What we watch
Refreshed every few minutes, not once a quarter. These are the signals that tell us a tenant is drifting or under attack.
Sign-in risk & identity
Risky users from Identity Protection, blocked MFA attempts, new admin roles, new user detection, and blast radius analysis showing what an account could reach if compromised.
Secure Score & CIS benchmark
Microsoft Secure Score with benchmarking, plus the CIS Microsoft 365 Foundations Benchmark v7 with 160 checks. Trended over time, with policy drift detection when a setting quietly changes.
Alerts, one feed
Defender XDR, Defender for Cloud Apps, Identity Protection and compliance alerts in a single queue. Known-benign noise is suppressed automatically and AI triage summarises what is left.
Conditional Access & MFA
Which policies are on, who is excluded, MFA coverage, and passkey readiness across the tenant.
Files leaving the business
Files shared to personal email addresses, stale external shares, sharing links, mass deletion and mass download detection, and a tenant-wide permissions audit.
Mailbox rules & quarantine
Forwarding rules, transport rules, quarantine and SPF, DKIM and DMARC health. Silent auto-forward rules are how most business email compromise starts.
Shadow AI & cloud apps
AI visibility across tools, cloud discovery for shadow IT, and the OAuth apps your staff have granted access to company data.
Devices & vulnerabilities
Intune compliance and configuration, BitLocker keys, RoboShadow vulnerability scanning and Heimdal threat prevention on the same endpoint dashboard.
Licences & spend
Assigned versus unused licences, renewal notifications and Microsoft price changes, with wholesale cost data from our distributors.
What we pull from your tenant
Watchmont connects to Microsoft Graph and Exchange Online with a documented, read-only permission set. This is the data it collects.
Identity & access
- βUsers, licences, admin roles and sign-in history
- βMFA coverage, methods and passkey readiness
- βRisky users and risk detections
- βConditional Access and Security Defaults status
- βEnterprise apps and OAuth consent grants
- βSign-in logs with targeted search
Files & sharing
- βTenant-wide permissions audit
- βSharing links and recent library shares
- βFiles shared to personal email addresses
- βStale external shares
- βMass file deletion and download signals
- βStorage drill-down and SharePoint usage
Email & domains
- βSPF, DKIM and DMARC health
- βMailbox and transport rules
- βQuarantine and email trace
- βTenant allow and block list
- βMobile devices connected to mailboxes
Security & posture
- βSecure Score and CIS Benchmark v7 results
- βDefender alerts and incidents
- βAI usage and cloud discovery
- βSign-in and audit logs
- βService health and Global Secure Access visibility
Devices
- βIntune managed devices and compliance
- βConfiguration and compliance policies
- βBitLocker recovery keys
- βVulnerabilities and endpoint threats via RoboShadow and Heimdal
Licensing & usage
- βLicence assignment and unused seats
- βMicrosoft 365 usage and Teams Phone reporting
- βWholesale cost, renewals and price changes
- βAzure subscription visibility
Alerts, Secure Score, sign-in risk and licences refresh every few minutes. Policies, groups and SharePoint data refresh on a schedule, and report data is rebuilt nightly. None of your files or email content is ever stored.
What we manage
Monitoring needs nothing more than read-only access. When you want us to act, the connection moves to read/write and we handle the day-to-day from the same console, with every action logged.
Joiners & leavers
The onboarding wizard creates the user, clones licences, groups and manager settings, and sends the welcome email. Offboarding converts the mailbox to shared, blocks sign-in, revokes sessions, reclaims licences, hands over mailbox and OneDrive access, and removes devices.
Contain an account
One click blocks sign-in, revokes sessions, resets the password and disables risky inbox rules. Temporary Access Pass, scheduled sign-in blocks and travel mode cover the everyday cases.
Conditional Access
Design, deploy and review the policies that decide who gets in, from where, and on what device.
Intune & devices
Compliance and configuration policies, lock-down of unmanaged devices, and remote wipe or retire for a lost laptop.
Mailbox forwarding and inbox rules, transport rules, quarantine release, allow and block senders, trusted IPs and email trace.
Sharing & data
Revoke external shares, remove permissions and links, restore deleted files, create encrypted view-only labels and review Purview DLP policies.
Risk remediation
Dismiss or remediate risky users, resolve alerts, and push anything that needs a ticket straight into our service desk.
What you receive
You never log into anything. Reports come to you, branded, on a weekly or monthly schedule, with a full send history.
Management Report
The monthly PDF for leadership: headline posture, trends, alerts resolved by month, how you compare, phishing results, SharePoint estate, vulnerability updates, service desk tickets, licence waste, invoices and an AI-written executive summary.
Management Summary
A one-page executive view for directors and partners: where you stand, what changed, what we recommend.
Security Assessment
Pass, warn and fail findings against best practice and the CIS Microsoft 365 Foundations Benchmark v7. Useful before a Cyber Essentials assessment.
Fifteen more on demand
Users, licence optimisation, groups, alerts history, sign-in logs, mailbox rules, domain analysis, Teams, endpoint security, M365 apps health, Teams Phone, M365 usage, AI usage, phishing simulations and dark web.
Safe to let us in
Giving anyone access to your Microsoft 365 tenant is a trust decision. This is how the platform is built to earn it.
- βThree connection tiers: report-only, read-only and read/write. You choose how much we can do.
- βIt never stores your files or email content. Reports carry names, dates and permission entries, not documents.
- βEvery permission is documented. Ask us what the app can see and we hand you the list.
- βNo standing credentials. Access uses short-lived app tokens, never a signed-in admin session.
- βYou can revoke access at any time by removing the app from your tenant.
- βNew permissions are never added silently. Your Global Admin must consent again.
- βData stays in the UK, in AWS London, encrypted at rest and in transit, with point-in-time recovery.
- βOur engineers sign in with Microsoft single sign-on only, scoped to your tenant, with a full audit log of every action.
Beyond Microsoft 365
The same reports fold in the other tools that protect your business, so you get one picture rather than ten portals.
See what your tenant looks like from our side
Book a free tenant review. We connect read-only, run a security assessment, and walk you through the results. No commitment.
Book a Tenant Review