---
title: Utilizing Self-Service M365 Security Assessments
description: User guide for executing AgileBlue's M365 Security Scans.
---

[Skip to content](https://help.agileblue.com/m365-security-assessments#main-content)

English

Show submenu for translations

[Contact AgileBlue Support](https://help.agileblue.com/kb-tickets/new?hsLang=en) [Customer portal](https://help.agileblue.com/support-ticket-status?hsLang=en)

![FullColor-800px-Aug-04-2025-07-56-16-5066-PM.png\]](https://help.agileblue.com/hs-fs/hubfs/FullColor-800px-Aug-04-2025-07-56-16-5066-PM.png?height=32&name=FullColor-800px-Aug-04-2025-07-56-16-5066-PM.png)

Open main navigation

Close main navigation

- English
  
  Show submenu for translations
- [Contact AgileBlue Support](https://help.agileblue.com/kb-tickets/new)
- [Customer portal](https://help.agileblue.com/support-ticket-status)
- AgileBlue Portal

 AgileBlue Portal

 Hello. How can we help you?

- There are no suggestions because the search field is empty.

1. [Help Center](https://help.agileblue.com/?hsLang=en)
2. [AgileBlue Features](https://help.agileblue.com/agileblue-features?hsLang=en)
3. [Portal Management](https://help.agileblue.com/agileblue-features?hsLang=en#portal-management)

# Utilizing Self-Service M365 Security Assessments

## AgileBlue enables customers to access deep visibility into their M365 Security configuration through on-demand and scheduled assessments.

### Overview

AgileBlue securely connects your M365 tenant to run on-demand and scheduled security assessments using M365 modules and CISA’s ScubaGear. Results are then processed by our reporting engine and presented as clear summaries and risk scores, along with actionable remediation guidance to help improve your M365 security posture.

---

### Prerequisites

- Access to the **Microsoft Entra Admin Console** 
- Sufficient administrative privileges to grant API permissions and assign directory roles 
- ScubaGear Certificate File 
- Permissions to create application registrations 

---

### Download ScubaGear Certificate

1. Log in to the [AgileBlue SecOps Portal](https://portal.agileblue.com/login)
2. In the left-hand column, navigate to **Office365 Assessment**
3. Toggle the switch to **Enabled**
4. Click **Download Certificate**

Please note, this certificate will be valid for 365 days. When that timeframe has passed, the download certificate button will become available and the cert will need to be refreshed.

---

### Register A New Azure Application

1. Log in to the **Microsoft Entra Admin Console**
2. Navigate to **Entra ID**
3. Select **App registrations**
4. Click **New registration**
5. Provide a name for the application (use any name that can be easily referenced, ex. **AgileBlueScuba**)
6. Click **Accounts in this organizational directory only (Single tenant)
   
   ![](https://help.agileblue.com/hs-fs/hubfs/undefined-Feb-06-2026-09-42-10-5582-PM.png?width=670&height=468&name=undefined-Feb-06-2026-09-42-10-5582-PM.png)**
7. Select **Register**
8. After registering the application, copy the **Application (client) ID**, which will be needed for the **Assessment Configuration Form** in our portal
   
   ![Group 1, Grouped object](https://help.agileblue.com/hs-fs/hubfs/undefined-Feb-06-2026-09-44-50-5892-PM.png?width=625&height=107&name=undefined-Feb-06-2026-09-44-50-5892-PM.png)
9. Next, collect your **Primary Domain**, which can be located on the landing page of Azure on the Overview page; this will be used for the **Organization** field later on
   
   ![](https://help.agileblue.com/hs-fs/hubfs/undefined-Feb-06-2026-09-45-35-8270-PM.png?width=670&height=285&name=undefined-Feb-06-2026-09-45-35-8270-PM.png)  
   ![](https://help.agileblue.com/hs-fs/hubfs/undefined-Feb-06-2026-09-45-41-9469-PM.png?width=670&height=196&name=undefined-Feb-06-2026-09-45-41-9469-PM.png)

---

### Configure Microsoft Graph API Permissions

1. From the app created in the previous section, select **API permissions**
2. Click **Add a permission**
3. Choose **Microsoft Graph**
4. Select **Application permissions**
5. Add the following permissions: 
     1. *Directory.Read.All*
     2. *GroupMember.Read.All*
     3. *Organization.Read.All*
     4. *Policy.Read.All*
     5. *RoleManagement.Read.Directory*
     6. *RoleManagementPolicy.Read.AzureADGroup*
     7. *PrivilegedAccess.Read.AzureAD*
     8. *PrivilegedEligibilitySchedule.Read.AzureADGroup*
     9. *User.Read.All*
6. Click **Add permissions**

