product image
product image

TenantWatch

$29/ month
14 day trial

Read-only M365 & Google Workspace posture auditing — now with sign-in watch

TenantWatch audits Microsoft 365 and Google Workspace security settings, read-only, and reports what gets small organisations breached.

Features

  • Configuration checks: accounts without MFA, over-permissioned third-party apps, mailboxes auto-forwarding outside the org, admin sprawl, “anyone with the link” sharing, spoofable domains
  • Sign-in Watch (v0.2): reads 7 days of sign-in activity — legacy auth that SUCCEEDED, admin password-only sign-in, password spray that landed (Critical); impossible travel (High); provider-flagged suspicious sign-ins. No learning period
  • Findings prioritised and self-resolving: fix the setting, it clears next scan
  • Findings to webhook/syslog (Loglight)

Read before you buy. Sign-in watch on M365 needs Entra ID P1/P2 (Business Premium, NOT Basic/Standard); without it those checks stay silent and say why. Google reports no country and no per-event auth strength, so two checks cannot run.

Server requirements

  • Linux x86-64; single static binary or Docker
  • Measured: ~10 MB binary, ~10 MB RAM idle, SQLite file — no database server
  • Minimum host: 1 vCPU, 512 MB RAM, 200 MB disk
  • Dashboard 127.0.0.1:8430; outbound HTTPS to Microsoft Graph / Google APIs with read-only credentials — nothing else

Tiers. Free: 1 tenant (GitHub). Pro and Team: more tenants, alerts, multi-user. 14-day trial.

Single Go binary, no telemetry, offline licensing.

Whop sells paid licences only. Free: github.com/nizartuanku/tenantwatch