ENVIRONMENT INTELLIGENCE
Unified visibility across your technology environment.
Monitor identity, cloud, collaboration, infrastructure, security, licensing, governance, and operational health from one platform.
Governance & Remediation
Tenant-scoped approvals, remediation work items, evidence, notes, and immutable governance audit history.
INCOMING GOVERNANCE DATA
Governance Candidates
Open findings and triggered alerts appear here automatically. Promote a candidate into a governed remediation request when action is required.
| Source | Severity | Title | Category | Observed | Suggested Action |
|---|
WORKFLOW
Remediation Requests
| Status | Risk | Request | Target | Requested | Approval | Execution |
|---|
POLICY EXCEPTIONS
Governance Exceptions
| Status | Exception | Entity | Expires | Requested By |
|---|
REMEDIATION SLA
SLA Status
| Policy | Action | Risk | SLA |
|---|
| Status | Remediation | Risk | Due | SLA |
|---|
APPROVAL POLICY
Approval Rules
| Name | Action | Minimum Risk | DES Admin | Enabled |
|---|
Governance Notes
Governance Audit Trail
ImmutableFULL ENVIRONMENT ASSESSMENT
Overall Assessment
Combine the latest available data from every module licensed for this tenant into a single executive assessment.
EXECUTIVE SUMMARY
Overall Assessment
Included Modules
Executive Recommendations
MONTHLY REPORTING
EnvironmentIQ Reports
Capture a versioned monthly snapshot, edit recommendations, and export HTML, PDF, or DOCX. Refresh Authentication registration and Organizational Mail Stats before capture for the newest MFA and mail-trend data.
Snapshots
Recommendations
SCHEDULED DELIVERY
Monthly Report Schedules
| Name | Day | UTC Hour | Formats | Recipients | Next Run | Status |
|---|
FOCUSED REPORTS
Operational report library
Generate focused, printable reports from the same immutable monthly snapshot.
ENVIRONMENT COMMAND CENTER
Select a tenant
Bird's-eye visibility across Microsoft 365 identity, messaging, collaboration, security, audit, licensing, and platform health.
SECURITY
Priority findings
EMAIL SECURITY
Threat snapshot
IDENTITY
Directory posture
COLLABORATION
Microsoft 365 footprint
PLATFORM HEALTH
Collector status
| Collector | Status | Last success | Duration | Detail |
|---|
UNIFIED AUDIT
Recent cross-workload activity
| Time | Service | Operation | Actor | Object |
|---|
INFRASTRUCTURE OPERATIONS
Infrastructure Monitoring
Availability, lifecycle, recovery readiness, network health, exposure, capacity, configuration drift, and business-service impact across connected infrastructure sources.
COVERAGE
Monitoring capabilities
BUSINESS IMPACT
Service-impact signals
Infrastructure findings
0| Severity | Source | Category | Finding | Entity | Last seen |
|---|
Meraki device availability
0| Status | Device | Model | Type | Firmware | LAN IP | Last reported |
|---|
EXCHANGE ONLINE
Messaging intelligence
Read-only inventory of mailboxes, forwarding, delegation, mail-flow rules, domains, connectors, and 30-day mailbox usage.
EXCHANGE ONLINE
Organizational Mail Stats
Monthly organization mail-flow totals in the same format used by the DE Solutions Monthly Email Monitoring Report.
| Month | Total Mails Sent | Total Mails Received | External Mails Sent | External Mails Received | Internal Mails Sent | Internal Mails Received | Mails to Oneself |
|---|
EnvironmentIQ retains collected monthly totals so the history grows beyond Microsoft message-trace retention.
Mailbox inventory
0| Name | SMTP | Type | Forwarding | Keep copy | Hidden | Archive | Litigation hold |
|---|
Delegations
0| Mailbox | Trustee | Access | Inherited |
|---|
Mail-flow rules
0| Priority | Name | State | Mode |
|---|
Accepted domains
0| Domain | Type | Default |
|---|
Connectors
0| Type | Name | Enabled | Domains | Smart hosts |
|---|
Mailbox usage — last 30 days
0| User | Last activity | Storage | Items | Archive |
|---|
MICROSOFT TEAMS
Teams intelligence
Team inventory, owners, members, guests, channels, and 30-day activity.
