You are granting tenant-wide access. Here is exactly what that means.
dotCLOUD Assessor reads your Microsoft 365 configuration to assess it against 111 CIS controls. This page sets out what it can reach, what it cannot, and where the boundary is enforced.
Read-only by architecture
We can look. We cannot touch.
Every permission we request is a read permission, and the assessment engine contains no code path that creates, modifies or deletes anything in your tenant. It cannot change a policy, reset a password or alter a mailbox — and it will not do so even if one of your administrators asks it to. Remediation is always your action, taken in your own admin centre.
Zero content access
Your mail, files and chats are never opened.
We do not read, process or store the body, subject or attachments of any email; the contents of any SharePoint or OneDrive file; any Teams chat, channel message, meeting recording or transcript; or any calendar entry. We evaluate configuration and directory metadata — whether auditing is on, whether external sharing is restricted, how a policy is scoped.
Swiss engineering
Built in Switzerland, by Microsoft specialists.
dotCLOUD Consulting (Schweiz) GmbH is a Swiss company operating under Swiss law from Schlieren, Zurich. The platform is engineered by a team whose certifications run from Associate to Expert level and include Microsoft MVP Awards, in a best-practice culture shaped by Microsoft MVPs and recognised community contributors — the same people who deliver Microsoft 365 security engagements in the field.
Enterprise infrastructure
Microsoft Azure, West Europe.
The platform runs on Azure App Service with an Azure SQL database in the West Europe region. Data is encrypted in transit with TLS and at rest by the platform. Every record carries the identifier of the organisation that owns it, and every query in the customer portal is filtered by the identity established server-side in your session — never by a value your browser supplies.
Tamper-evident audit
Privileged actions are written to an append-only ledger.
Consent grants and withdrawals, report releases, and every support session in which a dotCLOUD administrator views your portal are recorded in an Azure SQL ledger table that cannot be edited or deleted after the fact. Support access requires a written justification and is read-only.
The boundary, stated plainly
Configuration on one side, content on the other. Nothing in the product crosses it.
Verified domains and their public SPF, DKIM and DMARC records
What we never touch
Email bodies, subjects or attachments
SharePoint or OneDrive file contents
Teams chats, channel messages or recordings
Calendar entries, contacts or tasks
Passwords, hashes, tokens or authentication codes
Anything at all in a tenant that has not granted consent
Full disclosure on identifiers. Because directory objects belong to people, findings do contain business identifiers — user principal names, group names, mailbox addresses — where naming them is what makes a finding actionable. That is personal data, and we treat it as such: it is processed on your instructions as your processor, capped in report text rather than reproduced wholesale, and never enriched with anything from the content of your tenant.
Transparency
Every permission we request, and why
These 16 application permissions are what a Global Administrator approves once, on Microsoft’s own consent screen. This list is generated from the same source the product uses, so it cannot drift from what you are actually asked to grant.
Identity & Access
Directory.Read.All
Microsoft Graph
Reads users, groups and directory objects — counts Global Administrators, finds break-glass accounts and identifies guest access.
Policy.Read.All
Microsoft Graph
Reads Conditional Access and authentication policies to verify legacy authentication is blocked and Security Defaults are configured correctly.
UserAuthenticationMethod.Read.All
Microsoft Graph
Reads which multi-factor methods users have registered. Registration data only — never a credential, secret or authentication code.
RoleManagement.Read.Directory
Microsoft Graph
Reads directory role assignments to report standing privilege and confirm least-privilege administration.
Security Posture
SecurityEvents.Read.All
Microsoft Graph
Reads Microsoft Defender alerts and security events to assess detection coverage.
AuditLog.Read.All
Microsoft Graph
Reads Entra and Microsoft 365 audit logs to confirm that logging is enabled and searchable.
Reports.Read.All
Microsoft Graph
Reads Microsoft 365 usage and authentication-method reports used to score identity posture.
InformationProtectionPolicy.Read.All
Microsoft Graph
Reads sensitivity-label policy so data-protection controls can be assessed.
Workload Configuration
Exchange.ManageAsApp
Office 365 Exchange Online
Runs read-only Exchange Online configuration cmdlets — mailbox auditing, mail-forwarding rules and anti-spam policy. Configuration only; message content is never read.
SharePointTenantSettings.Read.All
Microsoft Graph
Reads tenant-level SharePoint and OneDrive sharing settings to check external sharing limits.
Sites.Read.All
Microsoft Graph
Reads SharePoint site metadata and sharing configuration. Metadata only — no file contents are accessed.
TeamSettings.Read.All
Microsoft Graph
Reads Microsoft Teams configuration — meeting, messaging and guest-access policy.
Tenant Metadata
Organization.Read.All
Microsoft Graph
Reads tenant profile and licensing to scope the assessment correctly.
Domain.Read.All
Microsoft Graph
Reads verified domains so SPF, DKIM and DMARC records can be checked against your real sending domains.
Application.Read.All
Microsoft Graph
Reads app registrations and service principals to report over-privileged or stale third-party application consent.
AppCatalog.Read.All
Microsoft Graph
Reads the tenant app catalogue to assess third-party app governance.
On Exchange.ManageAsApp
This one carries a management name and will stand out on the consent screen. It is the mechanism Microsoft provides for application access to Exchange Online configuration, and we use it solely to open a read-only session and run configuration cmdlets. No cmdlet that writes, modifies or removes anything is invoked by the platform.
Controls no API can answer
Some CIS controls are not exposed by any published Microsoft interface, or ask whether a human review took place. We report those openly as requiring manual verification, with the portal page or command needed to check them — rather than guessing, or quietly leaving them out of the report.
You can pause or withdraw this access at any time, from the platform or from the Microsoft Entra admin centre.
Questions before you grant consent?
We would rather answer them now than have you approve something you are not comfortable with. Our full terms and privacy policy set out the same commitments contractually.