CY Cyber — M365 Security
Microsoft 365 security · asset · cost — in one scan

See who can access what across SharePoint, OneDrive & Teams — and what it's costing you.

Cyber — M365 Security scans your Microsoft 365 tenant read-only and surfaces the anonymous share links, ex-employee OneDrives, and storage hogs your backup and MDM tools never flag. Security posture, asset hygiene, and storage cost in under 10 minutes — without ever touching your files.

Sign in with Microsoft No credit card All 7 modules unlocked Read-only by default EU-hosted Fix from the same screen — optional
If you're the only one watching

You already know something's off. You just can't prove it yet.

Microsoft 365 admin centre tells you what exists. It doesn't tell you what's risky, dormant, or expensive. That's the gap Cyber — M365 Security closes — for teams that don't have a dedicated security engineer.

Audit is next quarter.

You don't know which SharePoint sites have external guests, which OneDrives hold regulated data, or whether "Anyone with the link" is still enabled from a 2021 rollout.

Teams & Groups have multiplied.

Anyone can spin up a new Team. Hundreds exist. Nobody remembers half of them. You have no single view of which are dormant, which still hold data, or which are safe to archive.

"Public" was the default.

Teams and channels created as Public expose files, messages, and meeting notes to every licensed user in the org — including finance data, HR conversations, M&A docs. You'd never spot it by clicking through the admin centre.

Owners left. Teams kept running.

A Team's only owner was an employee who offboarded eight months ago. It's now orphaned — nobody can approve new members, review access, or archive it. And you have dozens of them.

The contractor left six months ago.

Account is disabled. Licence is revoked. OneDrive with 312 GB is still sitting there. Share links they created? Probably still live. Probably.

The M365 storage bill keeps climbing.

Finance wants to know why. You need a list of the top storage hog sites, quotas >90%, and OneDrives of users who haven't logged in for a year. No dashboard gives you that in one view.

An OAuth app has mailbox scope.

You didn't approve it. An employee clicked "Allow" months ago. It hasn't been used in 90+ days — but the consent is still there, ready to pull email.

A Team site was shared with a vendor.

Vendor relationship ended in March. The guest still has Owner rights. You'd never find it clicking through the admin centre — there are 140 sites.

You have one hour per week for this.

You need the answer, not a tool. A Monday-morning digest you can forward to your accountant-turned-compliance-officer — with evidence timestamped and exportable.

The first question every admin asks

"Doesn't Microsoft already do this?"

It shows you settings. Site by site, page by page, across four admin centres that get renamed every year. What it doesn't give a small team is the answer: who can reach what, since when, and what to do about it.

Admin centre: settings

Cyber: consequences, per person, per Team, per link

Pick one person and see every Team, site and sharing link they hold — the leaver check in one filter. Pick one Team and see what is open internally, to guests, or to anyone on the internet. Close it in one click. That is the access review an auditor asks for, done in minutes instead of a week of PowerShell.

Microsoft: four consoles that keep moving

Cyber: one checklist of best practices that stays put

Entra, Purview, Defender, SharePoint admin — tools get renamed, pages move, the guidance is scattered. Cyber keeps the controls that matter in one place, in ISO 27001 and NIS2 vocabulary, readable by an IT team that doesn't have a Microsoft security specialist on staff.

Secure Score: a target you can't reach

Cyber: the score achievable on the licences you pay for

Half the recommendations need a P2 licence you don't have, so 100 % is off the table and the number stops meaning anything. Cyber shows the maximum achievable on your current licences, the points you can win today, and what an upgrade would actually unlock — before you buy it.

Admin centre: one global admin does everything

Cyber: delegate the cleanup without delegating admin rights

Each Team owner signs in and sees only their own groups, with a to-do list: this link is public, this guest left in March, this site has no second owner. You keep the overview and the proof; the fixing spreads across the people who created the mess.

Not a replacement for Microsoft — a reading of it. Cyber uses your tenant's own read-only Graph permissions, and it works on Business Basic, Standard and Premium. No P2 required to see the answers.

