Logo

Office 365 Vulnerability Scanning


Monitor Office 365 against best practice standards and custom policies for secure configuration. Detect and remediate common user mistakes in real time. Ensure compliance with standards by auditing your Office 365 configuration and file sharing for non-compliant security controls.

Based on NSA research, Misconfiguration and Poor Access Control are the two most common and easiest to exploit vulnerabilities for public cloud systems like Office 365.

Continuous Office 365 Configuration & Compliance Monitoring

The Pegasus Labs Office 365 Vulnerability Scanning platform monitors Office 365 & Azure AD configuration and audit logs to identify vulnerabilities and misconfigurations. It provides prioritised actions, automatic remediation, compliance monitoring and policy enforcement.

99% of cloud security failures are due to human error Gartner

The difficulty of native compliance monitoring

Office 365 includes 50+ separate apps, depending upon licensing, each with their own configuration. Overall there are 1000+ configuration settings, some of these have reasonable, secure defaults others do not.

Manually review is time consuming and requires staff with expert level understanding, as settings can have unexpected impacts on security and end users.

Annual configuration reviews do not work for cloud systems, where new software releases are deployed every month with additional applications, features and settings.

There are also vulnerabilities which cannot be disabled, such as the ability to share content with everyone in a tenant.

On average, every employee has access to 11 million files and 17% of all sensitive files are accessible to all employees. Varonis

Identify & Fix Misconfiguration

Pegasus Labs' platform will scan your Office 365 tenant and identify vulnerabilities caused by misconfiguration and unintended end user actions.

Get Visibility

Automatic monitoring of Office 365 configuration changes and compliance impact. Send alerts to your SIEM or via email, AWS SNS, AWS Kinesis or Azure Event Grid.

Enforce Policies

Customise best practice security policies to suit your environment and track compliance against them in real time.