Cloud Tenant View

Introduction

The Cloud Tenant view gives you a centralized way to monitor and improve the security posture of your connected Microsoft 365 tenants. The goal of this view is to help administrators:

  • Understand their overall cloud security posture

  • Identify the highest-risk configuration issues

  • Review recommended security configurations

  • Monitor tenant risk trends over time

  • Investigate specific security controls and remediation recommendations


Unlike our existing Cyber Risk views (Devices and Accounts), the Cloud Tenant view displays all security controls, including controls that are properly configured ("Normal"), to provide a complete picture of your security posture across your tenant(s).


This article covers the following topics: 


How Risks Are Determined

Cloud Tenant security controls are based on established security frameworks, including, CIS Controls, Azure Security Benchmarks, and other industry best practices.


The system continuously evaluates each tenant's Recommended Configuration vs. Observed Configuration. The difference between those values creates the risk finding shown to the user.


The focus is configuration security posture management, not just vulnerabilities or malware detection. Many cloud security incidents result from insecure or suboptimal configurations rather than active threats.


Field Effect Tenant Risk Score:

  • Higher score = higher risk

  • Uses Field Effect weighting and risk models

  • Critical findings have greater impact on scoring


Microsoft Secure Score

  • Higher percentage = better security posture

  • Calculated directly by Microsoft

  • Based on Microsoft's control framework


The two scores are not expected to match because:

  • They measure different controls

  • They use different scoring methodologies

  • Field Effect applies weighted scoring and critical-risk floors


A tenant with a single critical issue may maintain a higher-than-expected Field Effect risk score until that issue is addressed.


Access the Cloud Tenant View

The Cloud Tenant view is available from the MDR Portal's Cyber Risk section.

This page is made up of 2 sections:

  1. Cloud Tenant Dashboard

  2. Cloud Tenant List



Partner Navigation

Partners can view this page at both the partner and client views. Use the organization selector to switch between:

  • Client Views: see cloud tenant info for a specific client you manage.

  • Partner View: See all of you clients' cloud tenants simultaneously.

    • There is an additional "organization" column for sorting and filtering.



Dashboard View

The Dashboard provides a high-level summary and data visualizations.



The summary includes the following metrics, along with a comparison of the previous day's metrics for general trending:

  • Total Tenants: number of connected Microsoft 365 tenants being monitored

  • Cloud Providers: only Microsoft 365 is currently supported

  • Total Risks: total number of identified cloud configuration risks across all connected tenants. It compares this number against the previous day for high-level tracking.



Use the Trends and Risk Distribution visualizations to understand how your cloud risk is changing over time. From here, you can:

  • Trends: watch how risk levels (Critical, High, Medium, Normal) change over time.

    • Available visualizations

      • Tenants by risk level over time

      • Risks by risk level over time

      • Overall tenant risk score over time

    • View data for last 7 days or last 4 weeks



Tenant Grid

The tenant grid shows each connected cloud tenant as an individual row. Click the copy icon to copy the tenant ID directly from the grid.

Use the controls above the table to quickly locate specific tenants:

  • Search by tenant ID

  • Filter tenants by Risk level

  • (Partners): filter tenants by organization



The following columns are available in this list:

FieldDescription

Risk Level

Overall severity classification for the tenant

Score

Numeric representation of the tenant’s risk

Tenant ID

Unique identifier for the cloud tenant

Cloud Provider

The platform associated with the tenant

# of Risks

Number of identified risks for that tenant
Status
Integration state:
Connected – actively monitored
Integration Setup – requires configuration


Last Updated

When the tenant data was last refreshed


Tenant Details View

Click a tenant in the grid to open the Details view, which is a full-page view with summary information and a comprehensive list of cloud tenant security controls.



Summary information

The tenant summary includes:

  • Tenant Risk Score

  • Number of Identified Risks

  • Risk breakdown by severity

  • Microsoft Secure Score


Click Cloud Tenant to return to the main view.



Security Controls

This section lists all cloud tenant security controls for Microsoft 365. From here you can:

  • Search controls

  • Filter controls by risk level or category

  • Sort by risk level

  • Review individual configuration controls


The possible risk levels include Critical, High, Medium, Low, and Normal. Normal indicates the control meets the recommended configuration.


Controls are organized into security-related categories such as Identity Protection. Data Protection, and other framework-based categories. A single control may belong to multiple categories.


Use the expand arrows to open controls and see more detail.


Security Control Details

Each control includes the following:

  • Description: what the control evaluates, why it matters, and what action may be required.

  • Observed Configuration: current tenant configuration discovered during evaluation.

  • Recommended Configuration: configuration(s) required to achieve a normal state.

  • Evidence: specific supporting information collected during evaluation, mean to help you understand why a control received its risk rating.



Alternate Mitigations

When you completed mitigation using a tool or technique that cannot be detected by Field Effect MDR, add an alternative mitigation.


Example: Field Effect may detect MFA as missing because it cannot see a third-party MFA solution. In this case, users can add an alternative mitigation


Add an Alternative Mitigation

To add an alternate mitigation:

  1. Navigate to Cyber Risk > Cloud Tenant and select a tenant from the list

  2. Locate the control you have mitigated

  3. Expand the control

  4. Click Add Alternative Mitigation


The Alternate Mitigation form will open. Provide details on how you mitigated the issue, check the confirmation box, and click Confirm.



After saving:

  • The control becomes Normal

  • Risk counts are updated

  • Tenant score is recalculated

  • Microsoft Secure Score is recalculated

  • An Alternative Mitigation badge appears on the control


The platform also records the mitigation details (creator, last update timestamp) and it can be updated in the future.



Exclusions

Some controls may contain Microsoft-managed exclusions, which can only be edited through your Microsoft tenant.

Examples include:

  • User exclusions

  • Group exclusions

  • Location exclusions



When exclusions exist:

  • An Exclusions badge is displayed

  • Users can view details about the excluded objects


This is especially useful for controls such as MFA or Conditional Access policies.



Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article