Scanner login
A Point2IT demo user opens the tool. Microsoft is not used for website login, and the Point2IT production tenant is not connected.
Point2IT AI Guard
Microsoft Secure Score is not a control framework. AI Guard runs a Point2IT baseline against the customer tenant, including the gaps Microsoft does not score: GDAP, backup, logging retention, guest access, break-glass and admin consent.
A Point2IT demo user opens the tool. Microsoft is not used for website login, and the Point2IT production tenant is not connected.
Each scan signs into the customer M365 tenant with that tenant’s admin account, like Connect-MgGraph in the PowerShell checker.
The engine started as your Tenant Health Checker. The product baseline is stricter than Secure Score on purpose.
Mapped to NIS2 themes. Microsoft-sourced checks are labelled as signals. Everything else is Point2IT practice.
| ID | Control | NIS2 | Source |
|---|---|---|---|
| P2IT-ID-001 | MFA for all users | access-control | Point2IT |
| P2IT-ID-002 | Phishing-resistant MFA for privileged roles | access-control | Point2IT |
| P2IT-ID-003 | Legacy authentication blocked | access-control | Point2IT |
| P2IT-ID-004 | SMS and voice not used as primary MFA | access-control | Point2IT |
| P2IT-ID-005 | Microsoft Authenticator enabled | access-control | Point2IT |
| P2IT-ID-006 | Temporary Access Pass available for onboarding | access-control | Point2IT |
| P2IT-CA-001 | Conditional Access baseline present | risk-management | Point2IT |
| P2IT-CA-002 | Compliant or managed devices for corporate access | risk-management | Point2IT |
| P2IT-PRIV-001 | GDAP / partner relationships inventoried | supply-chain | Point2IT |
| P2IT-PRIV-002 | No expired GDAP relationships | supply-chain | Point2IT |
| P2IT-PRIV-003 | Break-glass accounts documented and excluded | business-continuity | Point2IT |
| P2IT-NIS2-001 | Unified audit log retention meets Point2IT minimum | logging | NIS2-gap |
| P2IT-NIS2-002 | Guest and supplier access restricted | supply-chain | NIS2-gap |
| P2IT-NIS2-003 | Tenant-level backup beyond Microsoft recycle bins | business-continuity | NIS2-gap |
| P2IT-NIS2-004 | Incident response contacts registered | incident-handling | NIS2-gap |
| P2IT-NIS2-005 | Admin consent workflow for applications | supply-chain | Point2IT |
| P2IT-SS-001 | Microsoft Secure Score used as a signal only (>= 70%) | risk-management | Microsoft |