MISA Member · 580+ Security Checks · Entra ID · M365 · Beta

Microsoft Entra ID Security,
Done Right.

One scan. Every gap. Instant action. Siemserva audits your entire Entra ID tenant, maps findings to compliance frameworks, and tells you exactly how to fix everything — in seconds, not weeks.

580+
Security Checks
2
Compliance Frameworks
15+
Audit Domains
0
Agents to Deploy

Your Entra ID Tenant Has Hundreds of Security Settings

Each one is a potential gap an attacker can exploit. Most teams don't have the bandwidth to check them all.

Configuration Drift

Tenants accumulate misconfigurations over time — stale accounts, overly permissive apps, gaps in Conditional Access coverage.

Incomplete Tools

Microsoft Secure Score and Identity Protection cover pieces of the puzzle, but not the whole picture. Critical gaps slip through.

Compliance is Manual

Mapping every control to MCSB and SCuBA frameworks is tedious manual work — and mistakes mean failed audits.

Teams are Stretched

Small security teams can't manually review every user, device, app, role, and policy across a growing tenant.

580+ Checks Across Every Domain

Purpose-built for Microsoft Entra ID and M365. Every check maps to real compliance controls.

Identity & MFA

MFA gaps, phishing-resistant auth, risk policies, stale accounts

show checks
MFA registration gaps across all users and guests
Phishing-resistant auth enforcement (FIDO2 / Passkeys / CBA)
Legacy authentication protocols still permitted
Sign-in and user risk policy configuration & scope
Stale accounts inactive 30, 60, 90+ days
SSPR enabled scope and authentication method strength

Conditional Access

What-if testing, sign-in replay, gap detection, bypass risk

show checks
Apps reachable without any CA policy enforcing MFA
Sign-in replay — real sign-ins that bypassed MFA today
Over-broad trusted named locations and IP ranges
Device compliance not required for high-value apps
Persistent browser sessions and token lifetime settings
Guest and external user CA coverage gaps

Privileged Access

PIM policies, just-in-time access, break glass monitoring

show checks
Global administrator count (recommended ≤5)
Permanent role assignments vs PIM eligible-only
PIM activation approval and justification requirements
Break glass account monitoring and MFA bypass detection
Privileged role members enrolled in phishing-resistant MFA
Role activation alert and notification coverage

Applications

Expired creds, dangerous permissions, unverified publishers

show checks
Expired or soon-expiring client secrets and certificates
High-risk permissions (Mail.ReadWrite, User.ReadWrite.All)
Unverified publisher apps with sensitive permission scopes
User consent policies permitting risky app approvals
Multi-tenant app registrations exposing tenant data
Service principal credential age and rotation gaps

Endpoint Security

Device compliance, OS versions, stale devices

show checks
Device compliance policy gaps and unassigned user groups
Minimum OS version compliance (Windows, iOS, Android)
Stale and inactive devices still active in the directory
BitLocker and disk encryption enforcement settings
Defender for Endpoint enrollment coverage
Managed vs unmanaged device access to sensitive apps

Email Security

Anti-phish, anti-spam, safe links, malware policies

show checks
Anti-phishing impersonation protection scope and strength
Safe Links policy coverage — all users and all domains
Safe Attachments detonation sandbox for all mailboxes
DMARC, DKIM, and SPF record validation
Zero-hour auto purge (ZAP) for malware and phishing
Bulk mail thresholds and anti-spam connection filter

M365 Workloads

Teams, SharePoint, OneDrive, Exchange configs

show checks
SharePoint external sharing level and default link type
Teams guest access and external federation settings
OneDrive sync restrictions and domain allow-lists
Exchange transport rules and mail flow policies
Teams app permission policies for third-party apps
Microsoft 365 Groups external collaboration settings

Logging & Detection

Audit log coverage, SIEM readiness, threat detection

show checks
Unified Audit Log enabled with adequate retention period
Sign-in log retention meeting compliance requirements
Defender XDR alert policy coverage and routing
Privileged action and admin activity audit coverage
Real-time alerts for high-severity identity events
SIEM connector health and log ingestion gaps

