CY Cyber — M365 Security
Microsoft 365 security · asset · cost — in one scan

See who can access what across SharePoint, OneDrive & Teams — and what it's costing you.

Cyber — M365 Security scans your Microsoft 365 tenant read-only and surfaces the anonymous share links, ex-employee OneDrives, and storage hogs your backup and MDM tools never flag. Security posture, asset hygiene, and storage cost in under 10 minutes — without ever touching your files.

Sign in with Microsoft No credit card All 7 modules unlocked Read-only by default EU-hosted
If you're the only one watching

You already know something's off. You just can't prove it yet.

Microsoft 365 admin centre tells you what exists. It doesn't tell you what's risky, dormant, or expensive. That's the gap Cyber — M365 Security closes — for teams that don't have a dedicated security engineer.

Audit is next quarter.

You don't know which SharePoint sites have external guests, which OneDrives hold regulated data, or whether "Anyone with the link" is still enabled from a 2021 rollout.

Teams & Groups have multiplied.

Anyone can spin up a new Team. Hundreds exist. Nobody remembers half of them. You have no single view of which are dormant, which still hold data, or which are safe to archive.

"Public" was the default.

Teams and channels created as Public expose files, messages, and meeting notes to every licensed user in the org — including finance data, HR conversations, M&A docs. You'd never spot it by clicking through the admin centre.

Owners left. Teams kept running.

A Team's only owner was an employee who offboarded eight months ago. It's now orphaned — nobody can approve new members, review access, or archive it. And you have dozens of them.

The contractor left six months ago.

Account is disabled. Licence is revoked. OneDrive with 312 GB is still sitting there. Share links they created? Probably still live. Probably.

The M365 storage bill keeps climbing.

Finance wants to know why. You need a list of the top storage hog sites, quotas >90%, and OneDrives of users who haven't logged in for a year. No dashboard gives you that in one view.

An OAuth app has mailbox scope.

You didn't approve it. An employee clicked "Allow" months ago. It hasn't been used in 90+ days — but the consent is still there, ready to pull email.

A Team site was shared with a vendor.

Vendor relationship ended in March. The guest still has Owner rights. You'd never find it clicking through the admin centre — there are 140 sites.

You have one hour per week for this.

You need the answer, not a tool. A Monday-morning digest you can forward to your accountant-turned-compliance-officer — with evidence timestamped and exportable.

Four questions

Could you answer these in a meeting — today?

Your auditor, your cyber-insurer, and your biggest customer's security questionnaire all ask versions of the same four questions. "I'd have to check" is the answer that costs deals, premiums, and audit findings.

1 How many "Anyone with the link" shares exist in your tenant right now?
2 How many OneDrives of people who left still hold company data — and how many GB?
3 Which Teams have external guests in them, and who approved each one?
4 Which third-party OAuth apps can read your mailboxes today?

If any answer is "I'd have to check" — that check is the free trial. Ten minutes, read-only, and you'll have all four answers with timestamps. Not knowing isn't neutral: it's the same exposure, minus the chance to fix it first.

Get the four answers →
Three jobs, one scan

SharePoint, OneDrive & Teams — now tripled in value.

Every read-only scan doubles as a security audit, an asset-hygiene report, and a storage-cost exercise. You pay for one tool and three different people on your team stop complaining.

Security posture

Find the things an attacker — or your auditor — would find first.

  • Anonymous "anyone-with-the-link" shares (no expiry, no audit)
  • External guests holding Owner / admin rights on sites & Teams
  • Public Teams & channels exposing confidential data org-wide
  • OAuth apps with mail, Files.ReadWrite or Sites.FullControl scopes
  • MFA gaps, legacy auth, conditional-access posture drift
  • Copilot blast radius — dormant licences and the oversharing Copilot will surface on rollout

Asset hygiene

Find the zombies. Ownerless Teams, abandoned Groups, OneDrives of disabled users, sites nobody opens.

  • Ownerless Teams & M365 Groups — no one left to review access
  • Abandoned Teams with zero activity > 180 days — archive candidates
  • OneDrives for disabled or unlicensed users (cleanup candidates)
  • SharePoint sites inactive > 90 days with data still inside
  • Guest accounts with no sign-in activity in last N days
  • Teams with external members added months ago, never removed

Storage & cost

Answer "why is the M365 bill climbing?" in a meeting, not a week.

