← Playbooks
Assessment

Security Posture Assessment

Evidence-based. Not a questionnaire. Only the domain you enter leaves your browser, as a DNS query to Cloudflare's public resolver.

All checks run in your browser or on your machine. The email check sends only the domain you enter, as DNS-over-HTTPS queries to Cloudflare's public resolver. No telemetry, no cookies, no accounts.
Tier A

Email Security Check

Enter your domain. We'll check SPF, DMARC, and DKIM configuration using public DNS lookups. Nothing is sent to our servers — the queries go directly to DNS.

Tier B

Command Checks

Run a command on your machine, paste the output below. The page interprets it locally in your browser — nothing is sent anywhere.

MFA Exception Count

How many users are excluded from Conditional Access MFA policies? Each exception is an attack surface.

Get-MgIdentityConditionalAccessPolicy | ForEach-Object { $_.Conditions.Users.ExcludeUsers } | Sort-Object -Unique | Measure-Object | Select-Object -ExpandProperty Count

Legacy Authentication Status

Is legacy auth (IMAP, POP3, SMTP basic auth) blocked? 99% of password spray uses legacy protocols.

Get-MgIdentityConditionalAccessPolicy | Where-Object { $_.Conditions.ClientAppTypes -contains "exchangeActiveSync" -and $_.State -eq "enabled" -and $_.GrantControls.BuiltInControls -contains "block" } | Measure-Object | Select-Object -ExpandProperty Count

Stale Admin Accounts

Admin accounts inactive for 90+ days. These are prime targets for credential theft.

$cutoff = (Get-Date).AddDays(-90); Get-MgDirectoryRoleMember -DirectoryRoleId (Get-MgDirectoryRole -Filter "displayName eq 'Global Administrator'").Id | Get-MgUser -Property SignInActivity | Where-Object { $_.SignInActivity.LastSignInDateTime -lt $cutoff } | Measure-Object | Select-Object -ExpandProperty Count

Mailbox Forwarding Rules

Forwarding rules to external addresses are the #1 BEC persistence mechanism. Any result > 0 may indicate compromise.

Get-Mailbox -ResultSize Unlimited | Get-InboxRule | Where-Object { $_.ForwardTo -or $_.ForwardAsAttachmentTo -or $_.RedirectTo } | Measure-Object | Select-Object -ExpandProperty Count

Windows Security Event Log Size

Default is 20MB — overwrites in hours on a busy server. Should be 1GB+ (1073741824 bytes).

wevtutil gl Security | findstr maxSize
Results

Your Score

—
Complete checks above to see your score
What this score means: This checks a handful of the most critical settings from the Configuration Drift playbook — the ones that show up in 59-84% of real breaches. It's not comprehensive. Run CISA ScubaGear for a full M365 assessment, or PingCastle for Active Directory.
Next Steps

What To Do Next