TRUSTED BY 40,000+ IT ADMINS

See where your Microsoft 365 governance stands today.

One scan gives you a score for your tenant, a short list of what to fix first, and a report you can send to your Head of IT.

Governance Autopilot assessment results with the tenant governance score and five scopes
Governance Autopilot score shown as today, priority, and full governance
Governance Autopilot recommendations list with policy IDs and severity levels

Solutions2Share is trusted by teams running Microsoft 365

THE PROBLEM

Microsoft 365 drifts over time.

Guests who should have been removed long ago. Teams with no owner. Sharing settings from a rollout three years ago that nobody has revisited. Nothing breaks on any single day, so it keeps getting postponed. Then a security review, an auditor, or a Copilot rollout asks whether your Microsoft 365 is in good shape.

THE SOLUTION

One read-only scan. A clear answer.

One scan runs 123 policies across five scopes. You get a score for your tenant, a short list of what to fix first, and a report you can send to your Head of IT. Nothing in your tenant is changed.

Apply for the beta
Governance Autopilot assessment results with tenant score, five scopes, and findings by severity
Governance Autopilot tenant score shown as today, priority, and full governance
THE PROBLEM

Can you show where your Microsoft 365 stands?

The evidence sits across several admin centers, and nobody has pulled it together. So the honest answer is usually "I think so."

THE SOLUTION

You know where you stand.

A score for your whole tenant, and a result for each of the five scopes with the weakest first. The score shows three steps: where you are today, where you'd be after the serious findings, and full governance. It carries a date, so you can say what has moved since.

Apply for the beta
THE PROBLEM

123 findings at once help no one.

A raw list of everything that is wrong reads like a report card. It doesn't tell you where to start.

THE SOLUTION

You know what to do first.

Every finding has a severity: Critical, High, Medium, or Informational. Open Critical and High findings carry a Priority mark, so the list you work from is short. Every recommendation says why it matters and what a correct setting looks like.

Apply for the beta
Governance Autopilot recommendation detail with severity, policy ID, and why it matters
Governance Autopilot PDF report that opens with what already works and is ready to forward
THE PROBLEM

The answer sits in several admin centers.

When a boss, an auditor, or a security review asks, pulling the evidence together by hand takes days you don't have.

THE SOLUTION

You can hand it to someone else.

Download the report as a PDF. It opens with what already works in your tenant, not a list of problems. Send it to your Head of IT without rewriting it. Every finding carries a policy ID anyone can look up next quarter.

Apply for the beta

123 governance policies across five scopes

The score comes from a catalog of 123 policies. Here is what each scope covers, with two real policies you can quote. Every policy has a fixed ID.

Identity and Access · 34 policies

Accounts, admin rights, sign-in protection, groups, and licenses. We flag unused accounts, admin rights spread too widely, groups with no owner, and licenses paid for but sitting on disabled accounts.

Examples

  • IDA-0026 Require MFA for all user sign-ins (Critical)
  • IDA-0034 Reduce permanent Global Administrator count (High)

Lifecycle and Owner · 34 policies

Who owns each Team and site, whether it is still used, archived, or a duplicate, and how the SharePoint structure is built.

Examples

  • LCO-0005 Resolve workspaces with no owners (High)
  • LCO-0014 Surface workspaces dormant for 180+ days (Medium)

Naming Conventions · 23 policies

Whether a naming rule exists and where names have drifted from it: old prefixes, migration leftovers, and test or demo names.

Examples

  • NAM-0002 Confirm a Microsoft 365 group naming policy is configured (Medium)
  • NAM-0011 Identify names containing test, sandbox, or demo (Informational)

External Sharing · 20 policies

Which guests still have access, who may invite them, what may be shared outside, and which other Microsoft 365 tenants yours connects to.

Examples

  • EXS-0012 Restrict guest invitation permission (High)
  • EXS-0001 Detect guests retained after guest access was disabled (High)

Storage and Retention · 12 policies

Where storage is growing and what is left behind: sites near their limit, departed users' OneDrive, oversized files, and meeting recordings piling up.

Examples

  • STR-0010 Surface OneDrive of departed users (Medium)
  • STR-0004 Detect sites approaching storage quota (Medium)

Four steps, and you only sit down for two of them.