Four questions

Could you answer these in a meeting — today?

Your ISO 27001 auditor calls it an access review. Your cyber-insurer and your biggest customer's security questionnaire ask versions of the same four questions. "I'd have to check" is the answer that costs deals, premiums, and audit findings.

1 How many "Anyone with the link" shares exist in your tenant right now?
2 How many OneDrives of people who left still hold company data — and how many GB?
3 Which Teams have external guests in them, and who approved each one?
4 Which third-party OAuth apps can read your mailboxes today?

If any answer is "I'd have to check" — that check is the free trial. Ten minutes, read-only, and you'll have all four answers with timestamps. Not knowing isn't neutral: it's the same exposure, minus the chance to fix it first.

Get the four answers →
Three jobs, one scan

SharePoint, OneDrive & Teams — now tripled in value.

Every read-only scan doubles as a security audit, an asset-hygiene report, and a storage-cost exercise. You pay for one tool and three different people on your team stop complaining.

Security posture

Find the things an attacker — or your auditor — would find first.

  • Anonymous "anyone-with-the-link" shares (no expiry, no audit)
  • External guests holding Owner / admin rights on sites & Teams
  • Public Teams & channels exposing confidential data org-wide
  • OAuth apps with mail, Files.ReadWrite or Sites.FullControl scopes
  • MFA gaps, legacy auth, conditional-access posture drift
  • Copilot blast radius — dormant licences and the oversharing Copilot will surface on rollout

Asset hygiene

Find the zombies. Ownerless Teams, abandoned Groups, OneDrives of disabled users, sites nobody opens.

  • Ownerless Teams & M365 Groups — no one left to review access
  • Abandoned Teams with zero activity > 180 days — archive candidates
  • OneDrives for disabled or unlicensed users (cleanup candidates)
  • SharePoint sites inactive > 90 days with data still inside
  • Guest accounts with no sign-in activity in last N days
  • Teams with external members added months ago, never removed

Storage & cost

Answer "why is the M365 bill climbing?" in a meeting, not a week.

  • Top-N storage hog sites & OneDrives with exact GB & allocation %
  • Quotas > 90% — before Microsoft throttles your users
  • GB-per-disabled-user — the clean-up-and-save-money list
  • Sites over configurable threshold (default 50 GB) flagged
  • Per-tenant storage trend, week over week

SharePoint & OneDrive are the "most used" modules for a reason — one scan feeds all three outcomes. Every Team has a backing SharePoint site, so Teams, Groups, channels (including Public vs Private visibility), ownership, and activity are all enumerated in the same pass — with a one-click Archive Queue for the cleanup list.

Scan #1 · value in minutes

Here's what a typical first scan actually surfaces.

Not a marketing mock-up — this is the finding shape produced by the live SharePoint and OneDrive scanners on a real 50-seat tenant.

Critical
5 anonymous links on site "Client-X-Shared"
Oldest link created 2022-03-14. No expiry. Default sharing link set to "Anyone".
Warning
OneDrive for alex@acme.com — 312 GB
User licence revoked 2025-11. Account disabled. Drive still holds 312 GB.
Info
Leaver check: 1 person → 14 Teams, 3 sites owned alone, 9 live share links
Person view before the exit interview: every group membership, every site they own alone, every link they created — including the ones shared to their private address. Remove or revoke from one screen; export the rest as the offboarding checklist.
Critical
External guest holds Owner on 4 team sites
partners@vendor.com — last sign-in 2025-09. Still Owner on Finance-Q4, Legal, HR-Docs, Ops.
Warning
7 sites above 90% quota · top site 4.2 TB
"Marketing-Archive" at 4.2 TB / 4.5 TB. Projected full in 6 weeks at current growth.
Warning
8 OAuth apps with Mail.ReadWrite · 3 inactive
Three apps not seen in tenant sign-in logs > 90 days. Still consented. Safe to revoke.
Critical
Team "Project-Phoenix" is Public — 412 users can read M&A channel
Visibility set to Public on creation. All org-wide licensed users can join, read channels, and download files — including the M&A-Q4 channel.
Warning
47 Teams have no owner · 8 inactive > 180 days
Original owners offboarded. Nobody can approve new members or archive. Export list, bulk-assign an owner or flag for archive in one click.
Info
23 M365 Groups eligible for archive · 1.8 TB reclaim
Zero activity > 180 days. No guests. Safe archive candidates. Add to the Archive Queue and export the report for your ops team.
Critical
"Anyone with the link" default is tenant-wide
Org-level default sharing scope is still "Anyone". Every new link inherits it.
Info
3 admins without MFA enforced
Global Admin + SharePoint Admin + Exchange Admin. Conditional access not requiring second factor.

