MICROSOFT CLOUD ASSESSMENT · PILOT Know what is in your tenant.

remivis makes applications, permissions and configuration visible. Nine inventory areas and eleven Entra ID checks give your team a basis for understanding findings and following up on actions.

For MSPs and internal IT teams. The pilot is not yet publicly available.

remivis demo: assessment with six passed checks, four findings, one unassessed check and the inventory.
Isolated demo · fictional customerOpen full-size image (new tab)
A missing assessment is a result, too.

In this demo, ENTRA-007 is “Not assessed”: the declaration of which accounts are used for everyday work is missing. remivis makes this gap visible.

A CLOSER LOOK AT THE INVENTORY

Which application can read your mailboxes?

The application is called “Rechnungsimport Classic”. Its permission dates back to 2023. Does it still need that access today?

In the demo tenant, remivis records the granted permissions and when they were granted. This gives your team a concrete basis for discussing the need with the people responsible.

Mail.Read
Application permission for Microsoft Graph
full_access_as_app
Application permission for Exchange Online
remivis demo inventory: Rechnungsimport Classic with Mail.Read and full_access_as_app, both granted on 30 August 2023.
Detail · isolated demo · fictional customerOpen full-size image (new tab)

THE INVENTORY

Nine areas. A traceable record of your tenant.

The current focus: Microsoft Entra ID and its directory and policy settings.

The inventory is now the larger part of the assessment. It shows what is configured and which access has been granted. Alongside it, eleven checks assess clearly defined criteria.

  1. Tenant inventory

    Profile, domains and licences.

  2. Users and guests

    User, guest and group settings, plus consent policies.

  3. Enterprise applications

    Applications in the tenant and the application permissions granted to them.

  4. Sign-in methods

    Authentication methods permitted in the tenant.

  5. Delegated consents

    Permissions consented to for individual users or all users.

  6. Locations and authentication strengths

    Named locations and configured authentication strengths.

  7. Password protection

    Password protection and expiry settings for each domain.

  8. Consent workflow and contacts

    Admin consent workflow and technical contacts.

  9. Devices in the directory

    Registered devices, their join status and the recorded device information.

remivis demo device inventory: six fictional devices with join status, operating system and approximate last sign-in.
Isolated demo · fictional customerOpen full-size image (new tab)

DEVICES ARE PART OF THE PICTURE

What is still in the directory?

An old intern laptop, a hybrid-joined workstation, a registered tablet: the demo shows devices with their join status and the information available about them.

This is an inventory of directory devices. It is not device management or an Intune assessment.

A CLEAR ACCESS SCOPE

Read what is needed.

You authorise each tenant separately. remivis uses required read permissions and optional read permissions you can choose individually. It does not request write permissions.

Directory and policies
Collection covers configuration, objects and permissions. Mailboxes, files, SharePoint and Teams are not queried.
Optional permissions stay optional
Each optional read permission can be declined individually. The affected section is marked as not collected rather than silently left empty.
Your team remains in control of changes
remivis supports follow-up through tasks and reassessment. Your team makes the actual changes.

FROM CURRENT STATE TO REASSESSMENT

One assessment. Four clear steps.

Every result stays linked to its assessment. Task completion and technical verification are separate steps.

Connect a tenant

Connect and authorise each Microsoft tenant individually. Specify any accounts or apps required for the relevant checks.

Review the assessment

Review the inventory alongside check results. Understand applications, accounts and policies, and see which criteria could be assessed.

Work on actions

Use the practical review steps under “Remediation”. Assign tasks to an owner, set priorities and implement appropriate changes as a team.

Reassess

Run a new scan to reassess the defined criteria. A completed task alone does not prove that an issue has been technically resolved.

CURRENT PRODUCT STATUS

The inventory provides context.
Eleven checks provide direction.

Checks and prerequisites

Alongside the inventory, eleven rules check areas including accounts, roles, MFA, baseline protection and app registrations. Each check has a defined criterion and its own prerequisites.

Four possible assessment results

Passed
The defined criteria for this check are met.
Finding
The check identifies an issue that needs attention.
Not assessed
No assessment result is available for this check.
Not applicable
The check does not apply in this context.

