MISA Member · 580+ Security Checks · Entra ID · M365

Microsoft Entra ID Security,
Done Right.

One scan. Every gap. Instant action. Siemserva audits your entire Entra ID tenant, maps findings to compliance frameworks, and tells you exactly how to fix everything — in seconds, not weeks.

580+
Security Checks
2
Compliance Frameworks
15+
Audit Domains
0
Agents to Deploy

Your Entra ID Tenant Has Hundreds of Security Settings

Each one is a potential gap an attacker can exploit. Most teams don't have the bandwidth to check them all.

🕑

Configuration Drift

Tenants accumulate misconfigurations over time — stale accounts, overly permissive apps, gaps in Conditional Access coverage.

🔎

Incomplete Tools

Microsoft Secure Score and Identity Protection cover pieces of the puzzle, but not the whole picture. Critical gaps slip through.

📋

Compliance is Manual

Mapping every control to MCSB and SCuBA frameworks is tedious manual work — and mistakes mean failed audits.

👥

Teams are Stretched

Small security teams can't manually review every user, device, app, role, and policy across a growing tenant.

580+ Checks Across Every Domain

Purpose-built for Microsoft Entra ID and M365. Every check maps to real compliance controls.

🔐

Identity & MFA

MFA gaps, phishing-resistant auth, risk policies, stale accounts

🔗

Conditional Access

What-if testing, sign-in replay, gap detection, bypass risk

👑

Privileged Access

PIM policies, just-in-time access, break glass monitoring

💻

Applications

Expired creds, dangerous permissions, unverified publishers

📱

Endpoint Security

Device compliance, OS versions, stale devices

📧

Email Security

Anti-phish, anti-spam, safe links, malware policies

☁️

M365 Workloads

Teams, SharePoint, OneDrive, Exchange configs

📊

Logging & Detection

Audit log coverage, SIEM readiness, threat detection

🔒

Data & Network

Data protection, network security, AI security

Live Dashboard — See Everything in Real Time

A full-screen terminal dashboard that makes security data usable. Findings stream in live as the scan runs.

siemserva — contoso.onmicrosoft.com
SIEMSERVA
Risk: 67
Live Scan 147 AI Insights Remediation 42 Errors
Time Tenant Audit Severity Description
14:32:01 Contoso ImConditionalAccess Critical No CA policy enforces MFA for all users
14:32:01 Contoso PaEmergencyAccess Critical Break glass account missing MFA exclusion
14:32:02 Contoso AsAppCredential High 3 app registrations with expired credentials
14:32:02 Contoso ImPimRolePolicy High Global Admin role allows permanent assignment
14:32:03 Contoso EsDeviceCompliance Medium 14 devices non-compliant with OS policy
14:32:03 Contoso ImAuthMethods Medium SMS auth still enabled for 28 privileged users
14:32:04 Contoso EmPhishPolicy Low Anti-phish policy missing user impersonation

Every Feature You Need. Nothing You Don't.

Built by security engineers who got tired of manually checking 580 settings across dozens of tenants.

Severity Scoring

Weighted scoring system where severity compounds — five findings at one tier equal one at the next. A single numeric score reflects both severity and volume.

🛠

Remediation Plans

Every finding comes with a risk narrative, recommended action, three-tier severity rating by privilege level, and step-by-step fix plans with PowerShell scripts and portal paths.

🔍

CA Deep Analysis

The most thorough Conditional Access analysis available — what-if scenario testing, sign-in replay forensics, discrepancy detection, and coverage gap identification.

🚀

Zero Agents

Runs locally and queries Microsoft Graph API directly. No agents to deploy, no infrastructure to manage. Fast mode for daily scans, full mode for weekly deep coverage.

🌐

Multi-Tenant

Scan all your tenants from one dashboard. Built for MSPs and enterprises managing dozens of Entra ID environments. Each tenant scored independently.

📈

Trend Tracking

Compare scans over time to track improvement or regression. The Manager's Edition supports side-by-side comparison of any two scan exports.

AI-Powered Analysis — Your Security Copilot

Context-aware AI that understands your findings, explains risk in plain language, and generates production-ready remediation scripts.

A

Broad Security Insights

Press A on the Live tab to analyze visible findings. Scroll to different sections for different analysis.

A

Remediation Guidance

In-depth fix instructions with PowerShell commands, portal paths, prerequisites, and implementation order.

G

PowerShell Script Generation

AI generates production-ready .ps1 remediation scripts using Microsoft Graph PowerShell SDK with -WhatIf support.

