Collection
Direct API reads
Microsoft Graph and the Exchange and Teams administration APIs are queried read-only from an application registered in the tenant. No action on endpoints.
Configuration audit · CIS Benchmarks
Tenovia compares the actual configuration of your environments with the CIS Benchmarks, read-only, through direct calls to the administration APIs. You get a time-stamped finding, traceable evidence and a prioritised remediation plan.
Coverage
Two public frameworks, 249 recommendations, 821 pages of recommendations. Here is what Tenovia verifies on each platform, and by what means.
Benchmark v7.0.0
160 recommendations · 580 pages read for you
160 of 160 covered
CIS itself declares 17 of its recommendations non-automatable. No tool covers them programmatically. Tenovia puts them as precise questions and folds them into the same report: you get all 160, not 143 and a gap.
See Microsoft 365 coverageBenchmark v1.3.0
89 recommendations · 241 pages read for you
89 of 89 covered
CIS declares all 89 of its recommendations manual, without exception: the official framework holds that auditing Google Workspace is done by hand, screen by screen. Tenovia collects 79 of them automatically through the Cloud Identity Policy API, read-only. The remaining 10 are exposed by no interface; they are put as precise questions and folded into the same report: you get all 89, not 79 and a gap.
See Google Workspace coveragePlatform
Data is read at source, assessed by written rules, and reported together with its evidence. Nothing is declared, everything is observed.
Collection
Microsoft Graph and the Exchange and Teams administration APIs are queried read-only from an application registered in the tenant. No action on endpoints.
Assessment
Every collected line is matched against a readable, versioned and replayable rule. The verdict is reproducible from one audit to the next.
Evidence
Object, property, value, collection date: every finding retains the raw data behind it. An external auditor can retrace the path.
Reporting
Gaps ranked by severity, effort and gain, with the original wording of the CIS control and the expected correction.
Follow-up
The second audit reads as a difference: what has been fixed, what has regressed, what has not moved.
Deployment
Shared console, or deployment on your own infrastructure where your policy forbids configuration data leaving your estate.
Method
Your technical teams are only involved in the first step.
Registration of a read-only application in the tenant and admin consent.
Automated API queries. Raw data is normalised into a single format and time-stamped.
Compliance rules are applied, domain scores computed and gaps identified.
Audit report, supporting evidence and prioritised remediation plan, presented in session.
Audited scopes
Two environments, one console, one evidence format.
Based on the CIS Microsoft 365 Foundations Benchmark v7.0.0 of 20 May 2026.
Based on the CIS Google Workspace Foundations Benchmark v1.3.0, which contains 89 recommendations, 73 at level 1 and 16 at level 2. CIS declares every one of them manual: Tenovia collects them through the Cloud Identity Policy API, read-only.
Regulatory mapping
A technical finding is only worth something if it maps to a requirement. Every gap is tied back to the framework that demands it, together with the original wording of the control.
The baseline measures expected under article 21 cover access management, security policy and configuration control. A CIS audit documents the actual state of those measures across messaging and collaboration, with a defensible finding date.
For financial entities and their providers, ICT risk management requires knowing and controlling system configuration. The report provides the time-stamped technical evidence that supervisors expect.
Annex A covers privileged access, logging and cloud service security among others. CIS findings feed directly into the evidence presented to your certification auditor.
Security of processing requires appropriate technical measures. External sharing, anonymous links, retention and guest access are configuration points that directly condition that compliance.
ANSSI hygiene guidance and sector frameworks are handled on the same principle. Tenovia produces technical evidence: compliance remains yours to steer, and the report is not an attestation.
Frequently asked questions
It is the comparison of the actual configuration of a Microsoft 365 tenant with the recommendations of the CIS Microsoft 365 Foundations Benchmark, a public hardening framework published by the Center for Internet Security. The audit does not judge usage, it observes settings.
No. Tenovia queries the Microsoft APIs directly in read-only mode from an application registered in the tenant. No script is sent, run or maintained by your teams, which removes the main source of friction and risk in conventional audits.
Read permissions only, on Microsoft Graph and on the relevant administration APIs. No write permission is requested. The exact list is provided before onboarding and can be reviewed by your security team.
Yes. CIS hardening measures provide technical evidence that can be used directly to demonstrate control of the baseline hygiene expected by NIS2 and by Annex A of ISO/IEC 27001. The report indicates the mapping for each finding.
Yes, on the same footing as Microsoft 365. The CIS Google Workspace Foundations Benchmark v1.3.0 contains 89 recommendations, every one of which the Center for Internet Security declares manual. Tenovia collects them automatically through the Cloud Identity Policy API, read-only, and reports them in the same document as Microsoft 365.
A demo on a test environment, or a pilot audit on your own tenant. Judge on the report, not on the promise.