GTools.pro — Zero-Knowledge M365
ToolsPricingDesktopIndustriesCompareBlogSecurityTrustAbout
  1. Home
  2. Microsoft 365 Security Audit

Microsoft 365 Security Audit Tool

Audit Microsoft 365 security — SharePoint permissions, oversharing, privileged access, Copilot readiness. 25 dedicated security and audit tools.

Quick answer

A Microsoft 365 security audit here maps permission sprawl, surfaces oversharing before a Copilot rollout reaches it, and flags orphaned and privileged accounts across the tenant. Findings export as structured evidence a remediation team can act on directly. This is a detective control: findings are reported here, and remediation happens in the Microsoft admin consoles, not automatically.

FAQ

What’s in a complete M365 security audit?

A full audit covers identity and access (privileged roles, orphaned accounts, conditional access policies), data exposure (oversharing, anonymous links, external sharing patterns), permission sprawl (broken inheritance, unique permissions on subsites), governance (Teams policies, retention, lifecycle), and tenant configuration drift. GTools.pro includes 25 tools in total: 20 audit tools plus three dedicated security centers, a content-lifecycle center, and unified tenant configuration management — covering all of these.

Why do I need this before deploying Copilot?

Microsoft 365 Copilot answers prompts using anything the asking user has access to. If your tenant has oversharing — files shared with "Everyone" or unsealed external links — Copilot will surface that content in answers, including to people who shouldn’t see it. The Copilot Readiness tool quantifies your exposure before deployment so you can remediate first.

How is this different from Microsoft Purview or Defender?

Purview and Defender produce signals at the tenant level. GTools.pro converts those signals into actionable lists: every file with public sharing, every site with broken inheritance, every privileged account that hasn’t logged in for 90 days. The output is a CSV or Excel you can hand to a remediation team — not a dashboard you have to interpret.

Can I schedule audits to run automatically?

Yes — twelve audit tools support Scheduled Reports, where the platform runs the audit on a cron schedule and emails the result to a distribution list. Examples: weekly oversharing report, monthly privileged access review, quarterly orphaned users. Scheduled reports use a documented zero-knowledge exception (encrypted refresh tokens stored server-side).

What licenses does this require?

Most audit tools work with any M365 license. Privileged Access requires Azure AD P2 (PIM activations are a P2 feature). Defender for M365 alerts in the Security Dashboard require Defender for Office or M365 E5 Security. Each tool page lists its specific license requirements.

How we compare

Are you a SIEM?

No. gtools.pro generates point-in-time evidence files. For continuous detection and alerting, use Vectra AI, Microsoft Sentinel, or Defender for Cloud Apps.

Are you SOC 2 or ISO 27001 certified?

Not currently. We have a documented zero-knowledge architecture (Argon2id KDF + XChaCha20-Poly1305), with a formal internal audit completed April 2026 and all critical findings closed in v1.10.51. SOC 2 is on the roadmap. The ZK design materially reduces the risk surface a SOC 2 audit would examine.

How do you compare to Microsoft Defender for Cloud Apps?

Defender for Cloud Apps collects file metadata and content, retains 180 days, and shares across Defender XDR, Sentinel, Purview, and Entra ID Protection. gtools.pro proxies Graph API responses momentarily and never persists tenant data. Different purposes: Defender for continuous monitoring; gtools.pro for structured audit evidence without a permanent cloud footprint.

How do you compare to CoreView?

CoreView is enterprise governance with policy enforcement and automation, quote-only, scaled to enterprise procurement cycles. gtools.pro is structured evidence generation without a multi-month procurement cycle. Different personas — if CoreView fits your size, take it.

Does mailbox content leave my tenant during an audit?

No. Security tools don’t request mailbox content scopes — only Graph metadata: sign-in activity, Conditional Access state, MFA registration, OAuth consents, sharing structure. Compare to Defender for Cloud Apps (which documents collecting file metadata + content) and Lepide (DLP scans file content).

What scopes do you require in Entra ID?

Customer-registered Azure app you control, revocable at any time. Typical scopes: Directory.Read.All, Policy.Read.All, AuditLog.Read.All, SecurityEvents.Read.All, Sites.Read.All, Reports.Read.All. No Mail.Read, no Files.ReadWrite, no Teams message scopes.

Some tools are cloud-only on Desktop — which ones?

Three Config Export tools (M365 DSC, Security & Compliance Center, Exchange Security) shell out to PowerShell modules incompatible with the Desktop runtime in v1. All 20 audit and compliance tools and the Security Dashboard run natively on Desktop. No competitor in the category ships a desktop-native security audit application at all.

How do you compare to Netwrix?

Netwrix is long-retention audit log (10+ years), $20/user/yr, Windows-server install. gtools.pro is point-in-time evidence without long-term storage, zero-knowledge, no server to maintain. Different use cases — if you need a 7-year audit trail for PCI/HIPAA/SOX, choose Netwrix.

