Client-side only — nothing leaves your browser

Audit your M365 tenant in minutes

x365 connects directly to Microsoft Graph from your browser. No data touches a server. Your tokens stay in memory and vanish when you close the tab.

Connect your tenant

Enter your Azure AD app credentials to begin. Need to register an app first?

1
Register an app in Entra ID Single-tenant, redirect URI set to this page. Step-by-step guide →
2
Enter credentials below Tenant ID and Client ID from your app registration.
3
Sign in with Microsoft A popup opens for your admin account. Popups must be allowed.
4
Run the audit Select modules and run. Results appear in the dashboard.

Entra ID → Overview → Directory (tenant) ID

Entra ID → App registrations → [your app] → Application (client) ID

Nothing leaves your browser. Your Microsoft access token is stored in sessionStorage — same-tab only, cleared the moment you close this tab. Tenant ID and Client ID are also stored there for convenience. Nothing is sent to any server.

No app registration yet? Follow the setup guide →

Zero server involvement
Tokens in memory only
Your own app registration
Delegated permissions only
CIS · NIST · ISO 27001
Intune Audit Policy coverage gaps, conflicting profiles, stale devices, encryption & password baselines, compliance by platform.
v1.0
Identity Audit MFA gaps, Conditional Access coverage, Security Defaults, PIM & Global Admin sprawl, stale accounts, legacy auth.
v1.0
Applications & Consent Expiring app secrets & certificates, risky tenant-wide OAuth consent, and multi-tenant app exposure.
v2.0
Azure · Defender · Purview Resource posture, DLP, sensitivity labels, and Secure Score alignment — planned for future releases.
Roadmap