Yes. Safe Scan uses read-only Microsoft Graph permissions and never writes, modifies or stores anything from your tenant. The scan runs within your session, permissions are granted temporarily, and you can revoke them instantly from Microsoft Entra ID.
Six areas: data exposure across SharePoint and OneDrive, identity and access risks such as missing MFA and stale admins, compliance gaps like DLP and sensitivity labels, Teams configuration, licensing waste, and overall Microsoft 365 Copilot readiness.
Under five minutes for most tenants. Very large organisations (10,000+ users) may take up to ten. Results stream in progressively, so you see findings as they appear.
A prioritised report with a risk score per domain, a plain-English explanation of every finding, step-by-step remediation guidance and ready-to-run PowerShell. Export it as needed or share it with your team.