  • Top-N storage hog sites & OneDrives with exact GB & allocation %
  • Quotas > 90% — before Microsoft throttles your users
  • GB-per-disabled-user — the clean-up-and-save-money list
  • Sites over configurable threshold (default 50 GB) flagged
  • Per-tenant storage trend, week over week

SharePoint & OneDrive are the "most used" modules for a reason — one scan feeds all three outcomes. Every Team has a backing SharePoint site, so Teams, Groups, channels (including Public vs Private visibility), ownership, and activity are all enumerated in the same pass — with a one-click Archive Queue for the cleanup list.

Scan #1 · value in minutes

Here's what a typical first scan actually surfaces.

Not a marketing mock-up — this is the finding shape produced by the live SharePoint and OneDrive scanners on a real 50-seat tenant.

Critical
5 anonymous links on site "Client-X-Shared"
Oldest link created 2022-03-14. No expiry. Default sharing link set to "Anyone".
Warning
OneDrive for alex@acme.com — 312 GB
User licence revoked 2025-11. Account disabled. Drive still holds 312 GB.
Critical
External guest holds Owner on 4 team sites
partners@vendor.com — last sign-in 2025-09. Still Owner on Finance-Q4, Legal, HR-Docs, Ops.
Warning
7 sites above 90% quota · top site 4.2 TB
"Marketing-Archive" at 4.2 TB / 4.5 TB. Projected full in 6 weeks at current growth.
Warning
8 OAuth apps with Mail.ReadWrite · 3 inactive
Three apps not seen in tenant sign-in logs > 90 days. Still consented. Safe to revoke.
Critical
Team "Project-Phoenix" is Public — 412 users can read M&A channel
Visibility set to Public on creation. All org-wide licensed users can join, read channels, and download files — including the M&A-Q4 channel.
Warning
47 Teams have no owner · 8 inactive > 180 days
Original owners offboarded. Nobody can approve new members or archive. Export list, bulk-assign an owner or flag for archive in one click.
Info
23 M365 Groups eligible for archive · 1.8 TB reclaim
Zero activity > 180 days. No guests. Safe archive candidates. Add to the Archive Queue and export the report for your ops team.
Critical
"Anyone with the link" default is tenant-wide
Org-level default sharing scope is still "Anyone". Every new link inherits it.
Info
3 admins without MFA enforced
Global Admin + SharePoint Admin + Exchange Admin. Conditional access not requiring second factor.

Every finding exports to CSV, links back to the exact SharePoint/OneDrive object, and is timestamped for auditor evidence. Run your own scan →

Why now, not next quarter

Two deadlines are coming whether you plan them or not.

Tenant hygiene has been postponable for years. Two dated events — one from Microsoft, one from the EU — are about to end that.

July 2026

Copilot ships into your tenant.

Microsoft is bundling Copilot into Business plans from July 2026. Copilot reads everything each user can read — every overshared file from the last eight years becomes promptable on day one. The cleanup is far cheaper before rollout than after the first "how did you find that?" incident.

Summer 2026

NIS2 lands in national law.

Most EU member states have already transposed NIS2, and the late ones are closing the gap — France's Loi Résilience is expected this summer, bringing an estimated 10,000–15,000 companies into scope. Wherever you operate in the EU, management is personally accountable for overseeing cyber risk. A dated scan report today is a head start on cleanup, done without enforcement pressure.

Already in force

Regulators punish negligence, not breaches.

GDPR Article 32 requires demonstrable security measures — incident or not. Recent CNIL sanctions repeatedly cite "letting structural problems persist". A timestamped quarterly report is the difference between negligence and diligence on file.

Need something to show your management first? Ask for an anonymized sample executive report: contact@olyteck.com

Live in under 10 minutes

Three steps. No agents. No firewall rules. No IT ticket.

From "I just heard about this tool" to "here's my first finding list" — typically under 10 minutes on a standard M365 tenant.