Every finding exports to CSV, links back to the exact SharePoint/OneDrive object, is timestamped for auditor evidence — and has a fix button next to it: revoke the link, remove the member or guest, demote the owner. Read-only until you say otherwise. Run your own scan →

Why now, not next quarter

Two deadlines are coming whether you plan them or not.

Tenant hygiene has been postponable for years. Two dated events — one from Microsoft, one from the EU — are about to end that.

July 2026

Copilot ships into your tenant.

Microsoft is bundling Copilot into Business plans from July 2026. Copilot reads everything each user can read — every overshared file from the last eight years becomes promptable on day one. The cleanup is far cheaper before rollout than after the first "how did you find that?" incident.

Summer 2026

NIS2 lands in national law.

Most EU member states have already transposed NIS2, and the late ones are closing the gap — France's Loi Résilience is expected this summer, bringing an estimated 10,000–15,000 companies into scope. Wherever you operate in the EU, management is personally accountable for overseeing cyber risk. A dated scan report today is a head start on cleanup, done without enforcement pressure.

Already in force

Regulators punish negligence, not breaches.

GDPR Article 32 requires demonstrable security measures — incident or not. Recent CNIL sanctions repeatedly cite "letting structural problems persist". A timestamped quarterly report is the difference between negligence and diligence on file.

Need something to show your management first? Ask for an anonymized sample executive report: contact@olyteck.com

Live in under 10 minutes

Three steps to your findings. A fourth, when you decide, to fix them.

From "I just heard about this tool" to "here's my first finding list" — typically under 10 minutes on a standard M365 tenant.

1

Sign in with Microsoft

Standard Microsoft SSO. PKCE, delegated scopes. We never see your password. Takes ~30 seconds.

~30 seconds
2

Grant read-only admin consent

One click by a tenant admin. Narrow Graph scopes — read-only by default. You can revoke consent at any time from the Microsoft admin centre and the scanner stops cold.

1 click
3

First scan runs automatically

Scanner starts in the background. 5–15 minutes on most tenants. Findings populate the dashboard as they land. You get an email when the first scan completes.

5–15 minutes
4

Fix what you found — when you decide

Every finding carries its fix: revoke the sharing link, remove the guest or member, demote the orphan owner, queue the dead site for archive. Fixing needs a second, separate consent, acts as the person clicking, and lands in your own Microsoft audit log. Never enable it and the product stays read-only forever.

Optional · separate consent
What we never store

Your files never leave your tenant.

Most scanners ingest the content. Cyber — M365 Security doesn't. Here are the three classes of data we deliberately do not pull or persist.

File contents

We don't read what's inside your files.

No document bodies, no attachments, no OCR text. The scanner identifies that a file is shared, never what is inside it. Your IP and customer data never enter our database.

Share URLs

We record that a share exists — not the link.

When a SharePoint site has an "Anyone" link, we store the count and severity. We do not store the URL itself. Rogue links can't leak from our database because we never asked for them.

Access tokens

Tokens live in memory for one scan — then are gone.

Access tokens used to call Microsoft Graph are held in memory for the lifetime of a single scan and discarded. We don't persist them. A database dump of Cyber — M365 Security cannot be replayed against your tenant.

The full SAFE-payload rule is codified in our Privacy Policy §3.

