Microsoft 365 security & Copilot readiness · Free scan

Copilot readiness assessment — know what Copilot will see.

Copilot inherits every permission your users already have. SafeScan maps that exposure across your tenant, scores how ready you are out of 100, and hands your admin the exact PowerShell to close each gap — read-only, in under five minutes.

Available on Microsoft Marketplace Available on Azure Marketplace
Copilot SafeScan dashboard showing a Copilot Readiness Score of 71/100, items at risk and findings by severity
23automated checks across six domains
< 5 minfor a typical tenant scan
0–100Copilot Readiness Score
Read-onlyno write scope exists in the consent
The problem it solves

Copilot does not create exposure. It reveals it.

Every file a colleague could already open becomes something Copilot can quote. The risk was always there — Copilot just makes it trivially easy to find.

Permissions you set years ago

A folder shared with Everyone during a project in 2021, a site whose inheritance was broken to unblock one person, an anonymous link nobody revoked. Copilot reads all of it the moment you turn it on.

Reports without priorities

Generic compliance tools hand you a few hundred findings in no useful order. Knowing something is wrong is not the same as knowing what to fix first — and your admin loses a week deciding.

Scan, score, then actually fix it

SafeScan ranks every finding by severity, gives leadership one number to track, and generates the remediation script for each failing check. The loop closes in the same tool.

See it in action

Six surfaces, one scan

From the board-level score down to the individual script that fixes a single misconfigured site.

SafeScan dashboard with Copilot Readiness Score, severity breakdown and risk summary
Security dashboard

The whole posture on one screen

A Copilot Readiness Score out of 100 with a per-domain breakdown, tiles for items at risk and critical findings, a severity donut, and a service-by-service summary across SharePoint, Entra ID, Purview, Teams and Microsoft 365.

  • Readiness score, scored per domain
  • Items at risk, critical, high and medium counts
  • Members, guests and app registrations inventoried
SafeScan checkpoints showing all 23 checks across six domains
Security checkpoints

Twenty-three checks, six domains, one verdict each

Exposure, Identity, Compliance, Teams, Licensing and Copilot — every check returns pass, warning or fail with a score and a one-line explanation, so nothing needs interpreting.

  • Pass / warning / fail with a numeric score
  • Domain-level scores roll up to the total
  • Expand any check to see what it found
SafeScan risk findings ranked by severity with audience type and sensitivity
Risk findings

Every exposed item, worst first

The exact SharePoint path, who can reach it and how — internal, anonymous, external or broken inheritance — plus any sensitive-data matches, a recommended action and a status you can mark resolved.

  • Critical to low severity with risk scores
  • Audience type per item, including broken inheritance
  • Financial, legal and HR sensitivity flags
SafeScan remediation steps with linked Microsoft documentation
Remediation steps

The admin-centre path, written out

Each failing check comes with numbered steps through the relevant Microsoft admin centre and a link to the official documentation — so the fix is verifiable, not folklore.

  • Numbered steps per failing check
  • Microsoft documentation linked throughout
  • Covers SharePoint, Entra ID, Purview, Teams and M365
SafeScan generated PowerShell remediation script
PowerShell scripts

Generated for your tenant, ready to run

A commented PowerShell script per failing check, written against your own environment. Copy it, review it, run it in your admin terminal, then rescan to prove the finding is closed.

  • PowerShell 5.1 and 7+ compatible
  • Commented, with output logging for audit
  • Rescan to confirm the fix actually landed
SafeScan user and app registration inventory
Users & apps

The accounts and apps nobody is watching

Every user with MFA status, department and last sign-in, and every app registration with its secret expiry, permission count and risk flags — the governance gaps that never show up in a file-sharing report.

  • Filter by needs attention, disabled or guest
  • App secrets with nearest expiry date
  • Permission counts and risk flags per registration
Features

What each domain covers

Twenty-three checks, grouped the way an administrator actually thinks about a tenant.

Exposure

SharePoint and OneDrive oversharing, anonymous links, external sharing and sites whose permission inheritance has been broken.

Identity

MFA coverage, dormant and stale admin accounts, guest access and gaps in Conditional Access.

Compliance

DLP policy coverage, audit logging, sensitivity label usage and retention configuration.

Teams

External access settings, anonymous meeting joins, app governance and team sprawl.

Licensing

Unused licences, inactive users and SKU assignments worth revisiting before renewal.

Copilot readiness

The composite score, the oversharing Copilot would inherit, and the governance posture behind it.

PDF & Excel exports

Hand the findings to a CISO, an auditor or a client without giving them a licence and a login.