These results apply to the respective dated assessment. “Open” refers only to a task’s progress status.

THE PRODUCT DIRECTION

The next steps for remivis.

The inventory is the foundation for planned reporting and informed decisions. Further Microsoft areas are intended to have their own scope and acceptance review.

The three development stages of remivis Implemented in the pilot: 9 inventory areas and 11 checks, tasks and reassessment. Planned next: report output, follow-up questions and customer decisions. Intended for later: further Microsoft areas, each with its own scope and acceptance review. The pilot is not yet publicly available. No delivery dates are promised. Implemented in the pilot Understand the inventory 9 inventory areas · 11 checksTasks and reassessment Planned next Record decisions Report outputFollow-up questionsCustomer decisions Intended for later Expand with a clear scope Further Microsoft areasEach with its own scopeand acceptance review The three development stages of remivis Implemented in the pilot: 9 inventory areas and 11 checks, tasks and reassessment. Planned next: report output, follow-up questions and customer decisions. Intended for later: further Microsoft areas, each with its own scope and acceptance review. The pilot is not yet publicly available. No delivery dates are promised. Implemented in the pilot Understand the inventory 9 inventory areas · 11 checksTasks and reassessment Planned next Record decisions Report outputFollow-up questionsCustomer decisions Intended for later Expand with a clear scope Further Microsoft areasEach with its own scopeand acceptance review
The pilot is not yet publicly available. This roadmap shows development stages, not a schedule. No delivery dates are promised for planned extensions.

WHO IS remivis FOR?

For your tenant. Or your customers’ tenants.

The same transparent workflow supports three different working contexts.

Businesses

Your in-house IT team assesses its own tenant, interprets results and works on appropriate actions.

Small IT service providers

You manage individual customer tenants and help customers understand and address their findings.

MSPs

You manage multiple customer tenants and work through results in each customer’s context.

Each tenant is connected and authorised individually. remivis does not automatically discover customer tenants or receive blanket authorisation for all customers.

GOOD QUESTIONS. CLEAR ANSWERS.

What you should know about remivis.

What is remivis?

remivis is a Microsoft cloud assessment tool for MSPs, IT service providers and internal IT teams. It inventories applications, permissions and configuration, assesses defined Entra ID criteria and supports follow-up on findings through tasks and reassessment. Access is read-only.

What does the current pilot cover?

The current product includes nine inventory areas, eleven Entra ID baseline checks, tasks and reassessment. Data, read permissions, licences and, for some checks, declared accounts or apps determine what can actually be collected and assessed. The pilot is not a complete Microsoft 365 audit or a compliance certification.

Is remivis publicly available yet?

No. The pilot is being prepared. You can express your interest by joining the waitlist. Joining does not grant access to the app.

Does the assessment only show problems?

No. remivis shows all check results: Passed, Finding, Not assessed and Not applicable. Each result belongs to a dated assessment. Open is a task progress status, not an assessment result.

Does completing a task prove technical resolution?

No. A new scan is needed to assess the defined criteria at a new point in time. It does not confirm complete security or prove which change caused an improvement.

Who makes changes in the Microsoft tenant?

The responsible team evaluates and implements actions itself. remivis reads Microsoft configurations and does not perform automatic remediation. Each tenant must be connected and authorised individually.

Does remivis read emails or files?

No. remivis collects directory and policy settings and permission information. Mailboxes, files, SharePoint and Teams are not queried. When remivis shows another application’s Mail.Read permission, this does not mean that remivis itself reads mailbox contents.

What happens if we decline optional read permissions?

Optional read permissions can be declined individually. The corresponding section is then visibly marked as not collected. remivis does not request write permissions.

Does remivis already cover every Microsoft area?

No. The initial focus is Microsoft Entra ID, with the inventory areas and eleven checks described here. The device inventory, for example, is not an Intune assessment. Other Microsoft areas are not part of the currently available scope described here.

THE NEXT STEP

Interested in the remivis pilot?

For IT teams and MSPs who want to understand their inventory and follow up on findings with clear evidence.

You will first receive an email to confirm your address. Joining does not grant access to the app.

Pilot in preparation · Microsoft Entra ID