Skip to main content

Running Assessments

How to run compliance assessments in Securtea

assessmentcomplianceevaluationframeworks

Running Assessments

Compliance assessments evaluate your Microsoft 365 configuration against security frameworks. Learn how to run on-demand and scheduled assessments.

Prerequisites

Before running an assessment, ensure:

  • Microsoft 365 connected - App registration configured and working
  • Permissions granted - Required Graph API permissions are consented
  • Framework selected - Know which framework(s) to assess against

On-Demand Assessment

Starting an Assessment

  1. Navigate to Compliance in the sidebar
  2. Click the Run Assessment button
  3. Configure the assessment options
  4. Click Start Assessment

Assessment Options

Framework Selection

Choose one or more frameworks to assess:

  • CIS Microsoft 365 Foundations
  • NIST 800-53
  • SOC 2
  • ISO 27001

Scope Options

Customize what to include:

OptionDescription
All ControlsEvaluate every control in selected frameworks
Critical OnlyFocus on critical and high severity controls
Failed OnlyRe-evaluate only previously failed controls

Evidence Collection

Control evidence gathering:

OptionDescription
Full EvidenceCollect detailed evidence for all controls
Summary OnlyCollect minimal evidence for faster assessment

Assessment Progress

Once started, you'll see:

  • Progress bar - Percentage of controls evaluated
  • Current phase - Data collection, evaluation, or reporting
  • Control status - Real-time pass/fail updates
  • Estimated time - Approximate completion time

Assessment Duration

Typical assessment times:

ScopeDuration
Single framework (CIS)2-5 minutes
Multiple frameworks3-7 minutes
Large tenant (1000+ users)5-10 minutes
Failed controls only1-2 minutes

Scheduled Assessments

Setting Up a Schedule

  1. Go to Compliance > Settings
  2. Click Assessment Schedule
  3. Configure the schedule
  4. Click Save

Schedule Options

Frequency

OptionWhen It Runs
DailyEvery day at specified time
WeeklySpecified day and time
MonthlySpecified date and time

Time Configuration

  • Time: Select the hour (in your time zone)
  • Day: For weekly, select the day of week
  • Date: For monthly, select the day of month

Schedule Examples

Daily Morning Assessment

  • Frequency: Daily
  • Time: 6:00 AM
  • Frameworks: CIS, NIST

Weekly Compliance Review

  • Frequency: Weekly
  • Day: Monday
  • Time: 8:00 AM
  • Frameworks: All

Monthly Audit Preparation

  • Frequency: Monthly
  • Date: 1st
  • Time: 12:00 AM
  • Frameworks: SOC 2

Managing Schedules

ActionHow To
PauseToggle schedule to inactive
ResumeToggle schedule to active
ModifyClick Edit on the schedule
DeleteClick Delete (with confirmation)

Assessment Results

Viewing Results

After an assessment completes:

  1. Click the notification or go to Compliance > History
  2. Select the assessment run
  3. Review the summary and details

Results Overview

The results page shows:

  • Overall Score - Compliance percentage
  • Status Breakdown - Passed, failed, manual review, N/A
  • Severity Distribution - By critical, high, medium, low
  • Framework Summary - Per-framework scores

Drilling Into Details

Click on any framework or theme to see:

  • Individual control results
  • Evidence collected
  • Remediation guidance
  • Historical comparison

Re-Running Assessments

When to Re-Run

Re-run assessments when:

  • You've remediated failed controls
  • Configuration changes were made
  • Significant time has passed
  • Before an audit or review

Re-Run Options

Full Re-Assessment

  • Evaluates all controls fresh
  • Updates all evidence
  • May show new failures or passes

Failed Controls Only

  • Re-evaluates only previously failed controls
  • Faster execution
  • Useful after targeted remediation

Troubleshooting

Assessment Won't Start

Cause: Connection issue or permissions problem.

Fix:

  1. Go to Settings > Integrations
  2. Click Test Connection
  3. If failed, review app registration
  4. Ensure admin consent is granted

Assessment Stuck

Cause: Large tenant or API rate limiting.

Fix:

  1. Wait 10-15 minutes for completion
  2. If still stuck, cancel and retry
  3. Consider running during off-peak hours

Missing Controls

Cause: Controls may require specific licenses or configurations.

Fix:

  1. Check if the feature is enabled in your tenant
  2. Verify required licenses are assigned
  3. Some controls are marked N/A if not applicable

Inconsistent Results

Cause: Configuration changed between assessments.

Fix:

  1. Compare assessment timestamps
  2. Review drift events for configuration changes
  3. Note that some Microsoft data has propagation delays

Best Practices

Assessment Frequency

ScenarioRecommended Frequency
Active remediationDaily
Stable environmentWeekly
Compliance maintenanceMonthly
Pre-audit preparationOn-demand

Framework Strategy

  1. Start with CIS - Most M365-specific guidance
  2. Add NIST/SOC 2 - For broader compliance needs
  3. Include ISO - If pursuing certification

Evidence Management

  • Run with full evidence before audits
  • Use summary mode for routine checks
  • Export evidence for offline review

What's Next?

Global Search

Search for pages, settings, and documentation