Multi-tenant management

One dashboard across every client tenant — built for MSPs and groups running several estates.

Rescan and compare

Re-run after remediation to prove the score moved, and keep a record of posture over time.

Privacy first

It reads. It never writes.

SafeScan asks for the minimum it needs to answer the question, and nothing beyond it.

Read-only by design

Only read scopes are requested, so there is no code path that could create, change or delete anything. The consent screen shows every permission before you approve it.

No file contents

Permissions and metadata only — who can reach what. The text inside documents, emails and Teams messages is never read.

Revoke in one click

Remove access from Microsoft Entra whenever you like. It ends immediately, and nothing is kept afterwards.

Trusted by IT teams & MSPs

What teams found on their first scan

Security leads, CTOs and managed service providers on what changed after running SafeScan.

★★★★★
“We found 47 files shared with Everyone before our Copilot rollout. SafeScan saved us from a major data incident.”
Head of IT SecurityUK financial services firm
★★★★★
“The Copilot Readiness Score gave our board a single number they could track month on month. It changed how we report on security posture.”
CTOProfessional services group
★★★★★
“As an MSP we manage 30+ Microsoft 365 tenants. The multi-tenant dashboard is exactly what we needed — one view, every client.”
Director of Managed ServicesUK MSP
How it works

Up and running in three steps

  1. 1

    Connect

    Sign in with Microsoft and approve read-only Graph consent. No agent to deploy, no app registration to build, no firewall change.

  2. 2

    Scan

    SafeScan runs all 23 checks across your tenant and scores each domain. Under five minutes for most estates — close the tab if you like.

  3. 3

    Fix, then prove it

    Work down the ranked findings using the admin steps or the generated scripts, then rescan to show the readiness score moving.

FAQ

Copilot SafeScan: your questions answered

Can we buy through Microsoft?

Yes. Copilot SafeScan is listed on the Microsoft Marketplace and Azure Marketplace, so it can be billed through your existing Microsoft agreement.

What does Copilot SafeScan actually check?

Twenty-three automated checks grouped into six domains — Exposure, Identity, Compliance, Teams, Licensing and Copilot. Each returns a pass, warning or fail with a numeric score, so you can see at a glance which part of the tenant is dragging your readiness down.

How long does a scan take?

Under five minutes for a tenant of up to a thousand users; larger estates can take about fifteen. It runs in the background, so you can close the tab and come back to the finished result.

What permissions does it need?

Read-only Microsoft Graph scopes — Sites.Read.All, User.Read.All, Policy.Read.All and AuditLog.Read.All. There is no write scope anywhere in the consent, so the app physically cannot alter your tenant. The OAuth screen lists every permission before you approve it.

Does it read the contents of our files?

No. SafeScan looks at permissions and metadata — who can reach what. The text inside your documents, emails and Teams messages is never read and never leaves your tenant.

Can we remove its access later?

Yes, in one click from Microsoft Entra. Access ends immediately and nothing is retained afterwards.

What is the Copilot Readiness Score?

A single figure out of 100, broken down per domain, summarising how exposed your tenant would be the day Copilot is switched on. It gives a board or steering group one number to track month on month instead of a spreadsheet of findings.

Do the PowerShell scripts change anything by themselves?

No. SafeScan generates them; you review and run them in your own admin terminal. They are commented and log their output, so the change is auditable afterwards — and you rescan to confirm the fix landed.

What does it cost?

There is a free tier that runs a real scan of a real tenant, and paid plans for single-tenant, multi-tenant and MSP use, all with a seven-day trial. Current plans and prices are on the SafeScan site — or ask us and we will talk you through which fits.

Is it the same thing as a Copilot readiness assessment?

It is the technical half of one, automated. Our AI governance & readiness service wraps the scan in the parts software cannot do: agreeing remediation with data owners, persona use cases, training and a phased roll-out plan.

Now on the Microsoft & Azure Marketplace

Buy it straight from Microsoft.

Prefer to buy through Microsoft? Get Copilot SafeScan on the Microsoft and Azure Marketplace — billed through your existing Microsoft agreement, with the procurement your finance team already trusts. The same product, one click away.

Microsoft Marketplace Azure Marketplace

See what Copilot would find in your tenant

Run a free scan and get your Copilot Readiness Score, ranked findings and the scripts to fix them. No card, no agents, nothing written to your tenant.

Read-only Graph scopes · no file contents read · revoke access any time

LogiSam Assistant Guided help & instant answers

Answers come from this website. Privacy policy

↑↓ to navigate ↵ to open