CyberProva transparency

What CyberProva checks

See which Microsoft 365 and external controls CyberProva checks automatically, which need evidence, and where review is still required.

Identity and access

Automatically checked when Microsoft 365 is connected: user and guest inventory, current privileged-role assignments, Conditional Access policy observations and directory audit availability. An observation can require review rather than establish a pass.

  • Advanced assessment: MFA registration and policy coverage, legacy authentication, security defaults, inactive accounts, guest age and sign-in risk, subject to permissions and licences.
  • Evidence required: separate administrator accounts, joiner and leaver processes, justified exceptions and regular access reviews. Inventory alone does not prove these processes happen.

Microsoft 365 configuration

Automatically checked: Microsoft Secure Score. Advanced assessments also review application ownership and credential expiry metadata, privileged access, selected Intune device policies, password-protection settings and sharing configuration.

  • Evidence required: complete Purview audit configuration and Exchange mailbox auditing. Directory audit activity is only a partial observation.
  • Microsoft licensing, granted permissions and the selected CyberProva plan affect which checks can run. Unavailable data is not a pass.

Email security

Evidence required for Exchange anti-phishing protection, automatic forwarding, mailbox forwarding rules and Safe Links/Safe Attachments settings. CyberProva does not read your email messages to establish these controls.

  • Ask your IT provider for dated policy exports or settings evidence.
  • DNS email-authentication observations are separate from an Exchange policy review.

Sharing and collaboration

Automatically checked in the advanced assessment where access is granted: tenant-wide SharePoint and OneDrive sharing settings and selected link-expiry settings.

  • This is not a file-by-file permissions audit or a review of document contents.
  • Evidence required for actual access reviews and business approval of external sharing.

DNS and email authentication

Automatically checked for a verified website/domain on a supported plan: SPF, DMARC, the supplied DKIM selector, DNSSEC observations and selected DNS records.

  • Finding a record does not prove all senders are authorised, DKIM is signing messages or DMARC is enforced.
  • Some records require interpretation, including organisational-domain inheritance and DNS lookup limits.

Website and external controls

Automatically checked for a verified website: selected public HTTP/TLS observations and security headers. Available observations depend on the plan and what the public endpoint returns.

  • Domain ownership must be verified before monitoring.
  • This is not penetration testing, an authenticated application audit or a complete vulnerability scan.

Controls requiring evidence from your organisation or IT provider

Microsoft 365 cannot establish every control protecting your business. CyberProva records supplied evidence and lets your workspace reviewer accept it.

  • Device patching and endpoint protection across the wider estate.
  • Backup coverage, protection and successful restore tests.
  • Staff training, incident response exercises, policies and supplier reviews.
  • Network configuration, payment-fraud processes and data-protection records.
  • Evidence received or accepted is not independent certification of the underlying facts.