Improve Your Cloud Security Based On Facts
Assess your organization's Azure and Microsoft 365 security posture in just five minutes with this free Cloud Security Self-Service Assessment. Receive prioritized recommendations that help you take the most effective remediation actions. It's the essential first step toward protecting your organization from cyber threats efficiently and with confidence.

Why This Assessment
Why take a Cloud Security Self-Service Assessment?
Building cloud resilience starts with understanding your current security posture.
Know Your cloud Security Posture
Cyber resilience starts with visibility. Understanding your security posture before attackers identify a weakness is critical to protecting your organization and surviving a cyber-attack.
Keep Critical Operations Running
Ensure your essential business processes remain available and secure. Gain the insights needed to identify and address security risks before they impact your operations.
Enable Secure Modernization
Modernize your organization with confidence. Understand how cloud services, AI, and new technologies impact your security posture, so you can embrace innovation without compromising your security.
The evolving threat landscape demands greater agility.
A proactive and strategic approach, supported by intelligent security processes, enables organizations to protect critical operations, maintain continuous visibility, and respond to incidents quickly and effectively while minimizing disruption to business productivity. Achieving this requires a risk-aware, intelligent solution built for the complexities of modern cloud environments.
Cloud Security Self-Service Assessment
This Cloud Security Self-Service Assessment is offered to you free of charge to help you understand what your cloud security maturity is today. It is a simple and quick exercise providing you with valuable insights and recommendations. To complete the assessment, we need around 5 minutes of your time. It is a great starting point to work towards cloud resilience.
What's Included
What is included?
The Cloud Security Self-Service Assessment will guide you through a simple process.
Sign in with Microsoft
Confirm your Microsoft admin account — the same sign-in your team already uses for Azure and Microsoft 365.
Self-Service Assessment
Scanning your environment
What about my data?
Your data is used exclusively to provide you with relevant insights and recommendations that help improve your cloud security posture. We do not share assessment data with any third parties, and all information is handled in accordance with our data retention policies. All data collected during the assessment is stored within a dedicated PostgreSQL server with complete tenant isolation specifically designed for managing these assessments. During the analysis process, your data goes through a controlled workflow that includes data extraction and clean up, enrichment, analysis, and encrypted transfer back to the dedicated PostgreSQL server, If you would like additional information, please visit our FAQ.
FAQs
Find answers to the most common questions about the Self-Service Assessment. Select a topic below to get started.
Select a topic below
What is the Self-Service Assessment?
What is Self-Service Assessment?
The Self-Service Assessment is offered to you free of charge to help you understand your current cybersecurity maturity. It is a simple and quick exercise that provides valuable insights and recommendations. This is a great starting point for working towards cyber resilience.
What is the output of this Self-Service Assessment?
Upon completion of the scans and questionnaire, the Self-Service Assessment will provide you with two reports. One short and concise report presenting a high-level overview of your security position and the most important recommendations. Secondly, it will provide you with a detailed report of each security topic and insights into vulnerabilities found in your cybersecurity estate.
Is this an official Cybersecurity Audit?
No. This Self-Service Assessment is meant to provide you with quick insights into your security position based on some essential cybersecurity controls. While it will help you make security improvements effectively, the results of this assessment will not serve as Cybersecurity audit or prove any form of compliance to local regulations or security frameworks.
Is the Self-Service Assessment relevant to me?
If you worry about your organization’s cybersecurity position and you would like to receive relevant insights and recommendations with only a small effort; yes, it is! Cybersecurity incidents are all too common. Organizations are increasingly at risk due to a worldwide rise in cybercrime. Many organizations do not have adequate resources to safeguard the data they need to operate. This assessment will help you to understand your cybersecurity position and make effective improvements.
Does any type/size of customer fit Self-Service Assessment?