Read-only by default Scanner never mutates your tenant unless you explicitly invoke it.
Hosted in the EU Application data stays in the European Union. GDPR-aligned.
SAFE payload Counts & IDs only — never file contents.
No tokens stored Access tokens live in memory for one scan, then discarded.

Built for the security admin who has 20 other things to do.

Short path from "is this a risk?" to "here's the evidence."

Deploys in 10 minutes

Sign in with Microsoft, grant admin consent, finish the 4-step wizard. Your first scan runs automatically. No agents to install, no firewall rules, no ticket to IT.

SSO + admin consent + wizard

Executive-ready reports

Snapshot any scan to a saved report: cover page, trend chart, top findings, auditable timestamp. Share externally via a signed URL that expires on your schedule. No re-query, no PowerPoint night.

Saved reports · signed share URLs

Weekly digest + critical alerts

Monday-morning summary of new, resolved, and outstanding findings — sent in your tenant's local timezone. Critical findings page you immediately. Admins can opt out per-module.

Tenant-local digest · per-module opt-out
Common questions

What every IT lead asks before the first scan.

Is the scanner really read-only? Can it change anything in my tenant?
Yes — and it is not a setting, it is the permission grant. The scanner application holds 19 Microsoft Graph permissions and every one of them is read-only. It has no write permission of any kind, so there is no code path by which a scan can modify your tenant. It is also the only identity that runs unattended, so nothing on a schedule can change anything.

Fixing what we find is a separate application, and it is optional. Revoking a sharing link or removing a group member needs its own Entra registration, consented separately and revocable on its own. If you never enable it, the product cannot modify your tenant at all — every fix button refuses and tells you which permission it would need. When you do enable it, it acts as the person clicking, with that person's own rights, and the action appears in your own Microsoft audit log.

Don't take our word for it: check Enterprise applications → Permissions in your own tenant, or Security Console → Apps & consent in the product, which reads the live grant from Microsoft on every load. Security review brief (PDF) →
What data do you actually store in your database?
Counts, IDs, and severities — not content. For each finding we store the site or user ID, the finding type, the severity, and the timestamp. We do not store file contents, share URLs, access tokens, or email bodies. See Privacy §3 "SAFE payload" for the precise field list. Database is hosted in the EU; 30-day scan-history retention on trial & Starter.
Do I really not need a credit card to start?
Correct. Sign in with Microsoft, grant admin consent, and you're in. The 14-day free trial unlocks all 7 modules — SharePoint, OneDrive, Copilot, Identity, Email security, OAuth apps, Posture — with daily scheduled scans, weekly digest, critical alerts, and saved reports. Nothing rolls over to a paid plan automatically. When the trial ends, the product switches to read-only until you pick a plan.
How long does a scan actually take?
5–15 minutes for most SMB tenants. Heavily-loaded tenants (500+ SharePoint sites) can run longer. The scanner is rate-limited to respect Microsoft Graph throttling and always yields to your users — no impact on production. You can run up to 20 on-demand scans per day during the trial.
Can I share findings with my accountant or external auditor?
Yes. Any scan can be snapshotted to a saved executive report — cover page, trend chart, top findings, auditable timestamp. Share externally via a signed URL with your own expiry, or export findings as CSV for evidence attachments. No re-query needed from the auditor's side.
Will this disrupt my users during a scan?
No end-user impact. All calls go to Microsoft Graph application endpoints using the tenant's own admin consent — not to users' mailboxes or OneDrives. Users won't see a prompt, a notification, or a sharing change. Scans are completely transparent to them.
What happens when the 14-day trial ends?
The product switches to read-only mode. Historical findings and reports stay visible so you can export them, but scheduled scans pause until you pick a paid plan. No credit-card surprise charge. You can revoke admin consent at any time and our scanner loses access immediately.
We're an MSP with multiple customer tenants — does that work?
Yes — see the MSP plan on the pricing page. Each customer tenant gets its own isolated scan database; a single MSP console rolls up findings across tenants. Start with a free trial on one tenant first to get comfortable, then flip the switch.
What if the first scan finds a lot — doesn't that make me look bad?
The opposite — it's your budget request. Every first scan we have run so far found things — including in a well-run tenant whose admin writes his own PowerShell controls. That's the inheritance of Microsoft's defaults and every admin before you — not an audit of you. Most findings take minutes to fix once they're visible, and the dated report turns "we should do something about M365" into a concrete, costed cleanup plan you present on your own terms — before someone else asks the question for you.
We already have Defender, Purview and Secure Score. What does Cyber add?
The answer, not the settings. Microsoft's consoles are organised by product; Cyber is organised by question: who can reach what, since when, and who fixes it. Three things you will not get from the admin centre: a per-person and per-Team view of every membership, ownership and sharing link (the leaver check and the access review); a Secure Score read against the licences you actually own, so the target is reachable; and delegation — each Team owner sees only their own groups and their own to-do list. See "Doesn't Microsoft already do this?" above. It reads your tenant through Microsoft's own Graph API, read-only, and needs no P2 licence.
Can someone walk us through the first scan?
Yes — a 20-minute guided first scan. Bring the colleague who holds Global Admin (the consent is one click, by them), and you leave the call with your real findings list on screen. Write to contact@olyteck.com and we'll set it up.

