Built for Microsoft 365 environments

Microsoft 365 security,
in language your business understands.

Cindera reviews your Microsoft 365 environment for identity risks, NIS2 compliance gaps and insurance-ready evidence, then tells you exactly what to fix in plain language.

Read-only access · Designed for SMEs in Europe · EU data residency

cindera · fleet posture
Fleet posture score
72/ 100
Needs attention+4 vs 7 days ago
Critical
3
High
11
Tenants
14
critical
2 admin accounts without MFA
Contoso NV · NIS2-21.2.d
high
Legacy authentication not blocked
Vanderlee BV · NIS2-21.2.j

What you get

Four screens that answer what your client will ask.

Every tenant on one screen

One posture score across the whole portfolio, with the tenants that need attention sorted to the top. Microsoft gives you this per tenant, one login at a time.

Fleet posture score

72/ 100
+4 vs 7 days ago

Critical

3

High

11

Tenants

14

Vanderlee BV
41
Contoso NV
68

Cindera Watch

A new Global Administrator reaches you in minutes, not at the next nightly scan. Triage each change as expected or worth investigating.

+m.declercq@contoso.be was granted Global Administrator

Can take full control of the tenant.

2 hours ago · by IT Service Desk

Review

+svc-backup@contoso.be was granted Application Administrator

Privileged role on a service account.

7 hours ago

Review

−t.verlinden@contoso.be was removed from Helpdesk Administrator

yesterday

✓ Expected

Findings in plain language

Each finding names the affected account and the NIS2 or GDPR control behind it. Nothing to translate before you send it on.

CriticalHighOpen
Critical

2 admin accounts without MFA

j.dewit@contoso.be

NIS2-21.2.d
Critical

Legacy authentication is not blocked

No blocking policy found

NIS2-21.2.j
High

7 Global Administrators (recommended: 3)

Global Administrator

GDPR-32

A report you can hand over

Your branding, one table, and an explicit list of what could not be checked. It goes straight to an auditor or an insurer.

Your MSP

Security report for contoso.be

2026-08-19

Score

41

Critical

2

High

4

Not run

1

Checks not performed

Excluded from the score rather than counted as passed. This report never claims a control was met when it could not be verified.

Why now

Security expectations changed. Most SMEs haven’t caught up.

  • Small businesses are now in scope

    Attackers target Microsoft 365 tenants at any size. Credentials, mailbox access and admin takeovers don't care about headcount.

  • Default Microsoft 365 isn't secure enough

    Most tenants ship with gaps in MFA coverage, legacy authentication and over-permissioned apps. Nobody flags this for you.

  • Compliance and insurance keep raising the bar

    NIS2 obligations, cyber-insurance questionnaires and client security reviews increasingly expect documented identity controls.

  • You can't fix what you can't see

    Without a clear view of your identity posture, every audit, incident or renewal becomes a scramble.

NIS2 in plain language

A short briefing on NIS2, and why identity sits at the centre of it.

What NIS2 is

A European directive that raises the cybersecurity baseline for organisations operating in or supplying critical and important sectors. EU member states have transposed it into national law.

Who it applies to

Not just large enterprises. Many mid-sized companies in energy, manufacturing, digital infrastructure, food, healthcare, logistics and managed services now fall in scope, either directly or through their customers.

Why identity matters

Authentication, access control, MFA and admin hygiene are explicit requirements. Most breaches start with an identity issue, which is why regulators look at it first.

What's at stake

Non-compliance can lead to formal sanctions and personal liability for management. Even without enforcement, weak identity hygiene affects insurance terms and customer trust.

Free assessment

Not sure if you’re NIS2 compliant?

Answer a handful of questions about how you run Microsoft 365. You’ll get a quick read on where you stand, and the gaps that matter most to close first.

How Cindera works

From connection to remediation, in three steps.

01

Connect Microsoft 365

An admin grants Cindera read-only access to your Entra ID tenant in a guided two-minute consent flow. We never modify anything in your environment.

02

Automated security scan

Cindera reviews your identity configuration, admin accounts, sign-in policies and third-party app permissions. The first scan finishes in under a minute.

03

Findings and fix instructions

Every risk comes with a plain-language explanation, a realistic fix time and step-by-step remediation, written for the person who'll actually do the work.

What Cindera detects

The identity risks that quietly cause incidents.

Cindera ships with a curated rule set tuned for SMEs running Microsoft 365. Every finding is written in plain language and comes with a realistic fix time.

Missing MFA protection

Accounts signing in without strong authentication, especially admins.

Legacy authentication risks

Outdated sign-in protocols that bypass modern security controls.

Too many admin accounts

Excessive privileged access that increases your blast radius.

Dormant privileged users

Inactive admin accounts that haven't been used in months but still hold the keys.

Risky application permissions

Third-party apps with broad access to your data, often forgotten and rarely reviewed.

Expiring client secrets

Credentials nearing expiry that can quietly break services or leave gaps if rotated late.

MFA enforcement gaps

Users quietly exempted from your MFA policy through exclusion groups, still able to sign in with just a password.

Weak identity hygiene

Configuration gaps in sign-in policies, password rules and recovery options.

See your Microsoft 365 posture in 30 minutes.

We’ll walk through Cindera live, scan a sandbox tenant and answer your NIS2 questions. No slides, no obligation.