Cyber — M365 Security scans your Microsoft 365 tenant read-only and surfaces the anonymous share links, ex-employee OneDrives, and storage hogs your backup and MDM tools never flag. Security posture, asset hygiene, and storage cost in under 10 minutes — without ever touching your files.
Microsoft 365 admin centre tells you what exists. It doesn't tell you what's risky, dormant, or expensive. That's the gap Cyber — M365 Security closes — for teams that don't have a dedicated security engineer.
You don't know which SharePoint sites have external guests, which OneDrives hold regulated data, or whether "Anyone with the link" is still enabled from a 2021 rollout.
Anyone can spin up a new Team. Hundreds exist. Nobody remembers half of them. You have no single view of which are dormant, which still hold data, or which are safe to archive.
Teams and channels created as Public expose files, messages, and meeting notes to every licensed user in the org — including finance data, HR conversations, M&A docs. You'd never spot it by clicking through the admin centre.
A Team's only owner was an employee who offboarded eight months ago. It's now orphaned — nobody can approve new members, review access, or archive it. And you have dozens of them.
Account is disabled. Licence is revoked. OneDrive with 312 GB is still sitting there. Share links they created? Probably still live. Probably.
Finance wants to know why. You need a list of the top storage hog sites, quotas >90%, and OneDrives of users who haven't logged in for a year. No dashboard gives you that in one view.
You didn't approve it. An employee clicked "Allow" months ago. It hasn't been used in 90+ days — but the consent is still there, ready to pull email.
Vendor relationship ended in March. The guest still has Owner rights. You'd never find it clicking through the admin centre — there are 140 sites.
You need the answer, not a tool. A Monday-morning digest you can forward to your accountant-turned-compliance-officer — with evidence timestamped and exportable.
It shows you settings. Site by site, page by page, across four admin centres that get renamed every year. What it doesn't give a small team is the answer: who can reach what, since when, and what to do about it.
Pick one person and see every Team, site and sharing link they hold — the leaver check in one filter. Pick one Team and see what is open internally, to guests, or to anyone on the internet. Close it in one click. That is the access review an auditor asks for, done in minutes instead of a week of PowerShell.
Entra, Purview, Defender, SharePoint admin — tools get renamed, pages move, the guidance is scattered. Cyber keeps the controls that matter in one place, in ISO 27001 and NIS2 vocabulary, readable by an IT team that doesn't have a Microsoft security specialist on staff.
Half the recommendations need a P2 licence you don't have, so 100 % is off the table and the number stops meaning anything. Cyber shows the maximum achievable on your current licences, the points you can win today, and what an upgrade would actually unlock — before you buy it.
Each Team owner signs in and sees only their own groups, with a to-do list: this link is public, this guest left in March, this site has no second owner. You keep the overview and the proof; the fixing spreads across the people who created the mess.
Not a replacement for Microsoft — a reading of it. Cyber uses your tenant's own read-only Graph permissions, and it works on Business Basic, Standard and Premium. No P2 required to see the answers.
Your ISO 27001 auditor calls it an access review. Your cyber-insurer and your biggest customer's security questionnaire ask versions of the same four questions. "I'd have to check" is the answer that costs deals, premiums, and audit findings.
If any answer is "I'd have to check" — that check is the free trial. Ten minutes, read-only, and you'll have all four answers with timestamps. Not knowing isn't neutral: it's the same exposure, minus the chance to fix it first.
Get the four answers →Every read-only scan doubles as a security audit, an asset-hygiene report, and a storage-cost exercise. You pay for one tool and three different people on your team stop complaining.
Find the things an attacker — or your auditor — would find first.
Find the zombies. Ownerless Teams, abandoned Groups, OneDrives of disabled users, sites nobody opens.
Answer "why is the M365 bill climbing?" in a meeting, not a week.
SharePoint & OneDrive are the "most used" modules for a reason — one scan feeds all three outcomes. Every Team has a backing SharePoint site, so Teams, Groups, channels (including Public vs Private visibility), ownership, and activity are all enumerated in the same pass — with a one-click Archive Queue for the cleanup list.
