Clear Tenant
Clear Tenant: M365 Security Posture Management
At the centre is Tenant Hygiene, a running health score that tracks compliance and stale device signals, risk and exposure indicators from your security and policy posture, and movement over time so you can verify whether remediation is actually working. Teams start their day with the highest-risk and stalest tenants, drill into the hygiene category that matters, assign the fix, then re-check the trend once changes land. Alongside it, Clear Tenant covers Secure Score analysis, identity posture, policy analysis, incidents and alerts, blast radius, mail flow and advanced hunting, with baselines, patching and reporting built in.
Connected in an afternoon, not a project
Clear Tenant reads from the Microsoft stack you already run. There is nothing to install on a device and nothing to migrate.
Scoping call
We walk through how many tenants you manage, what you already have delegated access to, and which parts of the platform matter most to your team.
Connect a tenant
Grant delegated access to a single tenant first. No agent is deployed, no configuration is changed, and nothing is written back until you ask for it.
See your first hygiene score
The tenant is assessed across identity, devices and posture, so you see real findings from your own estate rather than a demo dataset.
Roll out across the portfolio
Once you are satisfied with what the first tenant shows, connect the rest and start deploying baselines and indicators across all of them.
Managed service providers and internal IT teams responsible for more than one Microsoft 365 tenant. The more tenants you run, the more the platform saves, because everything that would normally be repeated per tenant happens once.
Organisations with a single tenant still get the hygiene scoring, Secure Score history, blast radius analysis and alert triage, but the multi-tenant deployment features matter less.
No. Clear Tenant sits on top of the Microsoft security stack you already license, reading from Defender XDR, Entra ID and Intune through delegated access. It does not duplicate their function, and it does not require you to move away from any of them.
What it changes is the workflow around them: instead of opening each portal in each tenant, you work from one console and the actions land in the tenant they belong to.
No. Alert analysis is built into Clear Tenant. Every incident arrives with a summary of what happened, false-positive reasoning, supporting evidence and recommended actions.
Security Copilot offers comparable triage support, but it is licensed separately and billed by provisioned compute, which is a meaningful additional cost before a single alert is reviewed.
No. Clear Tenant works entirely through delegated access to the Microsoft Graph and Defender APIs. Nothing is installed on an endpoint or a server, and no client software is pushed to end users.
Clear Tenant reads posture and incident data through delegated access and stores the snapshots needed to show trends over time. Access is scoped to the permissions you grant, and can be revoked from your own tenant at any point.
Full detail on hosting location, retention periods and the handling of automated alert analysis is provided as part of the scoping call, and is covered by the data processing terms in your service agreement.
Connecting the first tenant is a delegated-access grant rather than a deployment, so the initial hygiene assessment can usually be reviewed the same day. Additional tenants are added individually once you are happy with what the first one shows.
Baseline import and rollout takes longer, because it depends on how many policies you want standardised and how much variation exists between your tenants today.
Nothing breaks in your tenants. Policies deployed through Baseline Deployment Studio and indicators pushed to Defender live in Microsoft, not in Clear Tenant, so they remain in place. You lose the central console, the trend history and the automated analysis, not your configuration.
Still have a question we have not answered?
The scoping call is a technical conversation with the engineers who built the platform, not a sales script. Get in touch and ask whatever you need to.
The same work, without the portal-hopping
Everything below is possible using Microsoft's native portals. The difference is how many of them you open, how much of it you rebuild per tenant, and how much of it you can prove afterwards.
| The job | Native portalsTenant by tenant | Clear TenantOne workspace |
|---|---|---|
| Knowing which tenant needs you today | Open each one Sign in to every tenant in turn and read its dashboard. Prioritisation is whatever you remember from last week. | Ranked on arrival One hygiene score per tenant across identity, devices and posture. Highest-risk and stalest surface first. |
| Explaining why a Secure Score dropped | Point in time The current score is visible, the history behind it much less so. Attributing a drop to a specific control means digging. | Day-by-day trail Every daily movement with the exact controls and points behind it, so regressions are named rather than guessed at. |
| Triaging an alert at 2am | Licensed separately Comparable AI triage is available through Microsoft Security Copilot, licensed on its own and billed by provisioned compute. | Included Every alert arrives analysed: what happened, false-positive reasoning, evidence and recommended actions. No separate licence. |
| Rolling a policy out to every client | Rebuild each time Recreate the policy in each tenant, or script it. Drift between tenants is only found when something breaks. | Import once, deploy wide Import from a source tenant, stage into baseline groups, scope assignments, deploy to targets, with import timestamps throughout. |
| Blocking a hash you found this morning | Once per tenant Add the indicator manually in each tenant. Expiry and coverage are tracked in whatever spreadsheet you keep. | One block list Approve once, push across the portfolio as Defender custom indicators, manually or daily. Status shows drift and failures per tenant. |
| Answering "are we getting better?" | Assembled by hand Export, paste into a deck, repeat next quarter. The comparison is only as good as what someone captured last time. | Already recorded Trend movement is captured continuously, so remediation can be shown to have worked rather than asserted. |
Clear Tenant does not replace Microsoft 365
It sits on top of the Microsoft security stack you already pay for, reading from Defender XDR, Entra ID and Intune through delegated access. Nothing is duplicated, no agent is deployed, and every action taken lands in the tenant it belongs to.