---

### Configure Additional API Permissions

#### Exchange Online Permissions

1. Click **Add a permission**
2. Choose **APIs my organization uses**
3. Search for **Office 365 Exchange Online** and select in, then choose **Application permissions**
4. Add the following permission: 
     1. *Exchange.ManageAsApp*
5. Click **Add permissions**

#### SharePoint Permissions

1. Once again, click **Add a permission**
2. Choose **Microsoft APIs**
3. Search for and select **SharePoint**
4. Choose **Application permissions**
5. Add the following permission: 
     1. *Sites.FullControl.All*
6. Select **Add permissions**

Once all permissions have been added, the full list should look like the image below:

![](https://help.agileblue.com/hs-fs/hubfs/undefined-Feb-09-2026-04-16-45-1262-PM.png?width=670&height=352&name=undefined-Feb-09-2026-04-16-45-1262-PM.png)

---

### Grant Admin Consent

1. Confirm the permissions listed above are present
2. Select **Grant admin consent**
3. Click **yes** on the popup
   
   ![](https://help.agileblue.com/hs-fs/hubfs/undefined-Feb-09-2026-04-17-38-9971-PM.png?width=670&height=112&name=undefined-Feb-09-2026-04-17-38-9971-PM.png)
4. Confirm the green check mark under **Status** is present as in the image below
   
   ![](https://help.agileblue.com/hs-fs/hubfs/undefined-Feb-09-2026-04-18-07-6277-PM.png?width=670&height=351&name=undefined-Feb-09-2026-04-18-07-6277-PM.png)

---

### Assign the Global Reader Role

1. Navigate to **Roles & Administrators**
2. Click **here** as indicated in the image below
   
   ![](https://help.agileblue.com/hs-fs/hubfs/undefined-Feb-09-2026-04-20-24-6109-PM.png?width=670&height=82&name=undefined-Feb-09-2026-04-20-24-6109-PM.png)
3. Search for **Global Reader**
4. Click the **Global Reader** role text; DO NOT click on the checkbox
   
   ![](https://help.agileblue.com/hs-fs/hubfs/undefined-Feb-09-2026-04-20-56-0569-PM.png?width=670&height=102&name=undefined-Feb-09-2026-04-20-56-0569-PM.png)
5. Select **Add assignments
   
   ![](https://help.agileblue.com/hs-fs/hubfs/undefined-Feb-09-2026-04-21-33-5959-PM.png?width=670&height=155&name=undefined-Feb-09-2026-04-21-33-5959-PM.png)**
6. Click **No Members Selected
   
   ![](https://help.agileblue.com/hs-fs/hubfs/undefined-Feb-09-2026-04-21-52-8528-PM.png?width=670&height=583&name=undefined-Feb-09-2026-04-21-52-8528-PM.png)**
7. Search for the application name created earlier
8. Check box to attach **Global Reader role**
9. Verify that the correct application has been chosen, then click **Select
   
   ![](https://help.agileblue.com/hs-fs/hubfs/undefined-Feb-09-2026-04-22-25-9866-PM.png?width=670&height=520&name=undefined-Feb-09-2026-04-22-25-9866-PM.png)**
10. Verify all values are correct and click **Next
    
    ![](https://help.agileblue.com/hs-fs/hubfs/undefined-Feb-09-2026-04-22-45-3401-PM.png?width=613&height=936&name=undefined-Feb-09-2026-04-22-45-3401-PM.png)**
11. Provide justification for access and maintaining permeance then click **Assign
    
    ![](https://help.agileblue.com/hs-fs/hubfs/undefined-Feb-09-2026-04-23-21-9960-PM.png?width=627&height=936&name=undefined-Feb-09-2026-04-23-21-9960-PM.png)**
12. Click **refresh**

---

### Power Platform Permissions

1. Open a PowerShell session with administrative permissions
2. Check if PowerApps has been installed
3. Run the command below:
   
   ```
   Get-Module -Name *PowerApps* | Format-List Name
   ```
   
   ![](https://help.agileblue.com/hs-fs/hubfs/undefined-Feb-09-2026-04-29-42-7360-PM.png?width=670&height=120&name=undefined-Feb-09-2026-04-29-42-7360-PM.png)
4. If you do not see any results, use the following command to install the PowerApps library:
   
   ```
   Install-Module -Name Microsoft.PowerApps.Administration.PowerShell -Scope CurrentUser –Force
   ```
   
   ![](https://help.agileblue.com/hs-fs/hubfs/undefined-Feb-09-2026-05-11-29-7162-PM.png?width=670&height=14&name=undefined-Feb-09-2026-05-11-29-7162-PM.png)
5. Allow the command to complete and accept any confirmations presented
6. Execute the below command:
   
   ```
   Add-PowerAppsAccount -Endpoint prod -TenantId (insert Tenant ID)
   ```
   
   Be sure to insert your Tenant ID, which can be gathered from the **Entra ID Administrative Page** by selecting **Overview**
   
   When prompted to authenticate, ensure you are using an account that has either Power Platform Admin or Global admin permissions.
   