Data & Network

Data protection, network security, AI security

show checks
DLP policy coverage for sensitive information types
Sensitivity label auto-classification and enforcement
Network-based conditional access and location restrictions
Microsoft Purview compliance center configuration
Microsoft Copilot & AI data protection and grounding policies
Guest data access restrictions and sharing settings

Live Dashboard — See Everything in Real Time

A full-screen terminal dashboard that makes security data usable. Findings stream in live as the scan runs.

siemserva — contoso.onmicrosoft.com
SIEMSERVA
Risk: 67
Live Scan 147 AI Insights Remediation 42 Errors
Time Tenant Audit Severity Description
14:32:01 Contoso ImConditionalAccess Critical No CA policy enforces MFA for all users
14:32:01 Contoso PaEmergencyAccess Critical Break glass account missing MFA exclusion
14:32:02 Contoso AsAppCredential High 3 app registrations with expired credentials
14:32:02 Contoso ImPimRolePolicy High Global Admin role allows permanent assignment
14:32:03 Contoso EsDeviceCompliance Medium 14 devices non-compliant with OS policy
14:32:03 Contoso ImAuthMethods Medium SMS auth still enabled for 28 privileged users
14:32:04 Contoso EmPhishPolicy Low Anti-phish policy missing user impersonation

Every Feature You Need. Nothing You Don't.

Built by security engineers who got tired of manually checking 580 settings across dozens of tenants.

Severity Scoring

Weighted scoring system where severity compounds — five findings at one tier equal one at the next. A single numeric score reflects both severity and volume.

Remediation Plans

Every finding comes with a risk narrative, recommended action, three-tier severity rating by privilege level, and step-by-step fix plans with PowerShell scripts and portal paths.

CA Deep Analysis

The most thorough Conditional Access analysis available — what-if scenario testing, sign-in replay forensics, discrepancy detection, and coverage gap identification.

Zero Agents

Runs locally and queries Microsoft Graph API directly. No agents to deploy, no infrastructure to manage. Fast mode for daily scans, full mode for weekly deep coverage.

Multi-Tenant

Scan all your tenants from one dashboard. Built for MSPs and enterprises managing dozens of Entra ID environments. Each tenant scored independently.

Trend Tracking

Compare scans over time to track improvement or regression. The Manager's Edition supports side-by-side comparison of any two scan exports.

AI-Powered Analysis — Your Security Copilot

Context-aware AI that understands your findings, explains risk in plain language, and generates production-ready remediation scripts.

A

Broad Security Insights

Press A on the Live tab to analyze visible findings. Scroll to different sections for different analysis.

A

Remediation Guidance

In-depth fix instructions with PowerShell commands, portal paths, prerequisites, and implementation order.

P

PowerShell Script Generation

On the Remediation tab, press P to generate production-ready .ps1 scripts via AI. Uses Microsoft Graph PowerShell SDK with -WhatIf support. Saved to file automatically.

A

Error Diagnostics

Root cause analysis for permission gaps, Graph API failures, throttling issues, and step-by-step fixes.

A

Deep Dive Analysis

Full risk, compliance, and remediation context on any single finding. Open details and press A.

A

Full Scan Analysis

Comprehensive analysis of the top 25 most impactful findings. Direct streaming via the Anthropic Claude API, or copy-paste friendly for any AI tool.

Privacy by Design

All AI prompts are PII-free. Tenant names, user names, system names — all anonymized before anything leaves your machine.

Works without an API key. Press A to copy a ready-to-paste prompt for ChatGPT, Copilot, Claude, Gemini, or any AI tool. Press Ctrl+V to import the response.

Easy API setup. Run siemserva setup-ai for an interactive wizard — supports Anthropic Claude API (direct streaming), OpenAI-compatible, and M365 Copilot. Or set ANTHROPIC_API_KEY directly.

Compliance Mapping — Built In, Not Bolted On

Every finding automatically maps to real compliance controls. Evidence links, justifications, and control codes included.

MCSB v2

Microsoft Cloud Security Benchmark

12 × 66

12 security domains, 66 controls. Microsoft's own benchmark, aligned with Defender for Cloud and NIST SP 800-53.