One console for every Microsoft 365 tenant you manage
Posture, investigation and configuration in a single workspace, built around how engineers actually work across a multi-tenant estate.
Secure Score Command Center
See the current score against the maximum available, what moved it over the last 30 days, and which controls drove the change. Trend status flags whether a tenant is improving steadily or swinging, and the next milestone shows exactly how many points remain.
Control-level score history
Every daily movement, with the specific controls behind it and the points each one gained or lost. When a score drops, you can see whether real-time protection was turned off or Defender sensor data collection stopped reporting, rather than guessing.
Target Plan
Set a target secure score and generate a prioritised, sequenced path to reach it. The plan estimates engineering timeframe, points required and confidence, then separates quick wins from the changes carrying real risk, including compatibility and change-management considerations.
Incidents and alerts, triaged
A working queue banded by priority, with open counts, oldest open and median time to close. Every alert is analysed automatically: what happened, the reasoning behind a false-positive assessment, the supporting evidence and recommended next actions, alongside cross-domain context from the tenant's own hygiene signals. That analysis is built in. Microsoft Security Copilot delivers comparable triage support, but it is licensed separately and billed by provisioned compute, which puts it well beyond most mid-market budgets before a single alert is reviewed.
Advanced Hunting
Query Defender XDR data with KQL. Start from a ready-made hunt, build one step by step, or write your own. The library is organised by investigation type, covering alerts and triage, identity and sign-ins, email and phishing, and device and process activity.
One block list, every tenant
File hashes and URLs harvested from incident evidence are reviewed in one place, then deployed across the whole portfolio as Microsoft Defender custom indicators, manually or on a daily auto-push. Approved indicators carry a default expiry, and the status view shows drift, expiry and failures per tenant.
Baseline Deployment Studio
Import policies from a source tenant, stage them into baseline groups, configure assignment scope, then target tenants and deploy. Policies are grouped by purpose, tracked by type and platform, with import timestamps so you always know which version of a baseline is in play.
Application patching
Select applications from the WinGet catalogue and manage patching policy from one place. Search by app name, publisher or package ID, with the latest available version shown against each entry so you can see what is behind before you build the policy.
Licence optimisation
A sortable, filterable inventory of licences by product, with utilisation shown against seats assigned. Optimisation suggestions surface unassigned paid seats that should be reassigned or reduced, so spend is visible rather than discovered at renewal.
Built by Microsoft-certified engineers, not generalist developers. Clear Tenant was designed by the people who run these tenants every day, which is why it follows the workflows engineers actually use rather than the ones a product roadmap assumes.
One account is compromised. What can they actually reach?
Detection tells you something happened. Blast radius tells you how far it goes, and it is the question every client asks first.
Blast Radius analysis
A single compromised mailbox is rarely a single mailbox. Delegated access, forwarding rules set months ago, transport rules nobody documented and shared distribution groups all extend reach far past the account that was breached.
Clear Tenant maps that reach before an incident happens, so the containment decision is made against evidence rather than assumption, and the client gets a straight answer about exposure on the same call.
- Mailbox delegations
- Mail forwarding
- Transport rules
- Personal inbox rules
- Distribution groups
- SharePoint exposure
Identity posture
Assessment of Microsoft 365 identity security across the tenant, so weak authentication and over-privileged accounts surface before someone exploits them.
Policy analysis
Review of tenant security configurations and policies, with false-positive handling so findings can be marked and tracked rather than re-triaged every cycle.
Mail flow analysis
Review of mail-related security risk across the tenant, covering the routing and rule configuration that phishing and business email compromise depend on.
Device visibility
Inventory and posture information for managed devices, feeding the stale-device and compliance signals that drive each tenant's hygiene score.
Remediation tracking
Progress is measured over time rather than at a point, so you can show a client that what you changed last quarter actually moved their posture.
Built on delegated access
Clear Tenant reads from Defender XDR, Entra ID and Intune through delegated permissions. No agent is deployed and every action lands in the tenant it belongs to.
Contact us today
Connect one Microsoft 365 tenant and see its real hygiene score, Secure Score history and blast radius in the same session. No agent to deploy, no configuration changed, and no Security Copilot licence required. Speak to the Microsoft-certified engineers who built the platform and use it across client tenants every day.