Security posture management for small businesses and MSPs
Find the security gaps before attackers do
Attackers exploit misconfigured Microsoft 365, weak email settings, and unprotected endpoints. PosturIQ checks all three - identity, email, and devices - so you close the gaps first.
A story that plays out every day
One phishing email. Two paths to disaster. PosturIQ checks the settings that let these attacks succeed.
Three pillars, one dashboard
Hundreds of security settings to get right. We check the ones that matter most - and explain each one in plain language. No security expertise needed.
Microsoft 365
Automated checks via Microsoft Graph API - no agent needed.
- ✓ MFA enforcement & registration gaps
- ✓ Legacy authentication blocked
- ✓ Global admin count & hygiene
- ✓ OAuth consent & risky third-party apps
- ✓ Inactive licensed users (90+ days)
- ✓ Guest access & external sharing
- ✓ Device code flow blocked
- ✓ Audit logging enabled
Devices
Windows & macOS checks. Lightweight scripts, no MDM needed.
- ✓ Antivirus / XProtect active
- ✓ OS patching & auto-update
- ✓ Disk encryption (BitLocker / FileVault)
- ✓ Firewall all profiles enabled
- ✓ RDP disabled / remote login off
- ✓ Screen lock timeout ≤5 min
- ✓ Software updates (winget)
- ✓ Local admin account sprawl
Automated checks via Exchange Online - EOP & Defender for Office 365.
- ✓ Impersonation protection (CEO fraud)
- ✓ Safe Links & Safe Attachments
- ✓ External forwarding blocked
- ✓ Spam filter bypass rules (SCL=-1)
- ✓ DKIM signing & DMARC enforcement
- ✓ Anti-spam & anti-malware alignment
- ✓ Preset security policy active
How it works
Start free trial
Sign in with your Microsoft account. No setup wizard.
Connect Microsoft 365
Grant read-only access via OAuth admin consent. We never modify your settings.
Get your security score
Checks run automatically. See your score, findings, and remediation steps in seconds.
For MSPs
All your clients, one dashboard
Multi-tenant dashboard with aggregate scores, per-client drill-in, weekly digest emails, and PDF reports. Onboard clients in minutes with admin consent - no client interaction needed.
- ✓ Multi-tenant client overview with scores
- ✓ One-click client onboarding (admin consent)
- ✓ Per-client PDF reports & CSV exports
- ✓ Weekly digest email across all clients
- ✓ Multi-user access with roles
Simple, flat pricing
No per-user fees. No per-device fees. No calculator needed.
Standard
or €79/month billed annually
- ✓ One M365 tenant
- ✓ Security checks across M365, Identity, Email and Devices
- ✓ Weekly automated scans
- ✓ PDF reports & CSV exports
- ✓ Email notifications
MSP
includes 25 client tenants
- ✓ Everything in Standard
- ✓ Multi-tenant dashboard
- ✓ Admin consent onboarding
- ✓ Weekly client digest email
- ✓ +€29/month per extra tenant
Built for teams without a security department
Read-only access
We never modify your M365 settings. PosturIQ reads configuration data through Microsoft Graph - nothing is changed.
Data stored in EU
All data is processed and stored in Azure European data centers. No data leaves the EU.
No agents to install
M365 and email checks run via API. Endpoint scripts run locally on devices - only results are sent back.
See your security score today
Automated security checks. Identity, email, and endpoints. Free for 30 days.
Start 30-day free trial