Built on the open-source Aura framework

Your tenant passed the check.
Prove it stayed that way.

Aura tells you whether your Microsoft 365 security configuration is correct right now. Aura Cloud remembers what it looked like every run before that — so you can see what changed, when it changed, and who changed it.

Retention
5+ years
Setup
One cmdlet
Secrets to rotate
None

A scan is a snapshot. Audits ask for a film.

Run the open-source framework and you get an answer about today: 412 passed, 18 failed, here is how to fix them. That answer is genuinely useful, and it is also gone the moment the next run overwrites it.

The questions that actually cost you time are historical ones. Was this exclusion in place during the incident window? When did that policy stop requiring MFA? Can you show a reviewer twelve months of evidence that the control held? A folder of HTML reports on a share drive is not an answer to any of those.

Aura Cloud is the layer that keeps them. Every run is stored, indexed, and diffed against the one before it.

Drift detected contoso.onmicrosoft.com · 04:12 UTC

CA-014 — Require MFA for administrators

  • excludeGroups: []
  • excludeGroups: ["Break-glass-temp"]
Test result: pass → fail Changed by j.rivera@contoso.com

Two ways in

Keep the pipeline you already have, or let us run it. Same portal either way.

01

Send results from your own pipeline

You already run Aura in GitHub Actions, Azure DevOps, or a scheduled job. Add one cmdlet after the run and the results land in the portal. Nothing else about your pipeline changes.

# existing step
Invoke-Aura -OutputJson results.json

# new step
Publish-AuraCloudResult -Path results.json
02

Let the hosted runner do it

No pipeline to maintain. Pick a schedule and a region, consent the app in your tenant, and the runner executes the suite and files the results for you. Useful when you are covering tenants you do not build CI for.

  • Daily, weekly, or on-demand runs
  • Choose which baselines to include
  • Per-tenant schedules and owners

What the portal gives you

Everything here is a question about time, which is exactly what a single run cannot answer.

A timeline per tenant

Every run retained for five years or more, in the Azure region you nominate. Open any date and see the posture as it stood.

Diffs between runs

Consecutive runs compared field by field. New failures, fixed failures, and settings that moved without changing a result.

Alerts on change

Delivered to a Microsoft 365 mailbox when posture shifts, so drift reaches a human without anyone opening a dashboard.

All tenants at once

One board across every tenant you manage, ranked by what regressed most recently rather than alphabetically.

Evidence you can hand over

Export a control's full history for a date range as a signed report, with run identifiers a reviewer can trace.

Baseline conformance over time

Track EIDSCA, CISA SCuBA, CIS, and ORCA coverage as a trend line, not a number you re-derive each quarter.

Who this is for

Security & compliance

You are asked to evidence a control's state on a date in the past. Today that means screenshots and hope.

Identity & access

Conditional Access and authentication methods drift quietly. You want the diff the morning it happens, not at the next review.

Managed service providers

Thirty tenants, one team. You need the exceptions surfaced rather than thirty reports to read.

You keep the keys

Aura Cloud reads configuration. It does not change it, and it does not ask you to hand over a credential that outlives the session.

  • A single-tenant Entra app you create. It lives in your directory. You can read its permissions, and you can revoke it without asking us.
  • Workload identity federation and managed identities wherever Microsoft supports them — no client secrets, no certificates, nothing on a rotation calendar.
  • Read-only Graph scopes, listed explicitly before you consent.
  • Regional storage. You choose the Azure region your history is held in, and it stays there.
  • Your data is yours. Export the full history at any time; delete a tenant and its runs go with it.

The framework stays open source and free. Aura Cloud is the optional layer for teams who need the history kept for them — and it is what funds continued work on the tests themselves.

Browse the open-source framework →

Join the waitlist

Tell us how many tenants you look after and we will get in touch when your slot opens.

We use your address to contact you about Aura Cloud access. Nothing else, no list sharing, unsubscribe whenever.