Documentation

Everything you need to know about Cloud Locksmith

Cloud Locksmith is a Microsoft 365 identity security platform that continuously monitors your tenant's security posture, surfaces identity risks, and applies remediation only with your explicit approval.

Overview

Cloud Locksmith is a Microsoft 365 identity security platform built for continuous posture management. Instead of a one-time audit, Cloud Locksmith connects to your tenant through Microsoft Entra ID and monitors identity configuration on an ongoing basis — surfacing MFA gaps, dormant accounts, privileged role sprawl, and Conditional Access coverage gaps as they appear.

All data is read through the Microsoft Graph API in read-only mode. Remediation is available as a separate, explicitly-approved action — Cloud Locksmith never changes your tenant configuration without direct admin approval.

Features

Continuous Posture Monitoring

Ongoing scans of your Microsoft 365 tenant surface new identity risks as they appear, rather than only at the time of a one-off audit.

Identity & Access Assessments

Every user account is evaluated for MFA registration, sign-in activity, and directory role assignments.

Configuration Drift Detection

Changes to Conditional Access, authentication methods, and directory roles are tracked over time so unexpected drift is caught early.

Conditional Access Management

Visibility into policy coverage gaps, including users and applications not covered by any Conditional Access policy.

MFA Posture Analysis

Identifies accounts without registered authentication methods and tracks MFA registration coverage across the tenant.

Privileged Role Monitoring

Surfaces accounts holding Global Admin and other privileged directory roles, flagging excess or unexpected assignments.

License Optimization

Highlights unused or underutilized Microsoft 365 licenses to help reduce unnecessary subscription spend.

Verified Remediation

Fixes are applied only after explicit admin approval. Every remediation captures a snapshot beforehand, with one-click rollback available.

Executive Reporting

Summarized, severity-ranked findings suitable for leadership review and audit preparation.

Audit Logging

Every remediation action and configuration change is logged for accountability and compliance review.

System Requirements

Microsoft 365 Tenant

Any Microsoft 365 subscription backed by Microsoft Entra ID.

Microsoft Entra ID

The tenant must use Microsoft Entra ID (Azure AD) for identity management.

Supported Browsers

Current versions of Google Chrome, Microsoft Edge, Mozilla Firefox, and Safari.

Supported Licensing

Microsoft 365 Business Basic/Standard/Premium, Microsoft 365 E3/E5, or any plan that includes Microsoft Entra ID.

Required Microsoft Graph Permissions

User.Read.AllEnumerate user accounts
Directory.Read.AllRead tenant directory structure
UserAuthenticationMethod.Read.AllCheck MFA registration per user
Policy.Read.AllRead Conditional Access policies
RoleManagement.Read.DirectoryAudit privileged role assignments
AuditLog.Read.AllRead sign-in activity logs

Supported Microsoft Services

Microsoft Entra ID

Identity and directory data — users, groups, and directory roles.

Microsoft Graph

The API layer Cloud Locksmith uses to read tenant configuration.

Conditional Access

Policy coverage and configuration gap analysis.

Directory Roles

Privileged role assignment monitoring, including Global Admin exposure.

Authentication Methods

MFA registration status per user account.

Licensing

License assignment data used for optimization recommendations.

Sign-in Activity

Sign-in logs used to detect dormant or inactive accounts.

Security

Cloud Locksmith connects to your tenant using Microsoft OAuth 2.0 and reads data through Microsoft Graph in read-only mode. OAuth tokens are encrypted and never exposed to the frontend, tenant data is isolated per customer, and every remediation action is logged.

Read the full Security & Trust page

Frequently Asked Questions

What permissions are required?

Cloud Locksmith requests a fixed set of Microsoft Graph delegated permissions. See the System Requirements section below for the complete list. No permissions beyond this list are requested.

Does Cloud Locksmith read email?

No. Cloud Locksmith never requests Mail.Read or any similar content-access scope. Email bodies and headers are never accessed.

Does Cloud Locksmith access SharePoint files?

No. Cloud Locksmith does not request Files.Read, Sites.Read, or any SharePoint or OneDrive permission. Document contents are never accessed.

Can I disconnect at any time?

Yes. Disconnecting revokes Cloud Locksmith's access tokens immediately. Retained tenant data is deleted within 30 days of disconnection, with backups purged within 60 days.

How is tenant data protected?

OAuth tokens are encrypted and never exposed to the frontend. Each tenant's data is logically isolated, and no cross-tenant access is possible. Authentication is handled entirely through Microsoft Entra ID OAuth — Cloud Locksmith never collects or stores your Microsoft password.

Contact

Support

Questions about setup, permissions, or your account.

support.cloudlocksmith@gmail.com

Sales

Pricing, procurement, or MSP partnership inquiries.

support.cloudlocksmith@gmail.com

Security Disclosures

Report a suspected vulnerability.

security.cloudlocksmith@gmail.com