Overview
Cloud Locksmith is a Microsoft 365 identity security platform built for continuous posture management. Instead of a one-time audit, Cloud Locksmith connects to your tenant through Microsoft Entra ID and monitors identity configuration on an ongoing basis — surfacing MFA gaps, dormant accounts, privileged role sprawl, and Conditional Access coverage gaps as they appear.
All data is read through the Microsoft Graph API in read-only mode. Remediation is available as a separate, explicitly-approved action — Cloud Locksmith never changes your tenant configuration without direct admin approval.
Features
Continuous Posture Monitoring
Ongoing scans of your Microsoft 365 tenant surface new identity risks as they appear, rather than only at the time of a one-off audit.
Identity & Access Assessments
Every user account is evaluated for MFA registration, sign-in activity, and directory role assignments.
Configuration Drift Detection
Changes to Conditional Access, authentication methods, and directory roles are tracked over time so unexpected drift is caught early.
Conditional Access Management
Visibility into policy coverage gaps, including users and applications not covered by any Conditional Access policy.
MFA Posture Analysis
Identifies accounts without registered authentication methods and tracks MFA registration coverage across the tenant.
Privileged Role Monitoring
Surfaces accounts holding Global Admin and other privileged directory roles, flagging excess or unexpected assignments.
License Optimization
Highlights unused or underutilized Microsoft 365 licenses to help reduce unnecessary subscription spend.
Verified Remediation
Fixes are applied only after explicit admin approval. Every remediation captures a snapshot beforehand, with one-click rollback available.
Executive Reporting
Summarized, severity-ranked findings suitable for leadership review and audit preparation.
Audit Logging
Every remediation action and configuration change is logged for accountability and compliance review.
System Requirements
Microsoft 365 Tenant
Any Microsoft 365 subscription backed by Microsoft Entra ID.
Microsoft Entra ID
The tenant must use Microsoft Entra ID (Azure AD) for identity management.
Supported Browsers
Current versions of Google Chrome, Microsoft Edge, Mozilla Firefox, and Safari.
Supported Licensing
Microsoft 365 Business Basic/Standard/Premium, Microsoft 365 E3/E5, or any plan that includes Microsoft Entra ID.
Required Microsoft Graph Permissions
User.Read.AllEnumerate user accountsDirectory.Read.AllRead tenant directory structureUserAuthenticationMethod.Read.AllCheck MFA registration per userPolicy.Read.AllRead Conditional Access policiesRoleManagement.Read.DirectoryAudit privileged role assignmentsAuditLog.Read.AllRead sign-in activity logsSupported Microsoft Services
Microsoft Entra ID
Identity and directory data — users, groups, and directory roles.
Microsoft Graph
The API layer Cloud Locksmith uses to read tenant configuration.
Conditional Access
Policy coverage and configuration gap analysis.
Directory Roles
Privileged role assignment monitoring, including Global Admin exposure.
Authentication Methods
MFA registration status per user account.
Licensing
License assignment data used for optimization recommendations.
Sign-in Activity
Sign-in logs used to detect dormant or inactive accounts.
Security
Cloud Locksmith connects to your tenant using Microsoft OAuth 2.0 and reads data through Microsoft Graph in read-only mode. OAuth tokens are encrypted and never exposed to the frontend, tenant data is isolated per customer, and every remediation action is logged.
Read the full Security & Trust pageFrequently Asked Questions
What permissions are required?
Cloud Locksmith requests a fixed set of Microsoft Graph delegated permissions. See the System Requirements section below for the complete list. No permissions beyond this list are requested.
Does Cloud Locksmith read email?
No. Cloud Locksmith never requests Mail.Read or any similar content-access scope. Email bodies and headers are never accessed.
Does Cloud Locksmith access SharePoint files?
No. Cloud Locksmith does not request Files.Read, Sites.Read, or any SharePoint or OneDrive permission. Document contents are never accessed.
Can I disconnect at any time?
Yes. Disconnecting revokes Cloud Locksmith's access tokens immediately. Retained tenant data is deleted within 30 days of disconnection, with backups purged within 60 days.
How is tenant data protected?
OAuth tokens are encrypted and never exposed to the frontend. Each tenant's data is logically isolated, and no cross-tenant access is possible. Authentication is handled entirely through Microsoft Entra ID OAuth — Cloud Locksmith never collects or stores your Microsoft password.