Rolling out Copilot? Run this check first. It reads everything your staff can.

Free · read-only · before Copilot

See everything your Microsoft 365 is exposing.

Before you switch Copilot on, a free read-only scan of what it will surface to your staff: oversharing, anonymous links, broad and org-wide access, and unlabelled content. You get a clear score across six areas, measured against the Glow Cloud M365 Security Framework, plus the exposure findings that matter most. You grant a temporary, read-only role (such as Global Reader) for a scheduled window; we run the scan and retain nothing. Prefer to run it yourself? Use our sealed tool instead.

  • Temporary read-only access
  • A scheduled window; we retain nothing
  • Report and readout within a few working days

Request your health-check

No cost. No sales call required.

Or see a sample health-check first, no email needed.

Beyond the free check

Go deeper with the paid assessment.

T1

Full security assessment

Every control scored across the Glow Cloud M365 Security Framework and 6 platforms, with evidence and a recommended fix.

T2

Sharing deep-dive

Every site ranked by exposure, then every link drilled down to who can reach it and whether it expires.

Six areas we assess

Distilled to what matters, not a settings dump

Identity & access

MFA coverage · Legacy auth · Admin roles · Conditional access

Devices · Intune

Enrolment · Compliance · Encryption · Unmanaged devices

SharePoint & sharing

Link scope & expiry · External access · Org-wide access · Permissions

Email security

SPF · DKIM · DMARC · Anti-phishing

Data protection

Sensitivity labels · DLP · Retention · Oversharing

Copilot readiness

What Copilot can surface · Broadly shared content · Label coverage

What it surfaces

See exactly where you are oversharing.

The free check flags the sites open too widely: anonymous links, org-wide access and guest sprawl, the exact exposure Copilot would surface. Want it mapped link by link, with who can reach what? That is the full assessment.

Sharing report · Tier 1 · per-site read-only

Melbrooke Ltd · 40 sites · SharePoint & OneDrive

Where the exposure is

102
Total links
15
Anyone (anon)
16
External / guest
11
Sites w/ anon
All sites Has anonymous Has external Tier 1 · per site
SiteAnyoneOrgSpecificGuest
Executive Team 2 0 0 0
Finance 2 0 0 0
HR Team 2 0 0 0
Warranty 2 0 0 0
Stanmore Service 1 5 0 0
Prepared by Glow CloudTier 1 · per-site exposure

Why it's different

Most security reviews cost thousands, or want standing access to everything.

There are really three ways to find this out today: run a free script and interpret it yourself, pay for a governance platform that connects to your tenant and keeps your data in its cloud, or buy a Microsoft add-on and read the dashboards yourself. Ours is the missing fourth: free, focused on what Copilot will expose, and actually delivered. You grant a temporary, read-only role (such as Global Reader) for a scheduled window; we hand you an interactive report of where you stand and what to harden, then your access expires. It reads the settings about your tenant, never the files, mail or messages inside it. The only thing kept is the report we give you, and every read is recorded in your own Microsoft 365 audit log.

Free

Not a paid platform, an E5 add-on, or a consultancy day rate.

Read-only, and revocable

It reads settings about the tenant, never your files or mail. Access is temporary, you can revoke it any time, and every read shows in your own audit log.

Interactive, and explained

A live report you filter and drill into, by platform, domain and severity, plus a readout. Not a static PDF or a raw script to decode.

The report

Not another raw score dump.

A raw native score buries the signal under hundreds of granular toggles. Ours surfaces the security-critical configurations, their current state, and what to harden first, so you see your posture in minutes, not a spreadsheet to wade through.

  • Only the configurations that actually move your security posture
  • Each shown with its state: solid, or needs hardening
  • Prioritised High → Low, so you know what to fix first
  • Plain English. Readable in minutes, by humans.
Copilot readiness check read-only

Melbrooke Ltd · June 2026

High Risk · Not Ready

Critical oversharing is present. Resolve the High items before enabling Copilot.

14
Assessed
3
Passing
1
High
4
Medium

Top findings

Content-exposure surface for Copilot High
No domain-based external sharing restriction Med
No expiration on external sharing Med
Prepared by Glow CloudCopilot readiness · read-only

“11 sites open to the whole company.” A real first finding.

Open the full sample report →

After the free check

Go deeper: the full security assessment.

The free check is the Copilot-readiness slice. If you decide to go further, the paid deep-dive scores every control across the Glow Cloud M365 Security Framework and 6 platforms, then maps sharing site by site and link by link. Here is exactly what that report looks like.

Temporary read-only access We retain nothing Or run our sealed tool yourself
Get started →

Questions, answered

The bits people ask first.

Is the Microsoft 365 health-check really free? +

Yes. It is a free, no-obligation assessment. You keep the report whether or not you go on to work with us.

How do you access my tenant? +

You grant a temporary read-only role (such as Global Reader) that you can revoke at any time, or you run a sealed script yourself and send us the output. Nothing is installed, and you stay in control throughout.

What does the assessment cover? +

Six areas: identity and access (MFA, legacy auth, admin roles), devices and Intune, SharePoint and external sharing, email security (SPF, DKIM, DMARC), data protection (labels, DLP, retention) and Copilot readiness. Findings are scored against the Glow Cloud M365 Security Framework.

Will it tell me if we are ready for Microsoft 365 Copilot? +

Yes. We flag the oversharing, broadly shared content and label gaps that Copilot would surface to users, so you can fix them before you switch Copilot on.

Do I have to buy anything afterwards? +

No. There is no obligation. If you want help fixing what we find, we can quote a remediation sprint, but the report and the priorities are yours to keep.