Microsoft 365 security operations

Every tenant you manage.
One screen. Zero blind spots.

Saxalar watches every Microsoft 365 tenant you manage — continuously. It catches the change the instant it happens, scores your posture daily, turns license waste into savings, and puts an AI analyst on every finding so your team moves from signal to action.

Tenants supported
Unlimited
One workspace, many environments
Time to first insight
< 8 min
From consent to findings
Collectors · detectors
55 · 53
Graph API + Exchange Online
F · capabilities

See what changed.
Know what matters. Act faster.

Twelve operating surfaces, one console. Every surface is designed around what M365 admins actually do at 9:15am on a Monday — not a marketing diagram.

F-01 · identity

Identity & Access Visibility

Users, groups, directory roles, PIM eligibility, apps and service principals, credentials, devices, admin units, GDAP relationships — 46 Graph collectors, searchable from any screen.

cmd-k everywhere
F-02 · change

Change Tracking

Property-level before-and-after for every monitored entity. Incremental delta sync means changes land in seconds — not overnight.

before → after
F-03 · findings

Security Findings

53 detectors across the categories that cause incidents. Every finding carries lifecycle, suppression, related findings, and a 30-day trend — with the exact change event attached.

53 detectors · acknowledge → resolve
F-04 · posture

Posture Score

One number per tenant, tracked daily across Identity, Access, Data, and Compliance. History, pulse, posture controls against a baseline, and a fleet benchmark with your percentile.

daily · benchmarked
F-05 · licensing

License & Cost Intelligence

Cost, waste, margin, drift, renewals, and trials per tenant and fleet-wide. SKU matrix, MSRP price lists, and pricing policies — with assigned-but-unused seats flagged for recovery.

waste · renewals · margin
F-06 · adoption

Adoption & Copilot ROI

Idle seats, workload usage, cohorts, tier fit, and Copilot usage with a real ROI number — so the renewal conversation is about value, not seat counts.

copilot roi · tier fit
F-07 · remediation

Remediation Tasks & Runbooks

Turn a finding into a task with an owner and a due date, track it to closure, and follow a guided runbook for the fix. Read-only by design — the change happens in your admin tools, with your audit trail.

owners · due dates · kpis
F-08 · alerting

Real-Time Alerting

Finding-threshold, change-event, metric, and AI-enhanced rules. Templates, per-user subscriptions, cooldowns that kill alert fatigue, quiet hours, and digests — to email, Teams, Slack, or a webhook.

4 rule types · 4 channels
F-09 · exchange

Exchange Online

Mailboxes, permissions, inbox rules, transport rules, connectors, org config, protection policies, DKIM — correlated into the independent exfiltration vectors an attacker actually uses.

9 collectors · exfil vectors
F-10 · integrations

Ticketing & SIEM

One ticket per finding in Jira or ServiceNow. Outbound SIEM streams in JSON or CEF with a durable cursor, replay, and a signed test event — so your SOC sees what Saxalar sees.

jira · servicenow · cef
F-11 · reports

Customer Reports

Monthly PDF reviews rendered automatically, white-labelled per customer, shared by link. Tenant export and CSV for everything else.

white-label · monthly · share link
F-12 · platform

Multi-Tenant Platform

Org and tenant RBAC, self-service signup, guided onboarding with consent tracking, a fleet-wide Needs Attention queue, feature flags, and platform health — audited on every check.

rbac · audit-logged
D · detection coverage

53 detectors. Grouped by what actually causes incidents.

Not a checklist copied from a benchmark. Each detector watches a specific change in a specific place and fires with the before/after evidence attached — tuned per tenant, with coverage you can see.

