Register free and run this on any client's Microsoft 365 tenant. Download the full sample suite below — generated from a real Microsoft 365 tenant and fully de-identified — then scroll on for an illustrative walkthrough of the live portal report. The full version is yours to generate and share, branded as your MSP.
Every report below is generated from the same agentless scan of the same tenant — a real multi-studio business, fully de-identified. The numbers reconcile, because they are the same numbers. Download any of them.
An AI agent is a non-human identity. It is a type within the category, not a separate thing. There is no separate "AI agent report", because there is no separate population. AI agents appear as a filter and a row type inside every report above.
The reports above answer “who is watching the machines?” The AI Readiness Assessment answers a different question — “are we ready to turn on Copilot?” A separate 112-check assessment that scores your tenant 0–100 against CIS Benchmarks and the NIST AI Risk Management Framework, tells you plainly if it’s safe to switch AI on, and gives a 30/60/90 plan if it isn’t. It is a separate product from AIRM. It is free — three scans per tenant, for MSPs and end customers alike, and each customer tenant gets one assessment. Full details →
The assessment runs on your Microsoft 365 tenant, agentless, with nothing changed. Register and generate your own AI Readiness Score — three free scans per tenant, branded as your MSP.
Get your free AI Readiness Score → Free · connect a Microsoft 365 tenant · no credit cardOf 38 identities with High or Critical blast radius, these 8 also have no owner, an unverified publisher, or a dormant credential. That combination is what escalates them. The other 411 are routine. Full inventory of 431 in the live report.
| Identity | Type | Can access | Owner | Risk |
|---|---|---|---|---|
| PnP-Provisioning-Svc | AI agent | Mail.ReadWrite, Files.ReadWrite.All (tenant-wide) | None | Critical |
| OpenAI-Connector | AI agent | Mail.Read, Files.Read.All | None | Critical |
| ProspectEngine | AI agent | Directory.Read.All, Mail.Read | None | High |
| Copilot Studio, HR bot | AI agent | SharePoint (HR), Dataverse | J. Patel | High |
| InboxGuard-365 | App reg | Mail.ReadWrite (all mailboxes) | None | High |
| svc-legacy-backup | Svc principal | Sites.Read.All (dormant 428 days) | None | High |
| DataBridge-Sync | Connector | Files.Read.All, external egress | IT Ops | High |
| Notion AI Workspace | AI agent | Files.Read.All | None | High |
"OpenAI-Connector" holds tenant-wide Mail.Read and Files.Read.All granted 7 months ago; no business owner recorded. Highest-priority remediation.
Permissions far exceed observed activity, classic blast-radius exposure if any are compromised.
Unused >90 days but still hold live permissions, candidates for review and removal.
Prioritised remediation, generated automatically. Execution runs on an AIRM subscription, the free report shows you exactly what to do.
Findings mapped to 11 frameworks. ● aligned · ● gaps · ● action required.
Register, connect a Microsoft 365 tenant, and generate this full report in minutes. Subscribe per tenant to execute the actions and keep monitoring.
Free Sabiki NHI Risk Score →Northwind Trading is a fictional demo tenant used for the walkthrough above. The product, the scan and the numbers are real; the company and identity names are not. The downloadable sample suite at the top of this page is different: real production-scan reports, fully de-identified, with every figure adjusted so no client is attributable.