Read-only · no data leaves your browser

See your network access landscape — before you change it.

Sign in with Microsoft and scan your own tenant: application inventory, access patterns, Zero Trust posture, incumbent-vendor detection, and your recommended Global Secure Access coexistence path. Plus paste a VPN or firewall export to surface the legacy apps Graph can't see.

What this tool does

A read-only scan of your Microsoft 365 tenant that maps your network access landscape, so you can see what changes if you move to Secure Access.

App inventory

Every enterprise app + app registration, with SSO state.

Access patterns

Top apps by sign-in, remote vs on-prem, risky sign-ins.

Zero Trust posture

Conditional Access policies — enabled, disabled, gaps.

Vendor detection

Zscaler, Cisco, Netskope, Prisma… and your coexistence path.

What we read — and why

You sign in with Microsoft and grant read-only access. We never modify anything.

PermissionWhy
User.ReadYour name and email — to sign you in
Directory.Read.AllYour users and groups
Application.Read.AllYour app inventory
Policy.Read.AllYour Conditional Access policies
AuditLog.Read.AllYour sign-in logs (access patterns)
Organization.Read.AllYour tenant name and domains

These are granted once by your admin when the app is approved (admin consent). AuditLog.Read.All (sign-in logs) additionally requires an Entra ID P1 license — without it, that section simply shows as unavailable.

Read-only Runs in your browser Nothing stored Revocable anytime

Sign in to scan your tenant

You'll grant read-only access to directory, apps, policy, sign-in logs and GSA configuration. Nothing is stored — analysis runs in your browser.

Passbeck Discovery is an independent tool and is not affiliated with Microsoft. You sign in with your own Microsoft account and grant read-only access. Your data is analyzed in your browser and never uploaded, retained, or shared — the client-side source is public, so you can verify this yourself.

How to revoke: Entra admin center → Identity → Applications → Enterprise applications → "Passbeck Discovery" → Remove. Or revoke from myaccount.microsoft.com.

No consent? Run it yourself

Regulated buyers can run the same scan locally with their own credentials and upload the result — nothing is ever sent to us.

Download PowerShell script

Run export-gsa-discovery.ps1 in your tenant, then upload the JSON here.