Augmentt Update: Fix a Check Across Every Failing Tenant, and AI Risk Report Goes GA

Table of Contents

You find one setting turned off in a client tenant. You check the next tenant and it’s off there too. By the time you’ve worked through the list, it’s Tuesday.

That’s the work this release is aimed at. Here’s what shipped.

Fix a Failing Check Across Every Tenant From One Screen

The old version of this job: find the misconfigured setting, open the tenant, fix it, repeat. Fifteen clients, fifteen rounds.

From the All Companies Compliance Audit, open the Fix action on a check.

Augmentt will then line up every tenant currently failing it. Review the affected tenants, apply the recommended configuration, and it deploys to all of them in one go. You get a per-customer result so you can see exactly which tenants the change landed on, and every change is written to the audit log.

AI Risk Report Is Now Generally Available

Your clients are turning on Copilot whether or not they asked you first. The question that follows is what it can see.

The AI Risk Report is out of beta and available to every Secure user, under the Reports menu next to the Threat Report. It covers Copilot deployment readiness, data exposure, identity and access, and third-party shadow IT when the tenant is licensed for Discover. The report also explains why each recommendation matters, so it holds up in front of a client.

Two sections worth opening first.

AI Risk Report SharePoint site inventory showing ownership, sharing level and application access per site

SharePoint site inventory and sharing settings. Copilot surfaces what a user already has access to. Oversharing nobody noticed for three years becomes obvious the day Copilot turns on. You get the site-level view of what’s shared and how.

Sensitivity labels and data loss prevention. A label inventory sitting next to a DLP policy inventory, with counts for labels deployed, DLP policies in enforcement, and whether the tenant has a default label set. AI exposure comes down to what’s labeled and what isn’t, so this is the section to watch.

AI Risk Report third-party and AI ecosystem panel showing unsanctioned AI apps detected across the tenant

Shadow AI shows up as unsanctioned applications and websites. Pair Secure with Discover for the wider view of where client data is actually going.

Purview DLP Policies

Under Secure > Purview > Data Loss Prevention, Augmentt now pulls and displays a tenant’s DLP policies, so you can see them without opening the Purview portal.

Augmentt Purview Data Loss Prevention page listing a tenant’s DLP policies with mode and sync status

Turn a policy into a sanitized, reusable template and deploy it across as many tenants as you want. Same standardize-and-roll-out pattern you already use elsewhere in Augmentt.

DLP policies in Augmentt now support Microsoft 365 Copilot and Microsoft Foundry as policy locations, so as clients turn on AI you can extend their data-loss protection to cover it.

Purview access sits behind its own dedicated permission on your System Users, separate from the Secure permission, so you decide who on the team works with this data.

Break-Glass Accounts Stop Reading as Failures

Every tenant should have an emergency break-glass account, preferably two, kept aside so a Conditional Access misfire can never lock you out entirely. Augmentt had no way of knowing which account that was, so it showed up in the MFA report as a problem to chase.

A new posture check lets you define and validate a tenant’s emergency accounts. Once defined, they carry a distinct Break Glass status in the Admin MFA and User MFA checks and are treated as compliant, the same way a sign-in-blocked account already is, across the pie chart, the details table, and filtering.

More Compliance Checks, Plus SharePoint

SharePoint policies are now supported, which completes coverage of the CIS M365 controls.

New posture checks, all with a Configure action:

