evidenced by Microsoft 365 with their status and the checks behind each
The Requirements tab - shown with sample data.

The Requirements tab lists every requirement of your enabled frameworks that this platform can evidence, with the checks that map to it. A requirement's status is derived from those checks:

  • Met - every evaluated check passes.
  • Partially met - some checks pass and at least one fails.
  • Failing - every evaluated check fails.
  • Not evaluated - none of its checks has a verdict yet.

Filter by framework or status (the dashboard's numbers link straight to these filters) and open a requirement to see the check statements, the open findings and the remediation guidance from the scanner.

Map

Venvera platform coverage map drawing Microsoft 365 checks as ribbons to the framework requirements they evidence, with a decision list underneath
The Map tab: checks flowing to requirements - shown with sample data.

The Map tab draws the checks on the left and the framework requirements on the right, with a ribbon for every mapping. Failing checks are marked in red, so you can see at a glance which single misconfiguration is holding back the most requirements. The decision list under the map ranks failing checks by the number of requirements they affect, with the action to take: fix the setting in your tenant, or enable a check the scanner skipped. The same map is available under Coverage maps.

Findings, scans and resources

Findings opens the integration's findings list, where each finding carries its severity, the affected object, remediation guidance and the controls it maps to, and where you can attach a finding as evidence or mark it accepted. Scans shows the scan history with status and duration. For Microsoft 365 a Resources tab lists the Azure resources discovered through Defender for Cloud.

Running a scan

Open the platform section

In the sidebar, under Platforms, open Azure / Microsoft 365 or Google Workspace.

Run the scan

Click Run scan in the top bar. The scan is read-only and usually finishes within a minute or two; the dashboard refreshes with the new verdicts when it completes.

Work the decision list

Open the Map tab, fix the checks at the top of the list in your tenant, and run the scan again to confirm the requirements move to Met.

ℹ️
Passing checks are not just a status. Attaching a finding as evidence records the scan result against the mapped control, and the crosswalk marks every equivalent control in your other frameworks at the same time. See Integrations Overview for how cloud findings become evidence.

Google Workspace

Venvera Google Workspace security dashboard with check totals and the frameworks the Workspace scan evidences
The Google Workspace security dashboard - shown with sample data.

The Google Workspace section works the same way. Its scanner grades every check, so the dashboard shows an explicit pass for 2-Step Verification enrolment, super-administrator count, dormant accounts and device compliance rather than inferring a pass from silence. Requirements mapped from these checks cover the access-control, MFA and asset-management clauses of your frameworks.