   NOTE: If this is a government organization in a GCC tenant, replace "-Endpoint prod" with "-Endpoint usgov"
7. Execute the following command (be sure to include the Application ID from the app created earlier in this guide)
   
   ```
   New-PowerAppManagementApp -ApplicationId (Insert App Id)
   ```
   
    
8. Close the PowerShell window

---

### Upload the O365 Assessment Certificate

1. Return to your created **Application** and select **Certificates & Secrets**
2. Click **Certificates**
3. Select **Upload certificate**
4. Navigate to the location to which the certificate downloaded in the first section of this guide (**Download ScubaGear Certificate**) is saved
5. Upload the certificate
6. Click **Add**
7. Copy the **Thumbprint value** found on the ensuing page, which will be needed later on
   
   ![](https://help.agileblue.com/hubfs/undefined-Feb-09-2026-05-23-26-4927-PM.png)

### Complete Application Fields In AgileBlue Portal

1. Return to the AgileBlue portal and navigate back to **Office365 Assessment**
2. Fill in the information gathered in the previous sections: 
     1. **Application ID**
     2. **Organization**
     3. **Certificate Thumbprint**
3. Under **Products to Assess**, select each of the Microsoft products to be included in the scan
4. Select the **Environment Sensitivity** appropriate for your organization: 
     1. Non-government tenant
     2. Government cloud tenant
     3. Government cloud tenant (high)
     4. Department of Defense tenant
5. Click **Save Configuration**

---

### Scanning Cadence

#### On-Demand

Once the configuration has been saved, you can use the **Scan Now** button any time to execute an on-demand scan. Once a scan is completed, it will appear in the **Assessment Scan History **section and will include the start and finish times, the user who initiated the scan, and a summary of the findings. Full reports can be downloaded as a CSV file from the right-hand column.

#### Scheduled

To schedule recurring scans, click the **+** icon under **Current Assessment Schedules**. You can then choose specific dates or set scans to run automatically at regular intervals. Scans can occur multiple times per day, week, or month, or on a specific day of the week, month, or year.

These options are geared toward providing flexibility to automate your scanning workflow and ensure your products are assessed on a consistent, predictable schedule.

---

### **Need Help?** 

AgileBlue is always here to support you and ensure you are 100% successful. If there are any issues with the installation or if you have any questions, please reach out to [**AgileBlue Support**](https://help.agileblue.com/kb-tickets/new?hsLang=en). 

*Email: *[*support@agileblue.com*](mailto:support@agileblue.com)   
*Phone: (216) 606-9400🚨* 

- [Agent Installation](https://help.agileblue.com/agent-installation?hsLang=en#main-content)

    - [Windows](https://help.agileblue.com/agent-installation?hsLang=en#windows)
    - [Mac](https://help.agileblue.com/agent-installation?hsLang=en#mac)
    - [Linux](https://help.agileblue.com/agent-installation?hsLang=en#linux)
    - [Syslog Collection](https://help.agileblue.com/agent-installation?hsLang=en#syslog-collection)
    - [Agent Management](https://help.agileblue.com/agent-installation?hsLang=en#agent-management)
- [Application Integrations](https://help.agileblue.com/application-integrations?hsLang=en#main-content)

    - [Microsoft Tools](https://help.agileblue.com/application-integrations?hsLang=en#microsoft-tools)
    - [Third-Party EDR](https://help.agileblue.com/application-integrations?hsLang=en#third-party-edr)
    - [Other Security Tools](https://help.agileblue.com/application-integrations?hsLang=en#other-security-tools)
- [Cloud Integrations](https://help.agileblue.com/cloud-integrations?hsLang=en)
- [AgileBlue Features](https://help.agileblue.com/agileblue-features?hsLang=en#main-content)

    - [Portal Management](https://help.agileblue.com/agileblue-features?hsLang=en#portal-management)
    - [Support Systems](https://help.agileblue.com/agileblue-features?hsLang=en#support-systems)
- [Vulnerability Scanning](https://help.agileblue.com/vulnerability-scanning?hsLang=en)
- [Release Notes](https://help.agileblue.com/release-notes?hsLang=en)

[![AgileBlue](https://help.agileblue.com/hs-fs/hubfs/Current-Website-Logo-Replacement.png?width=1321&height=648&name=Current-Website-Logo-Replacement.png "AgileBlue")](http://www.agileblue.com)

AgileBlue Support Phone: 216.606.9400

Copyright © 2026, AgileBlue