1

Sign in with Microsoft

Standard Microsoft SSO. PKCE, delegated scopes. We never see your password. Takes ~30 seconds.

~30 seconds
2

Grant read-only admin consent

One click by a tenant admin. Narrow Graph scopes — read-only by default. You can revoke consent at any time from the Microsoft admin centre and the scanner stops cold.

1 click
3

First scan runs automatically

Scanner starts in the background. 5–15 minutes on most tenants. Findings populate the dashboard as they land. You get an email when the first scan completes.

5–15 minutes
What we never store

Your files never leave your tenant.

Most scanners ingest the content. Cyber — M365 Security doesn't. Here are the three classes of data we deliberately do not pull or persist.

File contents

We don't read what's inside your files.

No document bodies, no attachments, no OCR text. The scanner identifies that a file is shared, never what is inside it. Your IP and customer data never enter our database.

Share URLs

We record that a share exists — not the link.

When a SharePoint site has an "Anyone" link, we store the count and severity. We do not store the URL itself. Rogue links can't leak from our database because we never asked for them.

Access tokens

Tokens live in memory for one scan — then are gone.

Access tokens used to call Microsoft Graph are held in memory for the lifetime of a single scan and discarded. We don't persist them. A database dump of Cyber — M365 Security cannot be replayed against your tenant.

The full SAFE-payload rule is codified in our Privacy Policy §3.

Read-only by default Scanner never mutates your tenant unless you explicitly invoke it.
Hosted in the EU Application data stays in the European Union. GDPR-aligned.
SAFE payload Counts & IDs only — never file contents.
No tokens stored Access tokens live in memory for one scan, then discarded.

Built for the security admin who has 20 other things to do.

Short path from "is this a risk?" to "here's the evidence."

Deploys in 10 minutes

Sign in with Microsoft, grant admin consent, finish the 4-step wizard. Your first scan runs automatically. No agents to install, no firewall rules, no ticket to IT.

SSO + admin consent + wizard

Executive-ready reports

Snapshot any scan to a saved report: cover page, trend chart, top findings, auditable timestamp. Share externally via a signed URL that expires on your schedule. No re-query, no PowerPoint night.

Saved reports · signed share URLs

Weekly digest + critical alerts

Monday-morning summary of new, resolved, and outstanding findings — sent in your tenant's local timezone. Critical findings page you immediately. Admins can opt out per-module.

Tenant-local digest · per-module opt-out
Common questions

What every IT lead asks before the first scan.

Is the scanner really read-only? Can it change anything in my tenant?
Yes, read-only by default. The scanner uses narrow Microsoft Graph scopes that only allow reading site, OneDrive, user, and app metadata. Remediation actions (revoking a share, disabling a consent) are separate, explicit, and require a second click by a tenant admin — never automatic. You can revoke consent from the Microsoft admin centre at any time and the scanner stops immediately.
What data do you actually store in your database?
Counts, IDs, and severities — not content. For each finding we store the site or user ID, the finding type, the severity, and the timestamp. We do not store file contents, share URLs, access tokens, or email bodies. See Privacy §3 "SAFE payload" for the precise field list. Database is hosted in the EU; 30-day scan-history retention on trial & Starter.
Do I really not need a credit card to start?
Correct. Sign in with Microsoft, grant admin consent, and you're in. The 14-day free trial unlocks all 7 modules — SharePoint, OneDrive, Copilot, Identity, Email security, OAuth apps, Posture — with daily scheduled scans, weekly digest, critical alerts, and saved reports. Nothing rolls over to a paid plan automatically. When the trial ends, the product switches to read-only until you pick a plan.
How long does a scan actually take?
5–15 minutes for most SMB tenants. Heavily-loaded tenants (500+ SharePoint sites) can run longer. The scanner is rate-limited to respect Microsoft Graph throttling and always yields to your users — no impact on production. You can run up to 20 on-demand scans per day during the trial.
Can I share findings with my accountant or external auditor?
Yes. Any scan can be snapshotted to a saved executive report — cover page, trend chart, top findings, auditable timestamp. Share externally via a signed URL with your own expiry, or export findings as CSV for evidence attachments. No re-query needed from the auditor's side.
Will this disrupt my users during a scan?
No end-user impact. All calls go to Microsoft Graph application endpoints using the tenant's own admin consent — not to users' mailboxes or OneDrives. Users won't see a prompt, a notification, or a sharing change. Scans are completely transparent to them.
What happens when the 14-day trial ends?
The product switches to read-only mode. Historical findings and reports stay visible so you can export them, but scheduled scans pause until you pick a paid plan. No credit-card surprise charge. You can revoke admin consent at any time and our scanner loses access immediately.
We're an MSP with multiple customer tenants — does that work?
Yes — see the MSP plan on the pricing page. Each customer tenant gets its own isolated scan database; a single MSP console rolls up findings across tenants. Start with a free trial on one tenant first to get comfortable, then flip the switch.
What if the first scan finds a lot — doesn't that make me look bad?
The opposite — it's your budget request. Every first scan finds 15–30 items, in every tenant, including well-run ones. That's the inheritance of Microsoft's defaults and every admin before you — not an audit of you. Most findings take minutes to fix once they're visible, and the dated report turns "we should do something about M365" into a concrete, costed cleanup plan you present on your own terms — before someone else asks the question for you.
Can someone walk us through the first scan?
Yes — a 20-minute guided first scan. Bring the colleague who holds Global Admin (the consent is one click, by them), and you leave the call with your real findings list on screen. Write to contact@olyteck.com and we'll set it up.

