Running SafeScan across a client portfolio
A Microsoft 365 security assessment that scales past one client: multi-tenant scoring from one dashboard, where the recurring revenue sits, and how to pitch it.

A Microsoft 365 security assessment is a good piece of consulting and a poor product. You do it once, you hand over a document, and the engagement ends. Then you do the same work from scratch for the next client.
The partners who have made tenant assessment a real revenue line did one thing differently: they stopped selling the scan and started selling the rescan.
The problem with doing this per client
Run an assessment manually and the cost is mostly in the parts nobody pays for: getting consent arranged, remembering which checks you ran for the last client, rebuilding the report template, and discovering six months later that you cannot compare this quarter's findings to last quarter's because the method changed.
Across one client that is irritating. Across fifteen it is the reason the service never scales past the person who invented it.
What makes it scale is a fixed check set, applied identically everywhere, with the history kept per tenant. Twenty-three checks across six domains, run the same way in every estate, is not a constraint — it is the thing that makes a portfolio comparable.
One dashboard, every client
SafeScan's multi-tenant management puts every connected tenant behind one login, each with its own readiness score and findings. Practically, that changes three things.
You can triage across clients, not just within one. The question stops being "how is this client doing" and becomes "which of my fifteen clients has a critical finding this week". That is a different and much more sellable service.
Onboarding is a consent, not a project. Each client grants read-only access; the scan runs in minutes. Microsoft documents the admin consent flow, and because there is no write scope in the request, the conversation with the client's security team is materially shorter.
The same evidence works for everyone. Exports go to PDF for the client's board and Excel for your own engineers — and on the partner tier, PowerPoint, for the quarterly review you have to present rather than send.
Where the recurring revenue actually is
Not in the scan. The scan is the thing you give away, because a free first scan with a real finding in it sells the next conversation better than any deck.
The recurring revenue is in three places:
- The remediation. The findings come with steps and generated PowerShell, but someone still has to decide, schedule and run them, and talk to the client's Legal team about the guest accounts. That is billable work the scan has already scoped for you.
- The cadence. A tenant's posture decays — new sites inherit old patterns, guests accumulate, an admin leaves. A quarterly rescan is a recurring engagement with an artefact at the end of it.
- The evidence. Clients in regulated sectors increasingly have to show, not assert. A dated before-and-after pair is worth paying for in its own right.
Packaging it as something a client can buy
The assessment sells badly on its own because the client cannot picture the output. It sells well as a fixed-scope engagement with three named deliverables:
- A baseline. One scan, the score, and the findings ranked. Free or near-free, because its job is to make the next conversation concrete.
- A remediation sprint. A fixed number of days against the critical and high findings, with the generated scripts as the starting point and a rescan at the end as the proof. This is the billable core.
- A quarterly review. Rescan, compare, report, and a short list of what changed and why. Recurring, low-effort for you once the tenant is connected, and the thing that keeps you in the account.
The structural advantage is that the baseline scopes the sprint. You are not estimating blind — you are quoting against a list you have already seen.
The consent conversation
This is where partner-led assessments most often stall, so it is worth rehearsing.
The client's security team will ask what you are being granted. The answer is a set of read-only Microsoft Graph scopes, documented in Microsoft's permissions reference, with no write scope requested — so there is no path by which the tool could modify their tenant even if it were compromised.
They will ask what leaves the tenant. Metadata about configuration and permissions: site URLs, sharing settings, account states, policy coverage. Not file contents.
They will ask how to end it. Admin consent is revocable from their own portal, without involving you.
Having those three answers ready, in that order, turns a two-week security review into a ten-minute call. Not having them is how a signed engagement sits idle waiting for a tenant connection.
How to pitch it without overpromising
Two things to be straight about, because both will come up.
It is read-only. It finds and recommends; it does not fix. For a client worried about a third party touching their tenant that is the headline feature, not a limitation — but do not let a buyer believe they are purchasing automated remediation.
And it is a posture assessment, not a penetration test or a compliance certification. It tells you what Copilot would inherit and where the configuration is weak. It does not issue an attestation. Position it as the thing you do before the audit, and it sells easily; position it as the audit, and you will have a difficult meeting later.
Getting set up
Copilot SafeScan supports multiple tenants from one dashboard, with per-tenant scoring, history and exports. The Enterprise tier covers up to five tenants; the partner tier is unlimited and adds PowerPoint export. Pricing is published, and the first scan costs nothing — including on a client tenant you are trying to win.
Related: what moving a readiness score is worth, why posture decays between scans, and the remediation scripts.