14-day free trial — the full product, no card.

Launch in under 10 minutes, keep full access to every module, cancel by doing nothing. Value on scan #1 is the bar we hold ourselves to.

  • All 7 modules
  • Daily scheduled scans
  • 20 on-demand scans / day
  • Weekly digest + critical alerts
  • Saved exec reports
  • Read-only by default · EU-hosted · SAFE payload
Start free trial →

Simple pricing. No surprise paywall.

Your 14-day trial unlocks every module — pick a plan only once you know which ones you actually use. Annual billing is 2 months free on every tier. Cancel by doing nothing when the trial ends.

Essentials

See your three biggest Microsoft 365 risks in 24 hours.
€89/mo
billed annually · €1,068/year
  • 3 modules included
  • Daily scheduled scans
  • Email scan summary
Start free trial
Most popular

Workspace Security

Find every over-shared file, link, and external collaborator across SharePoint and OneDrive.
€249/mo
billed annually · €2,988/year
  • 5 modules included
  • Daily scheduled scans
  • Weekly digest + critical alerts
  • Saved executive reports
Start free trial

Complete

Every module, every employee. Self-service so users audit their own files.
€690/mo
billed annually · €8,280/year
  • All 7 security modules
  • Daily scheduled scans
  • Weekly digest + critical alerts
  • Saved executive reports
Start free trial

Need MSP or Enterprise? See the full feature matrix on the pricing page.

The objection, weighed

Which is riskier — a read-only scan, or not knowing?

Starting the trial

  • Ten minutes, read-only Graph scopes — nothing in your tenant changes
  • No credit card, no agents, no firewall rules, no IT ticket
  • Consent revocable in one click from your Microsoft admin centre — the scanner stops cold
  • Worst case: you spent ten minutes confirming your tenant is clean

Doing nothing

  • The anonymous links stay live — unlogged, unexpiring, unwatched
  • Ex-employee OneDrives keep holding data nobody is responsible for
  • Vendor guests keep Owner rights; consented OAuth apps keep mailbox access
  • Worst case: your auditor, your insurer, or an attacker finds it before you do

Not looking doesn't make the findings go away. It just guarantees you're the last to know about them.

Your tenant has findings right now.

The only question is whether you see them before your next audit, your next storage invoice, or your next incident. 10 minutes, no card, SSO with Microsoft.

Start free trial → No credit card · All modules · Read-only · Cancel by doing nothing

Prefer a guided first scan? 20 minutes, bring your Global Admin — contact@olyteck.com

About cookies on this site

We'd like your permission to use optional audience-measurement cookies — they help us understand which pages work and which don't, so we can improve them. Decline and the site stays free of analytics cookies. See the Cookie Policy for the full list of cookies, their purpose and lifetime.

Your choice is saved for 6 months on this device.