Security Overview
Microsoft 365, Entra ID & Active Directory posture — June 2026 assessment
Critical
4
Findings requiring immediate action
High
9
High-severity findings
Medium
17
Medium-severity findings
Passed
198
Controls passing
Total Tests
228
M365 + Entra ID + AD
71
/ 100
B−
Moderate risk posture. Critical findings require immediate remediation to prevent compromise.
4 Critical
9 High
17 Medium
Score by Category
Identity & Authentication
Conditional Access
Active Directory (on-prem)
Exchange & Mail Security
Teams & Collaboration
SharePoint & Data
Findings by severity (this scan)
Critical
High
Medium
Low
Score trend (last 6 months)
Jan
Feb
Mar
Apr
May
Jun
Critical & High Findings
View all →
| ID | Finding | Category | Severity |
|---|
All Findings
228 tests run · 30 findings · 198 passed
| ID | Finding | Category | Severity | Framework |
|---|
Remediation Roadmap
Prioritized 90-day action plan for First Oklahoma Bank
0
Completed
13
Total items
Configuration
Assessment settings, test suites, compliance frameworks & notifications
Scan Settings
Scope and frequency of assessment runs
Test Suites
Select which test categories to include
Identity & Authentication (EIDSCA)
44 tests · Entra ID auth methods
Conditional Access (CA)
32 tests · Policy coverage & gaps
Active Directory (on-prem)
58 tests · PingCastle + PowerShell
Exchange & Mail Security
38 tests · SPF, DKIM, DMARC, SMTP
Teams & Collaboration
28 tests · External access & app governance
SharePoint & Data Protection
28 tests · Sharing, DLP, guest access
Compliance Frameworks
Map findings to regulatory requirements
CISA SCuBA (M365)
CISA Secure Cloud Business Applications
CIS Microsoft 365 Benchmark
CIS Benchmark v3.0
FFIEC CAT / Cybersecurity
Financial institution compliance
NIST 800-53 Rev 5
Federal security controls mapping
MITRE ATT&CK
Technique-level threat mapping
Notifications & Alerts
Alert delivery when findings are detected
Email digest after each scan
Summary of new and resolved findings
Score regression alert
Alert if score drops more than 5 points
New critical finding alert (immediate)
Real-time alert for critical severity
Export Reports
Download your assessment results in multiple formats
Executive Summary
One-page summary for leadership and board presentation. Non-technical, risk-focused with score, grade, and top priorities.
Full Findings Report
Complete technical findings with severity ratings, affected controls, and remediation guidance. For IT and security teams.
Remediation Roadmap
90-day prioritized action plan with step-by-step PowerShell commands and remediation procedures for each finding.
Raw JSON Data
Full machine-readable export of all test results, scores, and metadata. Ideal for importing into SIEM or ticketing systems.