The Self-Service Assessment will be of help to anyone who wants to get fact-based recommendations to help improve its security position. The Self-Service Assessment helps you to gain insights into your security position based on a list of essential security controls. If you work for a larger organization, you will need to manage more than just the essential controls measured by this Self-Service Assessment. You might want to opt-in for a Full-Service Assessment via the Microsoft self-nomination page, or via your Microsoft representative.
Do I need an assistance in performing the successful scan?
The Self-Service Assessment platform is designed to allow IT administrators to independently complete a cybersecurity assessment. If you have access to administrative credentials and are working as an IT administrator or similar role, you will be fine. Are you less tech-savvy but you do worry about your cybersecurity position? Ask your IT administrator to run this Self-Service Assessment for you!
Why is the Self-Service Assessment offered free of charge?
In today’s landscape, your security approach should start with the key Zero Trust principles. But too often, complexity stand in the way. It is our commitment to helping you solve this, as we build security for all, delivered from the cloud. That’s why we offer this Self-Service Assessment to you free of charge to provide recommendations to effectively improve your security position. Security is a team sport, and we’re all in this together!
What are the sources the Self-Service Assessment collects information from?
Self-Service Assessment collects relevant information by extracting data from a small sample of the Windows Operating Systems (we recommend scanning 1 server and 4 workstations), Microsoft 365 services, the Azure platform, local Active Directory and Email DNS configurations. For each source, a different method of data collection is used. You will find more information per scan source in the FAQ.
What is the estimated time investment to run the Self-Service Assessment?
The average time spent to run the Self-Service Assessment is two hours. During your assessment, you will also see the time tracker to show you what steps you still need to take and how much time is still required.
Do I need to complete the assessment in one go?
No, you can set your own pace. After registration we will keep your assessment active for one month, so you can come back and pick up where you left off.
What kind of access rights are needed for the Self-Service Assessment?
To successfully run the Self-Service Assessment, you would need certain permissions. Important to know, the required credentials are not saved to the Self-Service platform. For each scan source, you would need to possess the following credentials:
- Email DNS: the email DNS scan retrieves public information from your external DNS. You only need to list your email domain and there is no permission needed to run this scan.
- Active Directory: a domain user account will allow you to run the AD scan successfully.
- Endpoint: you need access to a local administrator account to successfully run the endpoint scan agent.
- Microsoft Cloud: you need to have access to a Global Administrator account to set-up the Microsoft Cloud scan. Please note that the scan is not performed using these credentials, but the scan is performed through the Microsoft Cloud API.
If you need more information, you can ask your service partner or share your credentials and we will get back to you.
Self-Service Onboarding
How do I register for the Self-Service Assessment?
You can begin the registration process from the home page by selecting the button labelled ‘Start your assessment’. This will either guide you through creating your assessment or display a message explaining how to request access if approval is required.
Why do I get a Microsoft Consent and what is it?
After your registration you will receive an email with a link that will take you to a Microsoft consent screen. You will see an example of the screen below. With the consent, we can provide you with Single Sign-On access to the Self-Service platform. By accepting the consent, you allow the Self-Service platform access to limited information of your user profile to allow you to successfully login.
What is the checklist?
The checklist is designed to help you prepare for the Self-Service Assessment. It outlines the permissions, accounts, and actions required to complete the data collection successfully. The purpose of the checklist is to help you verify that everything is in place before you begin, so the assessment runs smoothly and without interruptions.
I receive a 503 error after my registration, what do I do?
When you receive the email and try to continue to your assessment, you might see a 503 error message, like below:
This message is presented when the processes of creating your Assessment environment is still running. Preparing your environment usually takes 15 minutes after registering and could take up to 30 minutes. To resolve this, simply wait for 30 minutes and try to open your environment again. If the issue persists, please let us know by sending an email to customersupport@aesonsolutions.com.
Data handling and Privacy
What information is stored in the Self-Service Assessment platform?
All customer information collected in a Self-Service Assessment is stored in a customer-dedicated SQL database instance in a tenant dedicated to managing Self-Service Assessments.
