Connect Microsoft 365 or Google Workspace with read-only access — no agents or software to install — and get an ASD Essentials report in minutes. Then let Aegis Eight watch for changes and quietly alert you when something material shifts.
✓Read-only access — never writes to your tenant
✓No access to emails or files
✓ASD Essentials aligned
✓Hosted in Australia
✓Australian-owned
Why do we ask for administrator consent?
Microsoft requires a Global Administrator (or equivalent) to approve read-only application access before any service can query your tenant configuration. Google Workspace uses the same principle via domain-wide delegation in Admin Console.
We only request the minimum read-only permissions needed to assess your ASD Essentials maturity. Every scope is shown before you grant access.
We cannot:
Read emails or mailbox content
Read SharePoint, OneDrive, Drive, or Shared Drive files
Read Teams, Chat, or Meet messages
Modify settings, reset passwords, or create users
We can read
We cannot read
Security and policy configuration (e.g. Conditional Access, MFA policies)
Your email or mailbox content
Which MFA and authentication methods are registered
Your files in OneDrive or SharePoint
Device compliance and operating-system version state
Your Teams messages
Admin roles and privileged-access configuration
Passwords or MFA settings — we cannot change anything
Microsoft 365 Backup protection and restore evidence
Any tenant other than the one that granted consent
Google Workspace follows the same content boundary — no Gmail, Drive, Chat, or calendar content. See Google permissions.
Do you read our emails?
No. Aegis Eight only reads security configuration metadata — MFA policies, Conditional Access, device compliance, admin roles, and similar settings. We never access email, file, chat, or calendar content.
Can you modify our tenant?
No. Every permission is read-only. There is no write surface in the product — we cannot change settings, reset passwords, or create users.
How long does the assessment take?
Usually 2–5 minutes after admin consent (or Google domain-wide delegation) is granted. Your Essentials PDF report is emailed when the scan completes.
Can I revoke access afterwards?
Yes. Microsoft 365 customers can remove our enterprise app from Entra admin center at any time. Google Workspace customers can revoke domain-wide delegation in Admin Console. Scanning stops immediately; you can request data deletion from the dashboard.
Is any data stored?
Assessment findings and configuration snapshots are stored in Australia to generate your report and (if subscribed) track drift. We do not store email, file, or chat content. See our Security & Privacy page for retention details.
A new Global Admin without MFA or a weakened Conditional Access policy can drop your maturity overnight — long before the next manual review.
Insurance and tenders want current evidence
Cyber insurers and procurement increasingly ask for timestamped ASD Essentials proof, not a spreadsheet from last quarter.
Point-in-time audits expire immediately
ASD and IRAP-style assessors expect ongoing posture visibility. A one-off scan is a snapshot; monitoring catches what changes after it.
Continuous monitoring — what subscribers see
After you subscribe, the dashboard tracks maturity per control and surfaces material drift between scans. Sample views below (single-tenant dashboard and MSP fleet) use fixture data, not a real tenant.
Aegis Eight — Monitoring dashboard
MSP fleet view (sample)
Aegis Eight — Fleet overview
Beyond point-in-time checklists
Manual consultants, Microsoft Purview Compliance Manager templates, and ACSC self-assessment spreadsheets all help — but they are snapshots. Aegis Eight adds automated daily scans, change-triggered alerts, and a verifiable API evidence chain so posture doesn't expire the moment a Global Admin changes something.
Aspect
Manual audit / consultant
Purview / ACSC checklist
Aegis Eight
Time to first report
Days to weeks (scheduling, interviews, manual checks)
Hours to days (template setup, manual evidence collection)
Minutes after read-only access is granted
Drift detection
Next audit cycle — config can regress silently
Point-in-time assessment — no continuous monitoring
You manage one cloud tenant (~20–250 users) on Microsoft 365 or Google Workspace and own day-to-day security posture.
✓Free maturity report before you subscribe
✓Daily drift scans — email only when something material changes
✓No agents; your cloud admin grants read-only access once
Compliance & risk teams
You need timestamped Essentials evidence for board papers, insurers, or assessors.
✓SHA-256 hashed API snapshots on API-derived findings
✓Plan-tiered evidence retention (90 days / 12 months / unlimited)
✓PDF, CSV, and hash-anchored evidence-pack exports for third-party review
What you'll need
A Microsoft 365 Global Administrator or Google Workspace Super Admin to grant read-only access
Nothing to install — no agents, no endpoint software
No write access to your tenant, ever — read-only directory and configuration metadata only
Never reads email, files, Teams/Chat messages, Drive, SharePoint, or OneDrive content
Scope: ASD Essentials maturity assessment and monitoring (ML0–ML3) · Not a SIEM, EDR, or antivirus — a posture-evidence layer that sits alongside them
Pricing
Free one-off ASD Essentials assessment. Continuous monitoring from A$59/month (or A$590/year) for tenants up to 50 users, with a per-tenant plan for MSPs managing multiple clients.