What this tool does
A read-only scan of your Microsoft 365 tenant that maps your network access landscape, so you can see what changes if you move to Secure Access.
App inventory
Every enterprise app + app registration, with SSO state.
Access patterns
Top apps by sign-in, remote vs on-prem, risky sign-ins.
Zero Trust posture
Conditional Access policies — enabled, disabled, gaps.
Vendor detection
Zscaler, Cisco, Netskope, Prisma… and your coexistence path.
What we read — and why
You sign in with Microsoft and grant read-only access. We never modify anything.
| Permission | Why |
|---|---|
| User.Read | Your name and email — to sign you in |
| Directory.Read.All | Your users and groups |
| Application.Read.All | Your app inventory |
| Policy.Read.All | Your Conditional Access policies |
| AuditLog.Read.All | Your sign-in logs (access patterns) |
| Organization.Read.All | Your tenant name and domains |
These are granted once by your admin when the app is approved (admin consent). AuditLog.Read.All (sign-in logs) additionally requires an Entra ID P1 license — without it, that section simply shows as unavailable.
Sign in to scan your tenant
You'll grant read-only access to directory, apps, policy, sign-in logs and GSA configuration. Nothing is stored — analysis runs in your browser.
Passbeck Discovery is an independent tool and is not affiliated with Microsoft. You sign in with your own Microsoft account and grant read-only access. Your data is analyzed in your browser and never uploaded, retained, or shared — the client-side source is public, so you can verify this yourself.
How to revoke: Entra admin center → Identity → Applications → Enterprise applications → "Passbeck Discovery" → Remove. Or revoke from myaccount.microsoft.com.
No consent? Run it yourself
Regulated buyers can run the same scan locally with their own credentials and upload the result — nothing is ever sent to us.
Run export-gsa-discovery.ps1 in your tenant, then upload the JSON here.