A

Error Diagnostics

Root cause analysis for permission gaps, Graph API failures, throttling issues, and step-by-step fixes.

A

Deep Dive Analysis

Full risk, compliance, and remediation context on any single finding. Open details and press A.

A

Full Scan Analysis

Comprehensive analysis of the top 25 most impactful findings. Direct API integration with Claude or copy-paste friendly.

Privacy by Design

All AI prompts are PII-free. Tenant names, user names, system names — all anonymized before anything leaves your machine.

Works without an API key. Siemserva generates ready-to-paste prompts for ChatGPT, Copilot, Claude, or any AI tool you trust.

Compliance Mapping — Built In, Not Bolted On

Every finding automatically maps to real compliance controls. Evidence links, justifications, and control codes included.

MCSB v2

Microsoft Cloud Security Benchmark

12 × 66

12 security domains, 66 controls. Microsoft's own benchmark, aligned with Defender for Cloud and NIST SP 800-53.

CISA SCuBA

Secure Cloud Business Applications

Federal

US federal security baselines for M365, increasingly adopted by private sector. Full control mapping with version tracking.

Export Everything — Your Data, Your Way

PDF reports, Excel workbooks, encrypted sharing, and database exports. All with a single keystroke.

Ctrl+P

PDF Report

Tab-aware export with compliance scorecards and time estimates

Ctrl+X

Excel

Multi-worksheet workbook with findings, users, roles, and entities

Ctrl+M

Email

Encrypt and email in one action with passphrase protection

Enterprise-Grade Security

AES-256-GCM encryption with PBKDF2-SHA512 key derivation (210,000 iterations)

No data leaves your machine unless you explicitly export or email

Passphrase protection with show/hide toggle for demo-safe operation

PII-free AI prompts — tenant names anonymized before prompt generation

AOT-compatible — NativeAOT target with no reflection-based serialization

Local-only by default — SQLite database with WAL mode, no cloud dependency

SIEM Mode — Continuous Security Monitoring

Run Siemserva as a persistent security monitor. Scheduled scans, multi-tenant support, and automated alerts.

🕒

Scheduled Scans

Configurable intervals with a game-clock countdown to the next cycle

🌎

Multi-Tenant

Monitor all your tenants in a single, unified dashboard

📩

Email Alerts

Immediate notification when new High or Critical findings appear

📈

Trend Detection

Track security posture changes across scan cycles over time

Manager's Edition

A standalone read-only viewer for sharing audit results with leadership. Executive dashboards, compliance scorecards, trend comparison, and AI analysis — no login or scanning required.

  • 5-tab interactive dashboard — Overview, Findings, Compliance, Remediation, AI
  • Executive-level reporting — business risk focus, not technical jargon
  • Trend comparison — compare two scans side-by-side
  • AI analysis — Claude-powered briefings with PowerShell generation
  • PDF & Excel export — configurable templates for any audience
  • Encrypted file support — open .siemserva and .siemserva-db files

Supported Formats

.sqlite

Raw database

.siemserva

Encrypted export

.siemserva-db

Encrypted database

$ siemserva-manager scan.sqlite
$ siemserva-manager export.siemserva
$ siemserva-manager current.sqlite --compare previous.siemserva

Up and Running in Minutes

No agents. No complex setup. Just connect and scan.

1

Connect

Point Siemserva at your Entra ID tenant. Service principal or managed identity — your choice.

2

Scan

580+ checks run automatically. Results stream in live on the dashboard as they're found.

3

Analyze

AI-powered insights explain risk in business terms. PowerShell scripts generated for every fix.

4

Remediate

Export PDF reports, share encrypted results, or run generated scripts to fix issues immediately.

Trusted by Microsoft. Proven in the Field.

Senserva is a Microsoft Intelligent Security Association (MISA) member and Microsoft Security Excellence Awards finalist. Built by the team behind Shavlik Technologies.

MEMBER OF THE Microsoft Intelligent Security Association Microsoft

MISA Member

Invited to join the Microsoft Intelligent Security Association for deep integration with Microsoft Sentinel, Entra ID, and Intune.

Microsoft Security Excellence Awards 2024 Microsoft Intelligent Security Association FINALIST Senserva Security ISV of the Year

Security ISV of the Year

Finalist in the 2024 Microsoft Security Excellence Awards — recognized for impact with Microsoft Sentinel and Defender.

Ready to Secure Your Entra ID?

One scan reveals every gap in your tenant. Schedule a demo to see Siemserva in action on your own data.

$ siemserva --tenantids <your-tenant-id>