  • MailTips enabled for end users (6.5.2), so people see the in-compose warning when sending externally or to a large audience
  • User owned apps and services restricted (1.3.4), covering Office Store access and starting trials on behalf of the organization
  • Internal phishing protection for Microsoft Forms (1.3.5), so a tenant that had this quietly switched off is easy to spot
  • Smart Lockout Threshold and Smart Lockout Duration, both settable inside Augmentt on the tenant’s Entra password-protection settings
  • Block the device code sign-in flow (5.2.2.12), a path attackers like to abuse, remediated by deploying our Conditional Access template from the check’s Configure tab
  • Sign-in frequency for Intune enrollment (5.2.2.11), which forces re-authentication at enrollment and closes the gap that lets someone enroll a rogue device on a stolen session
  • Exchange Online connection filter, two checks: confirm the IP allow list isn’t waving mail past your spam checks (2.1.12), and that the connection filter safe list is off (2.1.13)
  • Security Defaults monitoring, two checks reading the same signal with opposite logic, so you can confirm Security Defaults is on where a tenant relies on it as a baseline, or off where you’ve moved that tenant onto Conditional Access

Smaller Changes You Asked For

Set a check’s status yourself. Mark a posture check Planned, Risk Accepted, Resolved by 3rd Party, or Alternate Mitigation, or hand it back to Augmentt’s evaluated status at any time. Works across all postures and updates the Microsoft Secure Score where applicable.

Augmentt Resolve Check dialog setting a posture check status to Planned with status details

Add a note to any check. Record context and evidence on a posture check as free text, stored separately from the status. On export you choose whether notes come along, so you control what a customer sees.

Notes tab on an Augmentt posture check showing a dated comment added by a technician

Show only the columns you want. Pick which columns appear in the audit table, and that choice carries through to the PDF, CSV, and Excel exports. Hand a client a clean report with only the data you want on it.

Augmentt audit table column selector with checkboxes for status details, categories, rationale and notes

Better Conditional Access deployment. Inside the Compliance Audit Configure experience you can now apply a fresh policy to remediate a control, or edit a closely matching policy instead of creating a duplicate.

Augmentt Configure tab showing existing Conditional Access policies with a best match and per-requirement pass or fail

Alphabetical sorting. Some lists weren’t sorted. They are now. Tell us if you spot another.

Minimum license requirement is back. You asked for it, it’s back.

Where to Find It

Everything above is live. AI Risk Report under Reports, DLP under Secure > Purview, the rest inside Compliance Audit.

Cover Photo by Christian Wiediger on Unsplash

Author
Gavin Garbutt
Co-Founder & Chairman of Augmentt

FAQ

Using our GDAP tool & Magic Link, setting up is easy! You can integrate with your CSP partner portal in minutes
Augmentt uses a combination of Microsoft Secure Score best practices as well as industry standards such as NIST & CIS. You can use the out of box templates to get started right away and even build your own custom templates to match your client requirements.
Out of box, Augmentt comes pre-configured to not be noisy. Very few Microsoft alerts are critical in nature so you will be receiving tickets for account breaches and not minor user log related events. That said, everything is customizable and you can turn alerts on & off to match your clients’ needs.
No. You can choose to schedule alerts to any stakeholder you want and at the frequency you want or manually download reports when you need them.
Regardless of how MFA is managed across your tenants, we have you covered. Augmentt supports Conditional Access Policies, Security Defaults, Entra ID per user (Legacy) MFA as well as 3rd party MFA services like DUO.
No. You can use Augmentt to monitor and manage all clients regardless of their licensing. For environments with no premium licensing you can still provide alerts and monitoring for account breaches and configure security best practices. For environments with premium licensing, you can leverage Microsoft’s premium alerts and premium security configurations such as Conditional Access Policies.
Augmentt is one of the few vendors SOC 2 Type II, and GDPR compliant.
Site licenses to make sure you can deliver standardized service across all clients very affordably.

SUBSCRIBE for more resources

Related Content

Policy Sprawl Is Killing MSP Efficiency
Policy sprawl is quietly draining your margins, creating security gaps, and eroding client trust. The good news? Standardization is the cure.
Does Microsoft Secure Score Tell the Whole Story?
Do you have a complete understanding of your security? See why MSPs need to understand the role licensing plays in Secure Score results.
Top 10 M365 Security Best Practices for MSPs
Here are the top M365 security best practices to help you enhance protection, ensure compliance, and stay ahead of emerging threats.