How is my data analyzed?
Your data is sent to the Self-Service Assessment platform via SSL encrypted communication. There it will be analyzed by a data streaming engine. The analyzed data is then stored in the Self-Service Assessment platform. Only analyzed and aggregated information is stored in the Self-Service Assessment platform. Endpoint Survey and Active Directory On-Prem Survey data is sent to a centralized server for data collection using one of two routes: direct (on port 443, using a custom frame protocol) or indirect (on port 443, using an HTTPS post request, which then internally relays it to the data collector using the custom frame protocol.) In the analysis stage, your data undergoes a stepped process that covers: the extraction of derived data and data cleanup, enrichment of your data, analysis of your data (effectively rules-based analysis), followed by shuffling your data to your own dedicated SQL Database. Additional analysis of your data may be performed during report generation.
Who has access to the collected data?
Only users granted with access to the customers’ tenant have access to the information customer collected data. TENET maintains privileged service and support-account access, and any such access supports the delivery of the service. TENET’s privileged account access procedures and tooling monitor any staff access using a privileged account.
What level of protection is offered?
All data collected is stored in a customer-dedicated SQL database. Data in transit is encoded; communication over HTTPS protocol is tunneled securely. TENET’s privileged account access procedures and tooling monitor staff access using a privileged account.
How is data from my local network shared with the Self-Service Assessment platform?
Data is collected using either (or both) Endpoint Surveys and an Active Directory On-Prem Survey. Both surveys send their collected data using one of two routes: direct (on port 443, using a custom frame protocol) or indirect (on port 443, using an HTTPS post request, which then internally relays it to the data collector using the custom frame protocol.)
Are my corporate credentials stored in the Self-Service Assessment platform?
We took a deliberate and active decision not to store any corporate credentials in the self-service assessment platform. It is worth noting that the Microsoft Cloud Scan also does not save corporate credentials. The associated set-up agents’ only purpose is to guide your through registering and authorizing the Cloud Scanner in your Microsoft Cloud tenant. When completed, this will allow a Self-Service Scan to traverse your tenant.
How long is my data stored in the Self-Service Assessment platform?
Your Self-Service Assessment is active for 30 days. Most assessments end within days from the registration. Your dedicated SQL Server Databases and on-Demand Web Services will be deleted from the environment on day 30.
Customers who wish their data removed prior to the 30 days may contact support at customersupport@aesonsolutions.com to complete verification of the request and ultimately early removal.
Is personal data stored in the Self-Service Assessment platform?
By the nature of the data collected, some data is identifiable as personal. Specifically, this includes user first and last names on local and active directory accounts, user account names, and the user account name in paths located in the computers’ user directory. Browser History information is collected but not associated with a specific user, and complete URL and query string collection are disabled in the Self-Service Assessment. Please notice our data retention policy. Your information is only stored for a short period of time.
Does the Self-Service Assessment use my corporate information for other purposes?
The platform uses your corporate information solely to provide insights into your cybersecurity position and to provide recommendations on improvements. The scanned data is anonymized before being saved into a secure data lake, which is used exclusively for analysis and reporting purposes. All information collected from your IT environment is treated confidentially and is not shared with any third parties. As presented in our Privacy Statement, we might share your contact details with our partners to allow them to help and communicate with you about Cybersecurity solutions.
How does the solution create the AI recommendations?
The AI analysis is performed by the Azure AI Foundry solution, which is securely hosted by TENET. Importantly, your data never leaves the boundaries of the environment: All AI processing takes place within the secure infrastructure managed by TENET. Your data is not shared with third parties, nor is it used to train shared AI models or improve external services. The AI models and analysis are isolated within the environment, ensuring that your information remains confidential and protected at all times. These practices align with Microsoft’s strict privacy and security commitments for Azure AI Foundry: your data is not accessible to other customers or external providers, and is not used for any purpose beyond delivering analysis for recommendations. The Self-Service Assessment applies AI to generate tailored, risk-based recommendations for your environment. During data analysis, the AI examines the data from multiple perspectives, leveraging both historical patterns and the specifics of your organisation to identify anomalies and potential risks that might otherwise go unnoticed.