Teams
0| Team | Visibility | Owners | Members | Guests | Created |
|---|
Channels
0| Team | Channel | Type | Created |
|---|
30-day team activity
0| Team | Last activity | Active users | Active channels | Messages | Meetings |
|---|
ONEDRIVE FOR BUSINESS
OneDrive intelligence
30-day account activity, storage utilization, file counts, and inactive/deleted-account visibility.
OneDrive accounts
0| User | Last activity | Files | Active files | Storage | Allocated | Deleted |
|---|
SECURITY & IDENTITY RISK
Security intelligence
Identity Protection risk, failed sign-ins, cross-workload governance findings, and prioritized remediation signals.
Findings
0| Severity | Category | Finding | Status | Last seen |
|---|
Risky users
0| User | Risk | State | Detail | Updated |
|---|
Risk detections
0| Detected | User | Type | Risk | State | IP |
|---|
AUDIT & CHANGE HISTORY
Tenant activity
Seven-day Entra directory audit history and sign-in activity with failure, Conditional Access, and risk context.
Directory audit
0| Time | Activity | Category | Actor | Result |
|---|
Sign-ins
0| Time | User | Application | IP | Client | CA | Result |
|---|
EMAIL SECURITY
Threat protection intelligence
Spam, malware, phishing, spoof detections, Microsoft Defender alerts, and incidents.
Threat detections — last 10 days
0| Time | Threat | Subject | Sender | Recipient | Verdict | Action |
|---|
Clean / allowed activity
0Recent messages returned by the Microsoft security report that were not classified as spam, malware, phishing, spoof, or bulk. These are informational only and do not generate findings.
| Time | Subject | Sender | Recipient | Verdict | Action |
|---|
Microsoft Defender alerts
0| Created | Severity | Alert | Source | Status | Incident |
|---|
Microsoft Defender incidents
0| Created | Severity | Incident | Status | Classification |
|---|
MICROSOFT PURVIEW
Unified Audit
Cross-workload Microsoft 365 audit activity across Exchange, SharePoint, OneDrive, Teams, Entra, and related services.
If Microsoft 365 auditing is disabled or unavailable for the tenant, EnvironmentIQ reports that as a capability state instead of a platform error.
Audit searches
0Purview Audit Search is asynchronous. Start a search, then refresh results after Microsoft finishes processing it.
| Search | Window | Status | Records | Last checked |
|---|
Activity by service
0| Service | Records |
|---|
Recent unified audit activity
0| Time | Service | Operation | Actor | IP | Object |
|---|
Scheduling, alerts & notifications
Configure recurring EnvironmentIQ operations and tenant-specific notification recipients.
Notification recipients
| Enabled | Added |
|---|
ALERTING
Alert Policy Templates
Create tenant-specific alert policies from reusable EnvironmentIQ templates.
Deployed Alert Policies
0| Status | Severity | Policy | Triggered | Category | Settings | Last triggered |
|---|
Alert History
0| Time | Severity | Policy | Entity | Status | Notification | Detail |
|---|
Schedules
| Name | Type | Collectors | Frequency | Next run | Last status | Enabled |
|---|
Schedule run history
| Started | Schedule | Type | Status | Completed | Detail |
|---|
Notification history
| Created | Severity | Source | Title | Status | Error |
|---|
Users
0| Name | UPN | Type | Status | Licenses | Created |
|---|
Groups
0| Name | Mail enabled | Security | Types |
|---|
Directory roles
0| Role | Members | Description |
|---|
Enterprise applications
0| Name | App ID | Type | Enabled | Assignment required |
|---|
Licensing
0| SKU | Purchased | Assigned | Available | Warnings |
|---|
Collectors
| Collector | Status | Last success | Duration | Failures | Error |
|---|
Recent jobs
| Collector | Status | Started | Records | Error |
|---|
Selected tenant agents
Create a short-lived enrollment token for the currently selected tenant, then use it to enroll a Windows / AD agent.
Enrollment tokens expire after 30 minutes and can only be used once.
| Name | Host | Domain | Status | Last seen | Actions |
|---|
DES ADMINISTRATION
User Tenant Assignments
Assign a user principal name to a default customer tenant. These server-side assignments support guest users and override the sign-in tenant for non-DES users.
| User | Tenant | Object ID | Default | Created |
|---|
DES ADMINISTRATION
Tenant Module Licensing
Select a tenant, then choose the modules included in that tenant’s EnvironmentIQ access.