14-day free trial — the full product, no card.

Launch in under 10 minutes, keep full access to every module, cancel by doing nothing. Value on scan #1 is the bar we hold ourselves to.

  • All 7 modules
  • Daily scheduled scans
  • 20 on-demand scans / day
  • Weekly digest + critical alerts
  • Saved exec reports
  • Read-only by default · EU-hosted · SAFE payload
Start free trial →

Simple pricing. No surprise paywall.

Your 14-day trial unlocks every module — pick a plan only once you know which ones you actually use. Annual billing is 2 months free on every tier. Cancel by doing nothing when the trial ends.

Essentials

See your three biggest Microsoft 365 risks in 24 hours.
€89/mo
billed annually · €1,068/year
  • 3 modules included
  • Daily scheduled scans
  • Email scan summary
Start free trial
Most popular

Workspace Security

Find every over-shared file, link, and external collaborator across SharePoint and OneDrive.
€249/mo
billed annually · €2,988/year
  • 5 modules included
  • Daily scheduled scans
  • Weekly digest + critical alerts
  • Saved executive reports
Start free trial

Complete

Every module, every employee. Self-service so users audit their own files.
€690/mo
billed annually · €8,280/year
  • All 7 security modules
  • Daily scheduled scans
  • Weekly digest + critical alerts
  • Saved executive reports
Start free trial

Need MSP or Enterprise? See the full feature matrix on the pricing page.

The objection, weighed

Which is riskier — a read-only scan, or not knowing?

Starting the trial

  • Ten minutes, read-only Graph scopes — nothing in your tenant changes
  • No credit card, no agents, no firewall rules, no IT ticket
  • Consent revocable in one click from your Microsoft admin centre — the scanner stops cold
  • Worst case: you spent ten minutes confirming your tenant is clean

Doing nothing

  • The anonymous links stay live — unlogged, unexpiring, unwatched
  • Ex-employee OneDrives keep holding data nobody is responsible for
  • Vendor guests keep Owner rights; consented OAuth apps keep mailbox access
  • Worst case: your auditor, your insurer, or an attacker finds it before you do

Not looking doesn't make the findings go away. It just guarantees you're the last to know about them.

Your tenant has findings right now.

The only question is whether you see them before your next audit, your next storage invoice, or your next incident. 10 minutes, no card, SSO with Microsoft.

Start free trial → No credit card · All modules · Read-only · Cancel by doing nothing

Prefer a guided first scan? 20 minutes, bring your Global Admin — contact@olyteck.com

About cookies on this site

We'd like your permission to use optional audience-measurement cookies — they help us understand which pages work and which don't, so we can improve them. Decline and the site stays free of analytics cookies. See the Cookie Policy for the full list of cookies, their purpose and lifetime.

Your choice is saved for 6 months on this device.