Microsoft Cloud Scan methodology
How does the Self-Service Assessment retrieve data from my Microsoft Cloud tenant?
The Self-Service Assessment will allow you to download a local application to set-up the Microsoft Cloud scan. It will require you to login with a global administrator account to your Microsoft tenant. The login takes place in the application which runs on your machine. This means the Self-Service platform does not receive and/or store the credentials of your Global Admin account. Furthermore, the account credentials are not used to run the actual scan. The Global Admin credentials are used to create a Microsoft Entra ID Application with a set of permissions in your Microsoft Cloud tenant. The Microsoft Entra ID Application uses the Microsoft Graph API and Rest API to retrieve the relevant information from your Microsoft Cloud tenant.
What level of permissions are set on the Microsoft Entra ID application for the Microsoft Cloud scan?
A Microsoft Entra ID Application is retrieving the information from your Microsoft Cloud tenant via the Graph API. To do so, the Microsoft Entra ID Application is provided with a limited set of permissions. See below.
Graph API application permissions:
- Application.Read.All
- AuditLog.Read.All
- DeviceManagementConfiguration.Read.All
- DeviceManagementDevices.Read.all
- Directory.Read.All
- Group.Read.All
- IdentityProvider.Read.All
- IdentityRiskEvent.Read.All
- Policy.Read.All
- Reports.Read.All
- SecurityEvents.Read.All
- Sites.Read.All
- User.Read.All
- DeviceManagementApps.Read.All
- RoleManagement.Read.Directory
- RoleManagement.Read.All
Office 365 management Application permission
- ActivityFeed.Read
SharePoint Application permission
- Sites.FullControl.All
- The Microsoft Cloud scan requires “Full control” permissions on SharePoint Online to access the Microsoft SharePoint Search API. This API only allows searches with the Full Control permission. With lower permissions the scan fails.
Azure subscriptions
The scan will also look at your Azure subscriptions. During the setup of the scan, the application will automatically add Microsoft Entra ID read permissions to all available Azure subscriptions where possible. If the account does not have the necessary permissions to add the reader role, information about those subscriptions will not be collected.
Are the provided permissions revoked after the scan takes place?
Yes, The created Microsoft Entra ID Application on your tenant will delete itself upon completion of the scan.
Why does the Microsoft Cloud scan take long?
The Microsoft Cloud scan will retrieve relevant data from your Microsoft Cloud tenant. One of the scans involves a keyword search to find privacy sensitive data. This scan queries the SharePoint Online search API to collect the data. When scanning a Microsoft Cloud tenant with many SharePoint site collections (500+) the scan will take quite a while to complete. However, the SharePoint Online scan is limited to only scan for two hours. In that timeframe enough information is collected for analysis.
Azure subscriptions
The scan will also look at your Azure subscriptions. During the setup of the scan, the application will automatically add Microsoft Entra ID read permissions to all available Azure subscriptions where possible. If the account does not have the necessary permissions to add the reader role, information about those subscriptions will not be collected.
Additional information
The Self-Service Assessment methodology
The Self-Service Assessment provides insights into your organization’s cybersecurity posture, and actionable items to mitigate the discovered risks. The Self-Service Assessment is built by TENET, a Microsoft-focused Cloud Risk Intelligence Platform trusted to continuously monitor Azure and Microsoft 365 risk. To allow a more practical, no-commitment starting point, TENET provides this Self-Service Assessment. The Self-Service Assessment consists of scans of various resources in your IT environment and a questionnaire based on the Zero Trust Architecture Defense Areas defined by Microsoft. It is the perfect way to start improving the essential cybersecurity controls based on facts, with only a limited effort.
