You find one setting turned off in a client tenant. You check the next tenant and it’s off there too. By the time you’ve worked through the list, it’s Tuesday.
That’s the work this release is aimed at. Here’s what shipped.
Fix a Failing Check Across Every Tenant From One Screen
The old version of this job: find the misconfigured setting, open the tenant, fix it, repeat. Fifteen clients, fifteen rounds.
From the All Companies Compliance Audit, open the Fix action on a check.

Augmentt will then line up every tenant currently failing it. Review the affected tenants, apply the recommended configuration, and it deploys to all of them in one go. You get a per-customer result so you can see exactly which tenants the change landed on, and every change is written to the audit log.

AI Risk Report Is Now Generally Available
Your clients are turning on Copilot whether or not they asked you first. The question that follows is what it can see.
The AI Risk Report is out of beta and available to every Secure user, under the Reports menu next to the Threat Report. It covers Copilot deployment readiness, data exposure, identity and access, and third-party shadow IT when the tenant is licensed for Discover. The report also explains why each recommendation matters, so it holds up in front of a client.
Two sections worth opening first.

SharePoint site inventory and sharing settings. Copilot surfaces what a user already has access to. Oversharing nobody noticed for three years becomes obvious the day Copilot turns on. You get the site-level view of what’s shared and how.
Sensitivity labels and data loss prevention. A label inventory sitting next to a DLP policy inventory, with counts for labels deployed, DLP policies in enforcement, and whether the tenant has a default label set. AI exposure comes down to what’s labeled and what isn’t, so this is the section to watch.

Shadow AI shows up as unsanctioned applications and websites. Pair Secure with Discover for the wider view of where client data is actually going.
Purview DLP Policies
Under Secure > Purview > Data Loss Prevention, Augmentt now pulls and displays a tenant’s DLP policies, so you can see them without opening the Purview portal.

Turn a policy into a sanitized, reusable template and deploy it across as many tenants as you want. Same standardize-and-roll-out pattern you already use elsewhere in Augmentt.
DLP policies in Augmentt now support Microsoft 365 Copilot and Microsoft Foundry as policy locations, so as clients turn on AI you can extend their data-loss protection to cover it.
Purview access sits behind its own dedicated permission on your System Users, separate from the Secure permission, so you decide who on the team works with this data.
Break-Glass Accounts Stop Reading as Failures
Every tenant should have an emergency break-glass account, preferably two, kept aside so a Conditional Access misfire can never lock you out entirely. Augmentt had no way of knowing which account that was, so it showed up in the MFA report as a problem to chase.
A new posture check lets you define and validate a tenant’s emergency accounts. Once defined, they carry a distinct Break Glass status in the Admin MFA and User MFA checks and are treated as compliant, the same way a sign-in-blocked account already is, across the pie chart, the details table, and filtering.
More Compliance Checks, Plus SharePoint
SharePoint policies are now supported, which completes coverage of the CIS M365 controls.
New posture checks, all with a Configure action:
- MailTips enabled for end users (6.5.2), so people see the in-compose warning when sending externally or to a large audience
- User owned apps and services restricted (1.3.4), covering Office Store access and starting trials on behalf of the organization
- Internal phishing protection for Microsoft Forms (1.3.5), so a tenant that had this quietly switched off is easy to spot
- Smart Lockout Threshold and Smart Lockout Duration, both settable inside Augmentt on the tenant’s Entra password-protection settings
- Block the device code sign-in flow (5.2.2.12), a path attackers like to abuse, remediated by deploying our Conditional Access template from the check’s Configure tab
- Sign-in frequency for Intune enrollment (5.2.2.11), which forces re-authentication at enrollment and closes the gap that lets someone enroll a rogue device on a stolen session
- Exchange Online connection filter, two checks: confirm the IP allow list isn’t waving mail past your spam checks (2.1.12), and that the connection filter safe list is off (2.1.13)
- Security Defaults monitoring, two checks reading the same signal with opposite logic, so you can confirm Security Defaults is on where a tenant relies on it as a baseline, or off where you’ve moved that tenant onto Conditional Access
Smaller Changes You Asked For
Set a check’s status yourself. Mark a posture check Planned, Risk Accepted, Resolved by 3rd Party, or Alternate Mitigation, or hand it back to Augmentt’s evaluated status at any time. Works across all postures and updates the Microsoft Secure Score where applicable.

Add a note to any check. Record context and evidence on a posture check as free text, stored separately from the status. On export you choose whether notes come along, so you control what a customer sees.

Show only the columns you want. Pick which columns appear in the audit table, and that choice carries through to the PDF, CSV, and Excel exports. Hand a client a clean report with only the data you want on it.

Better Conditional Access deployment. Inside the Compliance Audit Configure experience you can now apply a fresh policy to remediate a control, or edit a closely matching policy instead of creating a duplicate.

Alphabetical sorting. Some lists weren’t sorted. They are now. Tell us if you spot another.
Minimum license requirement is back. You asked for it, it’s back.
Where to Find It
Everything above is live. AI Risk Report under Reports, DLP under Secure > Purview, the rest inside Compliance Audit.
Cover Photo by Christian Wiediger on Unsplash