How it works
Read once, with your permission. Evidence first, then the finding.
A Global Administrator approves a read-only application. Vitals reads the tenant, in memory, for the length of the scan. Every finding in the report is built from what it read — and shows it. Then you can remove the application, and most people do.
How a finding is made
In that order, every time. The prose is written from the finding; the finding is never written from prose. That is what makes it something a technician can check.
Evidence
What Microsoft Graph returned for this tenant — a count, a state, a subscription, a policy. Recorded with the endpoint it came from.
Rule
A defined test over that evidence. Not a model's opinion: a rule with an identity, a threshold and a version, the same for every tenant.
Finding
What the rule concluded, with a severity — and how it knows: observed, calculated, inferred, or not assessed. Where the rule read a proxy rather than the thing itself, the finding says so.
Explanation
Why it matters and what to do, written for the person deciding what happens next. The prose is generated from the finding; the finding is never generated from prose.
HighInferred69 people are licensed for device management, and 14 devices are enrolled
Device management is included in the subscriptions this organisation already holds. Where a device is not enrolled, none of it applies: company data on that machine cannot be protected, wiped if it is lost, or held to any standard.
Evidence
- People licensed for device management
- 69Graph /subscribedSkus
- Devices enrolled in Intune
- 14Graph /deviceManagement/managedDevices
- Unaccounted for
- 55
Recommended fix: Enrol company devices in Intune, starting with laptops that hold or access company data. No additional licence is needed — the entitlement is already there.
A finding from the sample report. Inferred, because device counts against licence counts is a proxy: a person can be licensed and have no company device.
Exactly what Vitals can access
The permissions the consent screen will show, and what each is used for. Every one is a read permission; there is no write permission in the list, so the assessment cannot change a setting, a file or a policy even if told to.
Vitals never reads the contents of your files, emails or Teams messages.
Two of the permissions below would technically allow file contents to be read. The scan does not do it: it reads properties — who can see a file, when it changed, whether it carries a label — and a content hash Microsoft already publishes, for duplicate detection. No permission to read email or Teams messages is requested at all. The Data Processing Agreement commits to this in writing, and the raw data is held in memory for the scan and discarded.
| Permission | Used for |
|---|---|
| Sites.Read.All | Which SharePoint sites exist, how big they are, when they were last active, and which have no owner. |
| Files.Read.All | File properties in the largest sites: who each file is shared with, whether it carries a label, when it changed, and its content hash for duplicate detection. Not the file itself. |
| Directory.Read.All | Users, guests, groups, administrators, licences and the subscriptions they come from. |
| SensitivityLabel.Read | The label scheme the tenant has published, so unlabelled can be told from labelled. |
| DeviceManagementManagedDevices.Read.All | Devices enrolled in Intune, whether they meet the tenant's own policy, and when they last checked in. |
| Policy.Read.All | Conditional Access policies and their state; security defaults; the authentication methods policy; sharing settings. |
| Reports.Read.All | Microsoft's own usage and registration reports — who is active, who can complete a multi-factor prompt. Aggregated in the report. |
| SecurityEvents.Read.All | Microsoft Secure Score and the controls behind it, so the report can put Microsoft's number beside ours. |
| SharePointTenantSettings.Read.All | The tenant-wide sharing defaults: whether anonymous links are allowed, what a Share button offers first, whether links expire. |
| MailboxSettings.Read | Mailbox rules — the ones that forward or delete mail automatically. The rules, never the messages. |
| AuditLog.Read.All | Thirty days of the directory audit log for one question: which accounts acquired a new sign-in method, and who added it. |
Application permissions, granted once by a Global Administrator through Microsoft’s own consent screen. A partly-consented scan does not fail: the dimensions it could not read are reported as not assessed and the score is computed from the rest. This list is Schedule 1 of the Data Processing Agreement.
Consent, and taking it back
Pay, accept the agreement, and forward one link to whoever administers your Microsoft 365. They approve; the scan runs; the report arrives by a private link. Nothing is installed and nobody at Vitals signs in to anything.
Revoke it in one click
Open the Microsoft Entra admin centre, go to Enterprise applications, find Innova Group, and delete it. That is the whole procedure. It needs no notice and no permission from us, and the delivery email tells you to do it.
What is kept afterwards
The report, for thirty days, behind a link that then expires. Your name and email for the same period, then removed automatically. Scores, counts and configuration states — nothing that identifies a person or a document — so a second scan can say what changed.
What it will not pretend to know
The report says on its face what it could and could not see. A reader is entitled to the difference between “checked and clean” and “not checked”.
Not assessed is a result
If a signal could not be read — a permission not granted, an endpoint Microsoft only exposes to a signed-in administrator — the check reports that, is left out of the score, and the report says what would unlock it. It is never counted as a pass.
A sample, not an audit
Every site is inventoried. Content is examined in the largest of them, and the report states how many sites that was and what share of your content by volume they hold.
Every finding says how it knows
Observed — read directly from the tenant; the evidence rows are the fact. Calculated — arithmetic over what was read: a difference, a share, a date against a threshold. Inferred — device counts against licence counts, a month of usage in one number, a heuristic for “looks sensitive”; the evidence strongly suggests it and Vitals cannot directly prove it. Not assessed — it could not look. Observed is the norm and carries no label, so everything without one can be trusted as read.