What is Zero Trust?
The Zero Trust Architecture principles are defined by The Open Group, a global consortium that enables the achievement of business objectives through technology standards. The architecture principles are product agnostic, and it is up to your organization’s strategy which products and solutions you eventually will implement. Though, as this assessment is offered to you by Microsoft, we include the relevant Microsoft products as well as their Zero Trust Reference Architecture. More information on can be found at theopengroup.org and microsoft.com/en/security/business/zero-trust.
What are the Zero Trust Principles?
The Zero Trust Principles are:
1. Verify explicitly
Always authenticate and authorize based on all available data points, including user identity, location, device health, service or workload, data classification, and anomalies.
2. Use least privileged access
Limit user access with just-in-time and just-enough-access (JIT/JEA), risk-based adaptive polices, and data protection to help secure both data and productivity.
3. Assume breach
Minimize blast radius for breaches and prevent lateral movement by segmenting access by network, user, devices, and app awareness. Verify all sessions are encrypted end to end. Use analytics to get visibility, drive threat detection, and improve defenses.
Instead of assuming everything behind the corporate firewall is safe, the Zero Trust model assumes breach and verifies each request as if it originates from an open network. Regardless of where the request originates from or what resource it accesses, Zero Trust teaches us to “never trust, always verify.” Every access request is fully authenticated, authorized, and encrypted before granting access. Micro-segmentation and least privileged access principles are applied to minimize lateral movement. Rich intelligence and analytics are utilized to detect and respond to anomalies in real time.
More information on can be found at theopengroup.org and microsoft.com/en/security/business/zero-trust.
What is the assessment background
Security is relative to the threats and risks an organization faces; there is no absolute security. That which is good for one organization can be overkill for another, a one-size fits all security program does not exist. Therefore, it is important to look at what the customer would need to improve their security. During the Self Service Assessment, the cybersecurity practices level has been measured by answering a Questionnaire. A strong foundation is necessary therefore this report is using the practices of the Zero Trust Architecture. Zero trust is explained by Microsoft as follows: “Zero Trust is the essential security strategy for today’s reality. In 2020, the global pandemic compelled nearly every organization to embrace a Zero Trust strategy as employees went remote, virtual private networks (VPNs) were breached or overwhelmed, and digital transformation became critical to organizational sustainability. The mandate emerged for a Zero Trust approach to verify and secure every identity, validate device health, enforce least privilege, and capture and analyze telemetry to better understand and secure the digital environment.” This text is taken from the Zero Trust whitepaper (microsoft.com/en-us/security/business/zero-trust). After the pandemic people kept working from home and more organizations support that people work from home. Since the working from home is kept as an option by organizations, the zero trust architecture is still relevant.
What are the Zero Trust Defense Areas?
The Zero Trust Defense Areas are six topics defined by Microsoft. See below.
- Identities
- Endpoints
- Apps
- Data
- Infrastructure
- Network
What do I do post Self-Service Assessment?
Do I need to continue assessing my environment after the Self-Service Assessment?
Every organization should periodically check their cybersecurity position. Not only to identify new risks, but also to report on progress. It is imperative to show that you know what your current cybersecurity position is and that you make progress over time. Not just to internal stakeholders, but also to auditors, shareholders and government entities. The Self-Service Assessment gives you a snapshot; TENET’s full platform extends that into continuous monitoring across Azure and Microsoft 365, so you’re not starting from scratch each time. Want to know more? Reach out to sales@aesonsolutions.com.
How can I get a more extensive scan of my environment?
TENET offers a full Cloud Risk Intelligence Platform that goes well beyond this Self-Service Assessment, covering IAM, anomaly detection, compliance, and AI risk monitoring across your entire Azure and Microsoft 365 estate. Book a free 30-minute expert assessment to see what a full scan of your environment surfaces.