Audit limitations and drawbacks

The M365 security audit is a detective control, not for live remediation. Watchtower enumerates roles, shared links, MFA posture, Conditional-Access coverage, and Defender alert state — then reports. Remediation is never automatic: the operator acts on the findings inside Entra ID, Defender XDR, or Purview using the existing admin consoles.

Severity rankings use the documented internal heuristic and may diverge from Microsoft Secure Score. Coverage stops at the Graph permission surface granted to the audit app; workloads behind tenant-licensed add-ons (Defender XDR, Purview eDiscovery Premium) require the matching license to enumerate. The audit cannot detect what Microsoft does not expose via Graph — a known limitation of any Graph-based scanner.

About the platform

This is a zero-knowledge toolkit. It helps IT admins, MSPs, security teams run their cloud safer. Use it inside a browser. Or install our Mac or Windows app.

Tenant secrets stay on your disk. We never store, log, or read them. Our server only sees billing metadata.

How it works

  1. You unlock a local vault with a passphrase. Argon2id stretches it.
  2. Tokens get sealed with XChaCha20-Poly1305 before any sync.
  3. X25519 protects shared keys. Ed25519 signs every action.
  4. Each operation runs against Graph from your device, not ours.

What you can do

  • Back up mail. Files. Chat threads.
  • Export Intune settings. One click.
  • Audit SharePoint shares. Spot risk.
  • Find idle sites. Reclaim quota.
  • Score Copilot. Plan rollout.
  • Move tenants. No staging.
  • Client-side keys. Always on.
  • Your data. Your disk.
  • One app. Many tenants.

Editions

  • Solo. Free. Three tools. No card.
  • Backup. Durable backups for your tenant.
  • Watchtower. Audits and alerts on risk.
  • Move. Tenant migration suite.
  • Blueprint. Config export for enterprise.
  • Everything. Full platform plus desktop and support.

Trust signals

  • Open source crypto primitives via libsodium.
  • Public threat model at /trust.
  • Public pricing. Direct purchase. No sales call.
  • Cancel any time inside settings.
  • EU-based billing. PayPal checkout today; card payments planned.

Built in Germany by Voltage Brothers Infrastruktur UG. Suits cloud workspaces of every size.

Standards, regions, retention

Regions: Frankfurt. Dublin. North America. Retention scales from 7 days. Up to unlimited. Schedules run hourly. Daily. Weekly. Monthly. Reports export as JSON. CSV. PDF. Evidence packs bundle hashes. Chain-of-custody metadata sits beside them.

Standards covered: ISO 27001 controls. SOC 2 readiness. NIS2 mapping. GDPR Article 28 terms. Audit logs cover entitlement events. Billing actions. License rotations. Workload payloads never reach a remote log.

Who uses it

  • Tenant admins running a single estate.
  • MSPs managing dozens of customer cloud workspaces.
  • Security teams investigating sharing risk.
  • Compliance officers preparing audit evidence.
  • Acquisition teams during M&A integration.
  • Procurement teams reviewing vendor risk.
  • Solo consultants billing by workspace hour.

Supported regions

Frankfurt, Dublin, Amsterdam, Stockholm, Paris, plus North America. Annual revenue scales from small studios up through multinational estates. Payment today is PayPal checkout; card payments (Stripe) are planned.

Numbers worth knowing

  • 49 capabilities. 6 editions.
  • Free tier: 3 tools. 0 cards.
  • Argon2id. 256 MB memory cost.
  • XChaCha20-Poly1305. 256-bit cipher.
  • X25519. 256-bit shared keys.
  • Ed25519. 100% of writes signed.
  • Retention: 7 days. 365 days. Or unlimited.
  • Founded 2024. Built in Germany.
  • Backup edition: 14 EUR per user per year.
  • Watchtower edition: 7 EUR per user per year.
  • Move edition: 9 EUR per migrated seat. One-time. 450 EUR project minimum.
  • Blueprint edition: 449 EUR per tenant per year.
  • Everything bundle: 2490 EUR per tenant per year.
  • Audit reports: 25 dedicated checks.
  • Config export: 9 Microsoft 365 workloads.
  • Migration record set in April 2026. 153,584 files. 0 errors.
  • Compliance posture updated in 2026.
  • Pricing: 1 public page. 0 sales calls.
  • Cancellation: 1 self-service page.
  • Audit logs: 90 days. Entitlement events.
  • GDPR Article 28. 27 member states.
  • NIS2 Directive. 18 sectors. Live since 2024.
  • SOC 2 Type II evidence. JSON. CSV. Signed PDF.
  • ISO 27001. 93 Annex A controls. 2022 revision.

Product.

  • Tools.
  • Pricing.
  • Desktop.
  • Security.
  • Industries.
  • Compare.
  • Download.
  • Blog.
  • For MSPs.
  • For SMB IT.

Company.

  • About.
  • Trust & Compliance.
  • Privacy Policy.
  • Terms of Service.
  • Impressum.

Connect.

  • hello@gtools.pro.
  • GitHub.

© 2026 GTools.pro · A product of Voltage Brothers Infrastruktur UG (haftungsbeschränkt).