SYAGA Audit audits your Microsoft 365 security configuration without ever touching it, with no server agent and no access to your content. Here's exactly how.
SYAGA Audit only read your tenant's configuration: the audit is 99% read-only. An add-on (SharePoint all sites, Defender) that Microsoft does not allow to be reached through any read access: the narrowest it offers is write-capable. This is not our limit, it is that of the Microsoft API. We offer it to you as an option, justified, and you decide. In all cases we never write anything: the operation takes place on your side, never on our servers, and you verify it yourself on the consent screen and in your own Microsoft logs.
Access is granted by your administrator via the consent screen official Microsoft, which lists the requested permissions. You remain in control at all times.
SYAGA Audit works entirely remotely, via the Microsoft API. Nothing to deploy on your side, no added attack surface on your network.
The SYAGA Audit infrastructure is hosted in Europe. Your audit results remain subject to French and European law.
Every audit is timestamped and documented. An attestation and an integrity log (planned for launch) will accompany the report so that you can verify its provenance.
Let's be precise. Collection and pseudonymisation run in your browser (extension): your real raw data never leaves and is never sent to us. The service only receives pseudonymised fingerprints. Your audit results (score, gaps, tokenised report) are kept in your client area, for as long as you remain a client, so that you can reopen them and track your progress; they are re-contextualised in the clear only on your device. Your billing information (the strict legal minimum) are also retained, encrypted, never resold and deletable on simple request (GDPR).
No installation, no password, revocable at any time.
A question about data protection? See the page Privacy.
The report is a diagnostic: it states what is observed, it does not fix anything on your behalf.