One read-only scan checks 123 policies across five scopes. Nothing in your tenant is changed.

STEP 01

Sign in

An IT person signs in with their Microsoft account. Nothing to install. It only confirms who they are and gives us no access to your data.

STEP 02

Consent once

A separate Microsoft screen. Only an administrator can approve it, and it grants read-only rights one time.

STEP 03

The scan runs

Close the browser. The scan runs in the background on our servers, with nobody logged in. The first scan finishes within 24 hours.

STEP 04

Read the results

Your score, the five scopes, the findings, and the recommendations. Download the report as a PDF and send it on.

Doing the same by hand takes 35 to 41 hours. That's our own estimate: 123 policies at roughly 17 to 20 minutes each, finding the setting, reading the value, writing it down. Most policies cover tenant-wide settings, so it's about the same whether you have 50 users or 5,000.

It only reads. That's built in.

Signing in and giving consent are two separate steps. The sign-in only asks who you are. The consent step is manual, only an administrator can do it, and it grants read-only rights one time. The scan then runs on our servers with nobody logged in, and it identifies itself with a certificate in Azure Key Vault, not a shared password.

12 read-only permissions, plus 1 that only signs the user in, each listed publicly with its reason
We read Team membership, file names, and sharing settings, never Teams messages or the content of your files
Your data stays in the EU, stored in Germany, separate from every other customer
Read our security architecture

Ten years of Microsoft 365 experience, written into 123 policies.

The catalog wasn't generated automatically, and it isn't a public checklist. Our team decided which rules matter in a real tenant, how serious each one is, and what a good setting looks like, from the team behind Teams Manager and External User Manager. And you don't have to take our word for it.

Check our work

Every policy shows the exact test we ran on your tenant, so you can verify it yourself.

Microsoft's own position

Every policy links to Microsoft's documentation on Microsoft Learn, right next to ours.

A fixed ID per policy

Every policy has a fixed ID, for example IDA-0025, so you can quote it and compare next quarter.

Be one of the first to run it.

IT teams can run the assessment on their own tenant free of charge before we open it to everyone. After the test phase, Governance Autopilot becomes a paid solution. The beta starts in September. We're looking for real tenants, bigger and messier than our own test environment, and your tenant stays untouched throughout. Early participants also help shape the guided rollout we're building next.

Apply for the beta

Run it for your customers.

If you resell Microsoft 365 apps, run the assessment on a customer's tenant and use the result to open the conversation. Same scan, same report. Apply below and choose "I'm a partner."

TRUSTED & CERTIFIED

Recognized certifications and awards that stand for quality and security.

Solutions2Share Badges — ISO 27001, Microsoft 365 Certified, G2 Awards

Frequently asked questions

Everything IT teams ask before they run the assessment.

Does Governance Autopilot change anything in our tenant?

No. It only reads. Signing in and giving consent are two separate steps, and the consent an administrator grants is read-only. The scan can't change a single setting, because we never asked for the right to.

Which permissions does it need?

12 read-only permissions, plus 1 that only signs the user in. Every one is listed publicly on our Trust Center, with the reason we need it. See the full list at trustcenter.solutions2share.com/architecture-security/governance-autopilot.

Where is our data stored?

In the EU. Your tenant data is stored in Germany, and the web front-end runs in Western Europe. Data from one customer is never mixed with another. Ask us to delete your data and we do.

How long does the first scan take?

Give consent, then close the browser. The first scan finishes within 24 hours. Nobody has to wait in front of the screen.

Which Microsoft 365 license do we need?

Microsoft 365 E3 is enough.

What isn't covered yet?

Today the assessment covers Identity and Access, Lifecycle and Owner, Naming Conventions, External Sharing, and Storage and Retention. Scopes like Sensitivity Labels, Access Reviews, Compliance and Audit, and Power Platform and Copilot are planned, not included yet.

What does the beta cost?

Nothing. Access during the beta is free for our test group. After the test phase, Governance Autopilot becomes a paid solution.

Apply for the Governance Autopilot beta

Run the assessment on your own tenant and get a report you can forward. Free during the beta. Read-only. Nothing in your tenant is changed. Hosted in the EU.

You'll get a confirmation email right away and a personal reply from us within two working days.