D-01Compromised accountsRisky users, risk detections, risky sign-ins, impossible travel
D-02Privileged access changesRole assignments, PIM activations, temporary elevation patterns
D-03Policy weakeningConditional Access edits, security defaults, auth-method policy drift
D-04MFA loss & weak methodsRegistration lost, SMS-only privileged users, no-MFA admins
D-05Legacy authenticationBasic auth still succeeding, protocols that bypass CA
D-06Break-glass sign-insEmergency accounts used outside a declared incident
D-07Service principal riskOver-privileged apps, OAuth grants, stale or expiring SP credentials
D-08SharePoint & OneDrive sharingAnonymous links, external sharing settings, oversharing exposure
D-09Teams guest sprawlGuest accumulation, external federation, ownerless teams
D-10Device complianceIntune non-compliance, stale devices, policy gaps
D-11GDAP relationshipsPartner delegated access scope, expiry, and drift
D-12EOP / MDO policy weakeningAnti-phish, safe links, safe attachments, spam policy regression
D-13Mail-flow exfiltrationInbox rules forwarding externally, transport rules, rogue connectors
D-14Stale identitiesDormant accounts, stale guests, unused licensed seats
D-15Audit & lockboxUnified audit log disabled, Customer Lockbox off
D-16Posture regressionScore drops, control baseline drift, benchmark slippage
per-tenant detector settings · coverage endpoint · every finding links to the change event that fired it
M · multi-tenant

Built for MSPs from day one.

Saxalar is multi-tenant to the core — not a single-tenant tool with connectors bolted on. Your entire book of business in one command center, with the most urgent item fleet-wide floated to the top.

M-01 Needs Attention queue — the 2 a.m. change, ranked first fleet-wide
M-02 Portfolio matrix — posture by pillar, every tenant, one screen benchmarked
M-03 License margin & billing — turn monitoring into revenue per-tenant pricing
M-04 Guided onboarding with a customer-facing consent link < 8 min
M-05 Granular RBAC — full reign on one customer, read-only on another org + tenant roles
M-06 White-label monthly reports, per customer, on a schedule your brand
Book an MSP walkthrough →
fleet_overview · 12 connected 3 need attention
I · connects to
Entra ID Microsoft Graph Conditional Access Identity Protection Sign-in & audit logs Exchange Online Defender for Office Intune SharePoint & OneDrive Teams Copilot usage Licensing & SKUs Jira ServiceNow Slack Webhooks SIEM · CEF / JSON ConnectWise · soon Autotask · soon HaloPSA · soon
A · ai analyst

The answer, not more homework.

Every critical finding is enriched by Claude, Anthropic's frontier AI: a risk score, the business impact, the realistic attack path, and step-by-step remediation. Your analysts stop triaging and start acting.

left pane · ai capabilities

An analyst that already read everything.

Instead of stitching together changes, findings, and role exposure by hand, Saxalar briefs your team every morning, explains every finding in plain language, and answers questions across your whole fleet — with the receipts still attached.

  • A-01Daily AI standup — what changed overnight, per tenantready at 07:00 local
  • A-02Per-finding enrichment: risk score, impact, attack pathrisk-scored
  • A-03Ask AI — interrogate any finding, multi-turnper finding
  • A-04Ask Saxalar — natural-language questions across every tenant, answered with evidenceorg-wide
  • A-05Bulk explain across selected findings — customer-readyone click
  • A-06Per-user recommendations from posture and activityactionable
  • A-07Cost governance — daily AI budgets per org tier, every call auditedcapped · audited
right pane · this morning's standup
AI standup · Fabrikam Group · 07:00

Overnight: MFA was removed from CA policy 'Partner Access' at 02:14 — restore it first. The same admin elevated to a privileged role three times this week; review standing eligibility. Posture is 54, down 4 — both items above are the drivers.

Ask Saxalar · org-wide

"Which privileged users don't have strong MFA?" — 6 across 3 tenants. Two Global Administrators in Fabrikam registered SMS only; one in Contoso has no method at all. Evidence: auth-methods collector, 07:02 · 3 findings linked.

H · workflow

A cleaner path from connection to action.

Three steps. No SDK install. No agents. Scoped, read-only consent — so you're returning value before your next standup.

H-01 · < 2 minutes

Connect

A guided wizard discovers the tenant and hands their admin a consent link — no screen-sharing through a permissions dialog. Add more tenants anytime.

H-02 · continuous

Monitor

55 collectors run continuously — identities, roles, policies, sign-ins, devices, sharing, mailboxes, licenses. Delta sync lands changes in seconds.

H-03 · when it matters

Act

The morning standup briefs the team, alerts reach Teams, Slack and email, findings become tasks with owners, tickets open themselves, and the monthly report writes itself.

