InquilionGRC gives MSPs a clean way to offer their clients independent Microsoft 365 governance evidence at board level. The MSP keeps the client relationship and the remediation work.
InquilionGRC provides the evidence layer above it.
Boards now treat Microsoft 365 as a governance environment. Identity, access, email, documents, collaboration, device control and information governance are concentrated inside the same platform. Configuration choices translate directly into governance posture.
Each assessment covers sixteen governance domains: fourteen for Microsoft 365 and two further Azure domains where they are in scope. Where a domain cannot be assessed at the client's licence tier or through available interfaces, it is reported as outside assessment scope rather than passed or failed.
The team configuring and managing an environment is rarely well placed to assure it independently. Boards, audit committees and other governance stakeholders are starting to ask for evidence that sits outside the operational team.
Independent assurance is stronger when it is separate from remediation.
This division matters: the board gets independent evidence.
The MSP gets a structured route into remediation, licence improvement and recurring governance support.
All three reports are delivered to the end-client board. The board decides what is acted on, by whom and how, and shares the Compliance Report with the MSP to enable remediation.
InquilionGRC is available to present the Board Governance Report directly to the end-client board, audit committee or agreed governance forum. The MSP may attend joint review sessions where the end client agrees.
The MSP may not rebrand, alter or represent InquilionGRC assurance outputs as its own independent assessment.
Remediation belongs to the MSP. If we fixed what we found, we could no longer independently assure it.
The assessment uses a mixed access model. Where supported, evidence is collected through a dedicated Microsoft Entra application registration with read-only Microsoft Graph and service permissions. Not every assessment domain can be collected through application permissions alone, so some portal-only or compliance-centre checks require a dedicated assessment account.
The baseline role for that account is Global Reader. Where the agreed scope includes Microsoft Purview or compliance checks, the account may also require the Compliance Administrator role in Microsoft Entra ID or relevant Microsoft Purview role groups. Those permissions are privileged, not read-only, and must be time-bound, auditable and used only for the agreed assessment activity.
InquilionGRC does not require use of a Global Administrator account for day-to-day assessment activity. A suitably authorised tenant administrator may still be required during onboarding to approve the application registration permissions and grant the agreed roles. No remediation changes are made as part of the assessment.
The assessment is read-only and does not inspect mailbox contents, document contents, files, Teams messages or message bodies. Configuration, identity, licence, policy and audit metadata may contain personal data and are handled under the agreed engagement terms.
A recurring governance rhythm helps the MSP move from reactive support to structured board-level value. The client sees progress over time, and the MSP has a clearer route into prioritised remediation work, licence improvement and recurring governance support.
No. The MSP keeps the end-client relationship and the remediation work. InquilionGRC provides the independent evidence layer.
No. The point is structural, not personal. Independent assurance is stronger when it is provided separately from the remediation function.
No. The assessment uses an Entra application registration with read-only permissions, supplemented by a dedicated assessment account at Global Reader level. Privileged roles are used only where the agreed scope requires them, on a time-bound basis.
Some Microsoft 365 and Purview checks are not available, complete or practical through app-only collection. For those checks, a dedicated assessment account is used with least-privilege roles. Baseline is Global Reader.
No. The MSP may not rebrand, alter or represent InquilionGRC assurance outputs as its own independent assessment. Joint review sessions are encouraged where the end client agrees.
Yes. The end client owns the report and decides on sharing, subject to the engagement terms.
No. InquilionGRC produces governance assurance evidence. It does not certify compliance and does not provide regulatory approval.
The report is not a criticism of the MSP. Most environments evolve over time: licences change, Microsoft releases new controls, board expectations increase and configuration decisions are often made under budget constraints. In many cases the MSP has already recommended improvements that were deferred. An independent report evidences those points at board level, creates a structured remediation path and gives the board a clearer basis for funding the work. The purpose is not blame. It is to turn informal technical concern into board-visible governance action.
A partner conversation takes thirty minutes and commits you to nothing.
REQUEST INFO