Enabled Modules
Unlicensed modules remain visible in the tenant sidebar, display “(unlicensed),” and cannot be opened.
Select a tenant to manage modules.
OWASP TOP 10
Website Security
Run a safe, unauthenticated assessment of a public website you are authorized to test. EnvironmentIQ does not submit forms, inject payloads, authenticate, fuzz, or exploit targets.
New Assessment
Public HTTP and HTTPS targets on standard ports only. Private, loopback, link-local, reserved, and credential-bearing URLs are blocked.
No assessment is running.
Latest Findings
No website assessment has been completed for this tenant.
| Severity | OWASP Category | Finding | Evidence | Recommended Action |
|---|
Scheduled Assessments
Queued and processed by the controlled EnvironmentIQ scheduler.
| Name | Target | Frequency | Next Run | Last Status |
|---|
Assessment History
The most recent 50 tenant-scoped assessments, including queue progress and changes from the prior run.
| Started | Target | Status | Progress | HTTP | Findings | New | Resolved | Configuration Changes | Requested By |
|---|
OWASP Coverage
A clean safe scan is not proof that an application is vulnerability-free. Limited and Not tested categories require authorized authenticated testing, code review, architecture review, or operational evidence.
| Category | Coverage | What This Means |
|---|
Loading saved Google Workspace data…
Google Workspace
Read-only directory, organizational-unit, group, and administrator visibility using a tenant-scoped Google service account with Domain-Wide Delegation.
CONNECTION
Google Workspace Service Account
The service-account JSON credential is encrypted at rest and the private key is never returned to the browser.
Create a Google Cloud service account, enable Domain-Wide Delegation, authorize the required read-only scopes, then save the credential and delegated administrator.
ORGANIZATION MAIL
Gmail Organization Mail Statistics
Monthly organization-level Gmail activity.
| Month | Sent | Received | Exchanged | Inbound Delivered | Coverage |
|---|
No Google Workspace mail statistics collected yet.
LICENSING
Google Workspace License Assignments
Assigned Google Workspace SKUs by user.
| SKU | SKU ID | Assigned |
|---|
AUDIT
Login & Admin Activity — Last 30 Days
| Time | Application | Event | Actor | IP Address | Details |
|---|
DIRECTORY
Users
| User | Org Unit | Status | Admin | 2SV Enrolled | 2SV Enforced | Last Login |
|---|
COLLABORATION
Groups
| Group | Name | Direct Members | Admin Created | Description |
|---|
ORGANIZATION
Organizational Units
| Path | Name | Parent | Block Inheritance | Description |
|---|
ADMINISTRATION
Admin Roles
| Role | Super Admin | System Role | Description |
|---|
ADMINISTRATION
Role Assignments
Role and assignee IDs are resolved to collected Google Workspace names where available.
| Role | Assigned To | Scope | Org Unit |
|---|
Loading saved Google Workspace data…
Google Gmail Security
Mailbox forwarding, filter forwarding, delegates, legacy protocol exposure, findings, and collector status.
COLLECTOR
Gmail Security Status
Collector status will appear after collection.
FORWARDING
Automatic Forwarding
| User | Enabled | Forward To | Disposition | External |
|---|
FILTERS
Filter-Based Forwarding
| User | Forward To | External | Criteria |
|---|
DELEGATION
Mailbox Delegates
| Mailbox | Delegate | Verification | External |
|---|
LEGACY ACCESS
POP / IMAP
| User | POP | POP Disposition | IMAP | Auto Expunge | Expunge Behavior |
|---|
FINDINGS
Gmail Security Findings
| Severity | Finding | Entity | Last Seen |
|---|
Loading saved Google Workspace data…
Google Drive Security
Public and external sharing exposure, permission roles, findings, recent Drive activity, and collector status.
COLLECTOR
Drive Security Status
Collector status will appear after collection.
SHARING
External Sharing Exposure
Drive metadata only; EnvironmentIQ does not collect file contents.
| File | Owner | Exposure | Target | Role | Modified |
|---|
ACTIVITY
Recent Drive Activity
| Time | Event | Actor | IP Address | Details |
|---|
FINDINGS
Drive Security Findings
| Severity | Finding | Entity | Last Seen |
|---|
Windows / Active Directory
Tenant-scoped agent health, Windows inventory, Active Directory health observations, and agent findings.
