Trust

Data protection

SurePosture is given privileged read access to Microsoft 365 tenants. This page explains exactly what it reads, what it keeps, how it is protected and how access is taken away.

Last updated 25 September 2026

Read-only by default
Assessment uses read permissions only. Write access is a separate, optional consent.
No content
Mail, files, chats and calendars are never requested or read.
Data minimised
Only the fields the checks use are kept from each Microsoft Graph response.
Revocable at any time
Your administrator can delete the enterprise application in Entra; access stops at once.

Who is responsible for what

When you use SurePosture to assess a Microsoft 365 tenant, the data read from that tenant is processed on your instructions. You (or your client, where you are an MSP acting for them) are the controller, and [Company legal name] acts as your processor under a data processing agreement. Where you are an MSP, we are a sub-processor to you.

For the accounts of people who sign in to SurePosture, and for billing, [Company legal name] is the controller. That is covered by the privacy notice.

How SurePosture connects

SurePosture authenticates as its own multi-tenant Microsoft Entra application with application permissions, granted by an administrator of the tenant through Microsoft's admin consent screen. No password or credential of yours is given to SurePosture. If a client requires their own app registration instead, its secret is encrypted with AES-256-GCM, bound to that tenant's record, so it cannot be decrypted in the context of any other tenant.

Read permissions (assessment)

PermissionWhy it is neededRequired
Organization.Read.AllTenant profile, verified domains, technical contacts and assigned plans.Yes
Directory.Read.AllUsers, groups, devices and directory objects that underpin most checks.Yes
User.Read.AllAccount state, licence assignment and sign-in activity per user.Yes
Group.Read.AllMicrosoft 365 groups, ownership, membership and guest exposure.Yes
GroupMember.Read.AllResolves the membership of groups targeted by Conditional Access.Yes
Policy.Read.AllConditional Access policies, authorization policy, security defaults, auth methods policy.Yes
RoleManagement.Read.DirectoryDirectory role assignments and PIM eligibility — the privileged access picture.Yes
Application.Read.AllApp registrations, service principals, credential expiry and delegated consent grants.Yes
AuditLog.Read.AllLast sign-in timestamps (dormant account detection) and directory audit retention.Yes
Reports.Read.AllAuthentication method registration and service usage reports.Yes
SecurityEvents.Read.AllMicrosoft Secure Score, control profiles and security alerts.Yes
IdentityRiskyUser.Read.AllIdentity Protection risky users and risk detections.Optional
DeviceManagementConfiguration.Read.AllIntune compliance and configuration policies.Optional
DeviceManagementManagedDevices.Read.AllEnrolled device inventory, compliance state and OS versions.Optional
MailboxSettings.ReadInbox rules, to find mail being forwarded outside the organisation. Rule definitions only; no message content.Optional
SharePointTenantSettings.Read.AllTenant-wide SharePoint and OneDrive sharing configuration.Optional
TeamSettings.Read.AllTeams guest access and meeting policy posture.Optional

Without an optional permission, the related checks are reported as not assessed and excluded from the score; they are never reported as passing. Email authentication checks (SPF, DKIM, DMARC, MTA-STS) need no permission: they read the public DNS records of your custom domains.

Write permissions (automation only)

These are only requested if you choose to use automated remediation, in a separate consent step. Even after they are granted, nothing can change in a tenant until automation is switched on for that specific tenant, a dry run has succeeded, and the change is approved by someone other than the person who proposed it.

PermissionUsed for
Policy.ReadWrite.ConditionalAccessCreate or amend Conditional Access policies via an approved action.
User.ReadWrite.AllDisable dormant accounts, revoke sessions, clear stale licences.
Directory.ReadWrite.AllRemove redundant role assignments and stale directory objects.
Application.ReadWrite.AllRevoke risky delegated consent grants and unused app credentials.

What is read and kept

Each assessment keeps a trimmed snapshot of the data the checks need, and the results of those checks:

  • People: user principal name, display name, account state, user type, licences assigned, last sign-in dates, MFA and authentication-method registration, department and job title where set.
  • Configuration: Conditional Access and authorisation policies, directory role assignments, app registrations and consent grants, group settings and ownership, SharePoint sharing settings.
  • Devices: device name, manufacturer, model, serial number, operating system and version, compliance and encryption state, enrolment and last sync dates.
  • Security signals: Secure Score, alert counts by severity, risky users and risk levels.
  • Email: public DNS records for your custom domains, and, with the optional permission, the name and external recipients of inbox rules that forward mail outside the organisation.
  • Results: findings with their evidence, reports you generate, notes your team adds, and an audit log of actions taken in SurePosture.

Never read: email bodies or attachments, files and documents, Teams messages, calendar entries, passwords or authentication secrets. SurePosture does not request the permissions that would allow it to.

Where data is stored

The SurePosture service, its database and generated reports are hosted in the EU (Frankfurt) by Render. Data from Microsoft 365 is read from Microsoft's service endpoints for the tenant's cloud and written only to that database.

How it is protected

  • Every workspace is isolated: records are fetched only through accessors that refuse rows belonging to another organisation.
  • Connections to SurePosture use HTTPS. Session cookies are HTTP-only, secure and same-site.
  • Passwords are stored as salted scrypt hashes. Session tokens, share links and invitation links are stored only as hashes.
  • Stored tenant credentials are encrypted with AES-256-GCM.
  • Logs redact secrets, passwords, tokens, cookies and keys before they are written.
  • Report downloads are private and scoped to your workspace; share links expire and are not indexed.
  • An append-only audit log records consents, assessments, report downloads and exports, finding updates, approvals and every change made to a tenant.

Signing in to SurePosture: with Microsoft, so your own Conditional Access and MFA apply, or with a password of at least 12 characters plus optional two-step verification from an authenticator app, which a workspace owner can make mandatory. Sign-in attempts are rate limited, and every sign-in, failed attempt and security change is recorded in the audit log.

Retention and deletion

  • Assessment snapshots, findings and reports are kept while your workspace exists, so trends and change tracking work.
  • Removing a tenant from SurePosture deletes its assessments, snapshots, findings and reports.
  • To close your workspace and delete all of its data, contact [privacy contact email].

Revoking access

A tenant administrator can remove SurePosture's access at any time in the Entra admin centre: Identity → Applications → Enterprise applications → select the SurePosture application → Delete. Access stops immediately; the next assessment will fail and report that consent is missing.

Sub-processors

ProviderPurposeData involved
RenderApplication and database hostingAll data described on this page
[email delivery provider]Sending notification and invitation emailsRecipient email addresses, tenant names and summary results
StripeSubscription billingBilling contact and payment details (no tenant data)

Incidents

If we become aware of a personal data breach affecting your data, we will notify you without undue delay, with the information you need to meet your own obligations.

Contact

Data protection questions and data processing agreements: [privacy contact email]. Security issues: [security contact email]. [Company legal name] is registered with the Information Commissioner's Office under registration number [ICO registration number].