Point2ITAI Guardpoint2it.ai

Point2IT AI Guard

Baseline security scans for Microsoft 365 and Azure — NIS2-shaped, Point2IT-owned.

Microsoft Secure Score is not a control framework. AI Guard runs a Point2IT baseline against the customer tenant, including the gaps Microsoft does not score: GDAP, backup, logging retention, guest access, break-glass and admin consent.

Scanner login

A Point2IT demo user opens the tool. Microsoft is not used for website login, and the Point2IT production tenant is not connected.

Customer admin credentials

Each scan signs into the customer M365 tenant with that tenant’s admin account, like Connect-MgGraph in the PowerShell checker.

Fill Microsoft gaps

The engine started as your Tenant Health Checker. The product baseline is stricter than Secure Score on purpose.

Point2IT baseline (17 controls)

Mapped to NIS2 themes. Microsoft-sourced checks are labelled as signals. Everything else is Point2IT practice.

IDControlNIS2Source
P2IT-ID-001MFA for all usersaccess-controlPoint2IT
P2IT-ID-002Phishing-resistant MFA for privileged rolesaccess-controlPoint2IT
P2IT-ID-003Legacy authentication blockedaccess-controlPoint2IT
P2IT-ID-004SMS and voice not used as primary MFAaccess-controlPoint2IT
P2IT-ID-005Microsoft Authenticator enabledaccess-controlPoint2IT
P2IT-ID-006Temporary Access Pass available for onboardingaccess-controlPoint2IT
P2IT-CA-001Conditional Access baseline presentrisk-managementPoint2IT
P2IT-CA-002Compliant or managed devices for corporate accessrisk-managementPoint2IT
P2IT-PRIV-001GDAP / partner relationships inventoriedsupply-chainPoint2IT
P2IT-PRIV-002No expired GDAP relationshipssupply-chainPoint2IT
P2IT-PRIV-003Break-glass accounts documented and excludedbusiness-continuityPoint2IT
P2IT-NIS2-001Unified audit log retention meets Point2IT minimumloggingNIS2-gap
P2IT-NIS2-002Guest and supplier access restrictedsupply-chainNIS2-gap
P2IT-NIS2-003Tenant-level backup beyond Microsoft recycle binsbusiness-continuityNIS2-gap
P2IT-NIS2-004Incident response contacts registeredincident-handlingNIS2-gap
P2IT-NIS2-005Admin consent workflow for applicationssupply-chainPoint2IT
P2IT-SS-001Microsoft Secure Score used as a signal only (>= 70%)risk-managementMicrosoft