COLLECTION SCHEDULE
Assessment Frequency Sets
Change the cadence for each assessment group. Checks inside a group share one frequency.
Defaults: Core Health hourly · Extended AD every 12 hours · Full Inventory daily.
AGENT STATUS
Windows / AD Agents
| Status | Agent | Host | Domain | Version | Last Seen | Operating System | Actions |
|---|
ACTIVE DIRECTORY
Open Findings
| Severity | Finding | Entity | Last Seen |
|---|
Microsoft Azure
Read-only Azure subscription, resource, Advisor, Resource Health and Azure Monitor alert-rule visibility.
FINOPS
Month-to-Date Cost by Service
Cost data is capability-aware and does not block the rest of Azure collection.
Azure cost status will appear after collection.
| Service | Cost | Currency | Subscription |
|---|
ACCESS READINESS
Azure Connection
Assign the DES EnvironmentIQ enterprise application Azure RBAC Reader access at the management group, subscription, or resource-group scope you want EnvironmentIQ to monitor. Monitoring Reader can be added later for broader monitoring-data access.
SUBSCRIPTIONS
Accessible Azure Subscriptions
| Subscription | Subscription ID | State | Authorization | Collected |
|---|
RESOURCE INVENTORY
Azure Resources
| Name | Type | Resource Group | Region | Subscription |
|---|
SECURITY
Defender for Cloud Findings
| Severity | Recommendation | Status | Resource | Remediation |
|---|
GOVERNANCE
Azure Policy Noncompliance
Grouped by policy assignment and affected scope so built-in initiatives do not appear as repetitive duplicate rows.
| Policy / Initiative | Scope / Resource | Type | Resource Group | Noncompliant Controls |
|---|
ENVIRONMENTIQ
Azure Findings
Normalized Azure security, policy, Advisor, tagging and exposure findings also flow into Governance Candidates.
| Severity | Category | Finding | Resource |
|---|
AZURE ADVISOR
Recommendations
| Impact | Category | Problem | Solution | Resource |
|---|
AZURE MONITOR
Alert Rules
| Name | Type | Enabled | Severity | Resource Group |
|---|
RESOURCE HEALTH
Availability
| State | Resource | Reason | Summary |
|---|
Cisco Meraki
Tenant-scoped Meraki inventory, health, licensing, WAN telemetry, wireless, switch-port and governance visibility.
CONNECTION
Meraki Dashboard API
The API key is encrypted at rest with Windows DPAPI and is never returned to the browser.
After a key is saved, leave this field blank. EnvironmentIQ reuses the encrypted stored credential automatically.
Configure the API key, test access, and select the organization to monitor.
LICENSING & RENEWALS
Organization Licensing
Licensing, deployed hardware reconciliation, renewal quantities, expiration status, and lifecycle details aligned to the DES Meraki Health Assessment.
License Counts & Renewal
| License Family | Licensed | Recommended Renewal | Expiration | Days Remaining | Priority |
|---|
Hardware Inventory by Model
| Model | Qty | Product Type | SKU | Assigned | Unassigned | EOX Status | End of Sale | End of Support |
|---|
Renewal Recommendations
| Priority | Item | Current State | Renewal / Action | Due | Business Impact |
|---|
DEVICE HEALTH
Meraki Devices
| Status | Name | Model | Type | Network | LAN IP | Firmware | Last Reported |
|---|
WIRELESS
SSIDs
| SSID | Enabled | Auth | Encryption | Network |
|---|
SWITCHING
Switch Ports
| Switch | Port | Name | Enabled | Type | VLAN | PoE | STP Guard |
|---|
ENVIRONMENTIQ
Meraki Findings
Open Meraki availability, licensing, lifecycle, WAN and wireless findings also feed Governance Candidates.
| Severity | Category | Finding | Target |
|---|
DES ADMINISTRATOR
Automations
Run an action for the selected tenant. Review the preview before executing. These actions run on demand.
Review action
Preview expires after 10 minutes.
Run history
Latest 100 runs for this tenant. If a result is Unknown or remains Running after an interruption, check the provider before creating another change.
| Created | Action | Administrator | Status | Details |
|---|