CISA SCuBA

Secure Cloud Business Applications

Federal

US federal security baselines for M365, increasingly adopted by private sector. Full control mapping with version tracking.

Export Everything — Your Data, Your Way

Self-contained HTML reports, browser-printable PDFs, AI-enhanced analysis, and database exports. All with a single keystroke.

Ctrl+R

Report Picker

4 HTML report types: Detailed, Compliance, Business Review, Remediation. Self-contained with embedded charts.

Ctrl+V

Paste AI

Paste AI responses from clipboard into any report for AI-enhanced analysis without an API key

O

Open as HTML

Open the current tab or any finding as a standalone HTML page in your browser. Print to PDF from there.

P

PowerShell Scripts

Generate executable .ps1 remediation scripts via AI on the Remediation tab. Saved to file automatically.

.sqlite

SDK & Database

Every scan writes to a standard SQLite database. Query with C#, Python, PowerShell, Power BI, or any SQL tool.

Enterprise-Grade Security

AES-256-GCM encryption with PBKDF2-SHA512 key derivation (210,000 iterations)

No data leaves your machine unless you explicitly export or email

Passphrase protection with show/hide toggle for demo-safe operation

PII-free AI prompts — tenant names anonymized before prompt generation

AOT-compatible — NativeAOT target with no reflection-based serialization

Local-only by default — SQLite database with WAL mode, no cloud dependency

SIEM Mode — Continuous Security Monitoring

Run Siemserva as a persistent security monitor. Scheduled scans, multi-tenant support, and automated alerts.

Scheduled Scans

Configurable intervals with a game-clock countdown to the next cycle

Multi-Tenant

Monitor all your tenants in a single, unified dashboard

Trend Detection

Track security posture changes across scan cycles over time

Simple, Transparent Pricing

Start free. Upgrade when you need more tenants, more checks, or AI API streaming.

Launch Promotion active now through June 1, 2026: Every tier gets every feature — all 580+ checks, all 4 report types, dashboard and exports. Only AI API streaming remains gated at Professional+.
Free
$0
forever
  • 2 tenants · 50 users
  • Core identity checks
  • Live dashboard & HTML reports
  • Copy/Paste AI (no API key needed)
  • PowerShell scripts & SDK
Download Free
Professional
$499/yr
after June 1, 2026
  • 10 tenants · 500 users
  • All 580+ checks
  • AI API streaming (Anthropic/OpenAI)
  • Compliance & Remediation reports
  • Manager's Edition (PDF & Excel)
Contact Sales
Enterprise
From $1,999/yr
Pro 5K · Pro 25K · Unlimited
  • 50–Unlimited tenants
  • 5,000–Unlimited users
  • All 580+ checks
  • Full AI API streaming
  • MSP & MSSP volume pricing
Contact Sales

Up and Running in Minutes

No agents. No complex setup. Just connect and scan.

1

Connect

Point Siemserva at your Entra ID tenant. Service principal or managed identity — your choice.

2

Scan

580+ checks run automatically. Results stream in live on the dashboard as they're found.

3

Analyze

AI-powered insights explain risk in business terms. PowerShell scripts generated for every fix.

4

Remediate

Export HTML reports, run generated PowerShell scripts, or open the Manager's Edition for PDF/Excel output.

Trusted by Microsoft. Proven in the Field.

Senserva is a Microsoft Intelligent Security Association (MISA) member and Microsoft Security Excellence Awards finalist. Built by the team behind Shavlik Technologies.

MEMBER OF THE Microsoft Intelligent Security Association Microsoft

MISA Member

Invited to join the Microsoft Intelligent Security Association for deep integration with Microsoft Sentinel, Entra ID, and Intune.

Microsoft Security Excellence Awards 2024 Microsoft Intelligent Security Association FINALIST Senserva Security ISV of the Year

Security ISV of the Year

Finalist in the 2024 Microsoft Security Excellence Awards — recognized for impact with Microsoft Sentinel and Defender.

Ready to Secure Your Entra ID?

One scan reveals every gap in your tenant. Download free and run your first scan in minutes.