Not a marketing mock-up — this is the finding shape produced by the live SharePoint and OneDrive scanners on a real 50-seat tenant.
Every finding exports to CSV, links back to the exact SharePoint/OneDrive object, is timestamped for auditor evidence — and has a fix button next to it: revoke the link, remove the member or guest, demote the owner. Read-only until you say otherwise. Run your own scan →
Tenant hygiene has been postponable for years. Two dated events — one from Microsoft, one from the EU — are about to end that.
Microsoft is bundling Copilot into Business plans from July 2026. Copilot reads everything each user can read — every overshared file from the last eight years becomes promptable on day one. The cleanup is far cheaper before rollout than after the first "how did you find that?" incident.
Most EU member states have already transposed NIS2, and the late ones are closing the gap — France's Loi Résilience is expected this summer, bringing an estimated 10,000–15,000 companies into scope. Wherever you operate in the EU, management is personally accountable for overseeing cyber risk. A dated scan report today is a head start on cleanup, done without enforcement pressure.
GDPR Article 32 requires demonstrable security measures — incident or not. Recent CNIL sanctions repeatedly cite "letting structural problems persist". A timestamped quarterly report is the difference between negligence and diligence on file.
Need something to show your management first? Ask for an anonymized sample executive report: contact@olyteck.com
From "I just heard about this tool" to "here's my first finding list" — typically under 10 minutes on a standard M365 tenant.
Standard Microsoft SSO. PKCE, delegated scopes. We never see your password. Takes ~30 seconds.
~30 secondsOne click by a tenant admin. Narrow Graph scopes — read-only by default. You can revoke consent at any time from the Microsoft admin centre and the scanner stops cold.
1 clickScanner starts in the background. 5–15 minutes on most tenants. Findings populate the dashboard as they land. You get an email when the first scan completes.
5–15 minutesEvery finding carries its fix: revoke the sharing link, remove the guest or member, demote the orphan owner, queue the dead site for archive. Fixing needs a second, separate consent, acts as the person clicking, and lands in your own Microsoft audit log. Never enable it and the product stays read-only forever.
Optional · separate consentMost scanners ingest the content. Cyber — M365 Security doesn't. Here are the three classes of data we deliberately do not pull or persist.
No document bodies, no attachments, no OCR text. The scanner identifies that a file is shared, never what is inside it. Your IP and customer data never enter our database.
When a SharePoint site has an "Anyone" link, we store the count and severity. We do not store the URL itself. Rogue links can't leak from our database because we never asked for them.
Access tokens used to call Microsoft Graph are held in memory for the lifetime of a single scan and discarded. We don't persist them. A database dump of Cyber — M365 Security cannot be replayed against your tenant.
The full SAFE-payload rule is codified in our Privacy Policy §3.
Short path from "is this a risk?" to "here's the evidence."
Sign in with Microsoft, grant admin consent, finish the 4-step wizard. Your first scan runs automatically. No agents to install, no firewall rules, no ticket to IT.
SSO + admin consent + wizardSnapshot any scan to a saved report: cover page, trend chart, top findings, auditable timestamp. Share externally via a signed URL that expires on your schedule. No re-query, no PowerPoint night.
Saved reports · signed share URLsMonday-morning summary of new, resolved, and outstanding findings — sent in your tenant's local timezone. Critical findings page you immediately. Admins can opt out per-module.
Tenant-local digest · per-module opt-outLaunch in under 10 minutes, keep full access to every module, cancel by doing nothing. Value on scan #1 is the bar we hold ourselves to.
Not looking doesn't make the findings go away. It just guarantees you're the last to know about them.
The only question is whether you see them before your next audit, your next storage invoice, or your next incident. 10 minutes, no card, SSO with Microsoft.
Start free trial → No credit card · All modules · Read-only · Cancel by doing nothingPrefer a guided first scan? 20 minutes, bring your Global Admin — contact@olyteck.com