S · security posture

Built for the way your security team already works.

No agents installed. No data moved. No write access to your directory. Saxalar connects through scoped, read-only Graph API consent — you see exactly what's pulled, and can revoke it in one click.

Read-only by design.

Saxalar is an observer, not an operator. It requests the minimum Graph scopes needed to read identity, role, and policy data — nothing more.

  • S-01 Scoped Graph API consentRead-only application permissions. Exchange access is a separate per-tenant opt-in — never part of base consent. enforced
  • S-02 Zero standing write privilegeRunbooks guide the fix; the change happens in your own admin tools, with your own audit trail. enforced
  • S-03 Encryption at rest and in transitAES-256 at rest, TLS 1.2+ everywhere. Secrets live in Azure Key Vault. enforced
  • S-04 Two-factor tenant accessEvery query is tenant-scoped. Access requires active org membership plus a tenant role — enforced at the API, audited on every check. enforced
  • S-05 Consent-drift protectionIf the scopes granted in a tenant ever differ from what the platform expects, you're told — before a collector silently goes dark. enforced
  • S-06 One-click disconnectRevoke consent from your tenant and Saxalar stops receiving data immediately. enforced
scoped_consent.jsonread-only
User.Read.All
Group.Read.All
Directory.Read.All
Policy.Read.All
IdentityRiskyUser.Read.All
AuditLog.Read.All
Organization.Read.All
Directory.ReadWrite.Allnot requested
User.ReadWrite.Allnot requested
Every scope listed above is what Saxalar asks for during consent — the consent screen itself renders the live list straight from the platform. If we ever need more, we ask first — never silently.
N · what's next

Shipping next. Say which one you need first.

The platform under each of these already exists — the ticketing framework, the report engine, the sharing detectors, the snapshots. What's left is the last mile, and design partners set the order.

N-01 · psacoming soon

ConnectWise, Autotask & HaloPSA

Finding → ticket in the PSA your techs already live in, with agreement sync so monitoring lands on the right invoice. Built on the same connector framework as Jira and ServiceNow.

finding → ticket · agreements
N-02 · compliancecoming soon

Compliance Crosswalk

CIS Microsoft 365 Benchmark, NIST CSF, HIPAA and SOC 2 mapped to detectors and posture controls — surfaced on the posture page and inside the monthly PDF as evidence.

cis · nist · hipaa · soc 2
N-03 · copilotcoming soon

Copilot Readiness & Shadow AI

An oversharing assessment before Copilot rollout, plus detection of unsanctioned AI apps consented into the tenant — packaged from the sharing and OAuth detectors already running.

oversharing · ai app consents
N-04 · salescoming soon

Prospect Security Assessment

A one-off white-label report from the first collection — the document that turns a prospect's "we're probably fine" into a signed agreement.

first-scan report · white-label
N-05 · configcoming soon

Configuration Backup & Restore

Snapshots of tenant configuration already exist. Next: export the previous known-good version of a policy straight into a runbook so a drift finding comes with the fix.

snapshots today · restore next
N-06 · opscoming soon

Finding SLAs & PagerDuty

SLA timers on remediation tasks, escalation when they slip, and PagerDuty as a first-class alert destination for the findings that can't wait for the morning standup.

sla timers · pagerduty
P · pricing

Simple plans.
Priced per tenant.

Stacking tenants shouldn't require a call with sales. Every plan starts with a free 14-day trial — full feature access, unlimited tenants, no card required.

P-01 · startersolo

Starter

For a single Microsoft 365 tenant. Everything you need to see what changed and what matters.

$99 per month
  • 1 tenant
  • All twelve operating surfaces
  • 53 detectors + AI enrichment
  • Alerting to Teams, Slack & email
  • PDF + CSV reporting
Start free trial
P-03 · enterprisecustom

Enterprise

For large directories, regulated environments, and custom deployment requirements.

Talk to us
  • SSO · SCIM · custom retention
  • Data residency & single-tenant deployment
  • Security review & questionnaire support
  • Dedicated onboarding engineer
  • Named customer success contact
Contact sales →
14-day free trial on every plan · full access · no card required
Q · questions we get

The parts people usually ask about first.

How long does onboarding actually take?
Q-01 · time to value Most tenants hit first insight in under 8 minutes. The wizard discovers the tenant and generates a consent link for their admin (~2 minutes), the initial collection typically runs for 3–5 minutes depending on directory size, and findings surface as soon as the first scan completes. Adding more tenants is the same flow — everything lands in the same workspace.
What exactly do you pull from my tenant?
Q-02 · data Metadata and configuration only: users, groups, directory roles, privileged assignments, Conditional Access policies, sign-in and audit log entries, risky-user signals, devices, license assignments, SharePoint and OneDrive sharing settings, Teams and Copilot activity summaries. Exchange mailbox metadata (statistics, permissions, rules — never message content) is a separate per-tenant opt-in. No files, no message bodies, no chat content. The full list of Graph scopes is shown during consent and enumerated above in the security section.
Is there a tenant limit per workspace?
Q-03 · scale No hard limit. The MSP plan is built around per-tenant billing specifically because stacking tenants shouldn't require a call with sales.
Can Saxalar change anything in my directory?
Q-04 · write access No. Base consent is read-only Graph scopes — Saxalar holds no standing write privilege. The optional Exchange integration grants a scoped directory role, and you approve it explicitly per tenant. When a finding needs action, the runbook tells you exactly what to change and Saxalar links you straight to the right object — the change happens in your own admin tools with your own audit trail.
Which AI do you use — and does my data train it?
Q-05 · ai Saxalar uses Claude, Anthropic's frontier model, over the Anthropic API. Your tenant data is sent only to generate the specific analysis you requested, is not used to train models, and every AI call is logged with tokens and cost — with a daily budget cap per organization so spend can never run away.
Does it work with the tools my SOC and techs already use?
Q-06 · integrations Yes. Findings open tickets in Jira or ServiceNow, alerts go to Teams, Slack, email or any webhook, and a SIEM stream in CEF or JSON keeps your SOC's view identical to the console — with a durable cursor and replay if the receiver is ever down. ConnectWise, Autotask and HaloPSA are next on the roadmap.
How do I disconnect if I need to?
Q-07 · offboarding Revoke the Saxalar enterprise application from your tenant's admin portal. Data collection stops immediately, and your workspace data is purged per your configured retention unless you re-authorize. Exports are available at any time.
Do you support on-prem AD or hybrid environments?
Q-08 · scope Saxalar reads whatever Entra ID sees. If your on-prem AD syncs to Entra via Entra Connect, those identities show up. Pure on-prem environments that don't sync to Entra aren't in scope today — that's a deliberate focus choice, not a roadmap item.
R · customer reports

The report your customer actually reads.

Every MSP ships a version of the monthly M365 review. Ours is built from the same data your console shows — rendered on a schedule, already branded, already explained in plain language.

From signal to a deliverable without lifting a finger.

Pick a tenant, pick a window, hit export — or let the monthly job do it. The PDF arrives with a written summary, the posture trend, the findings that actually mattered, and the receipts your customer expects to see.

  • R-01Plain-language executive summary, drafted for you
  • R-02Posture score trend and fleet percentile — the numbers that prove your value
  • R-03Grouped findings by severity with inline explanations
  • R-04White-label cover and branding per customer
  • R-05Monthly on a schedule, shareable by link, exportable as PDF or CSV
Example monthly review · real layout · illustrative data
SX
N · a note from the team · 09 · 2026
We built Saxalar because we were the MSP admins stitching together ten browser tabs to answer one customer question. Microsoft has the data — it just doesn't present it like a tool someone actually operates. So we made the console we wanted: read-only, tenant-aware, and focused on the two minutes before a finding becomes an incident.
— The Saxalar team · founded by identity & MSP operators · shipping since 2025
Ready when you are

Bring clarity to every tenant you manage.

Findings that matter, a posture score that proves your value, license waste turned into savings, and an AI analyst that briefs your team every morning — from a single screen.

time to first insight< 8 min
graph api scopesread-only
collectors · detectors55 · 53
tenants per workspaceunlimited
free trial14 days