VITALS

How it works

Read once, with your permission. Evidence first, then the finding.

A Global Administrator approves a read-only application. Vitals reads the tenant, in memory, for the length of the scan. Every finding in the report is built from what it read — and shows it. Then you can remove the application, and most people do.

How a finding is made

In that order, every time. The prose is written from the finding; the finding is never written from prose. That is what makes it something a technician can check.

Evidence

What Microsoft Graph returned for this tenant — a count, a state, a subscription, a policy. Recorded with the endpoint it came from.

Rule

A defined test over that evidence. Not a model's opinion: a rule with an identity, a threshold and a version, the same for every tenant.

Finding

What the rule concluded, with a severity — and how it knows: observed, calculated, inferred, or not assessed. Where the rule read a proxy rather than the thing itself, the finding says so.

Explanation

Why it matters and what to do, written for the person deciding what happens next. The prose is generated from the finding; the finding is never generated from prose.

HighInferred69 people are licensed for device management, and 14 devices are enrolled

Device management is included in the subscriptions this organisation already holds. Where a device is not enrolled, none of it applies: company data on that machine cannot be protected, wiped if it is lost, or held to any standard.

Evidence

People licensed for device management
69Graph /subscribedSkus
Devices enrolled in Intune
14Graph /deviceManagement/managedDevices
Unaccounted for
55

Recommended fix: Enrol company devices in Intune, starting with laptops that hold or access company data. No additional licence is needed — the entitlement is already there.

A finding from the sample report. Inferred, because device counts against licence counts is a proxy: a person can be licensed and have no company device.

Exactly what Vitals can access

The permissions the consent screen will show, and what each is used for. Every one is a read permission; there is no write permission in the list, so the assessment cannot change a setting, a file or a policy even if told to.

Vitals never reads the contents of your files, emails or Teams messages.

Two of the permissions below would technically allow file contents to be read. The scan does not do it: it reads properties — who can see a file, when it changed, whether it carries a label — and a content hash Microsoft already publishes, for duplicate detection. No permission to read email or Teams messages is requested at all. The Data Processing Agreement commits to this in writing, and the raw data is held in memory for the scan and discarded.

PermissionUsed for
Sites.Read.AllWhich SharePoint sites exist, how big they are, when they were last active, and which have no owner.
Files.Read.AllFile properties in the largest sites: who each file is shared with, whether it carries a label, when it changed, and its content hash for duplicate detection. Not the file itself.
Directory.Read.AllUsers, guests, groups, administrators, licences and the subscriptions they come from.
SensitivityLabel.ReadThe label scheme the tenant has published, so unlabelled can be told from labelled.
DeviceManagementManagedDevices.Read.AllDevices enrolled in Intune, whether they meet the tenant's own policy, and when they last checked in.
Policy.Read.AllConditional Access policies and their state; security defaults; the authentication methods policy; sharing settings.
Reports.Read.AllMicrosoft's own usage and registration reports — who is active, who can complete a multi-factor prompt. Aggregated in the report.
SecurityEvents.Read.AllMicrosoft Secure Score and the controls behind it, so the report can put Microsoft's number beside ours.
SharePointTenantSettings.Read.AllThe tenant-wide sharing defaults: whether anonymous links are allowed, what a Share button offers first, whether links expire.
MailboxSettings.ReadMailbox rules — the ones that forward or delete mail automatically. The rules, never the messages.
AuditLog.Read.AllThirty days of the directory audit log for one question: which accounts acquired a new sign-in method, and who added it.

Application permissions, granted once by a Global Administrator through Microsoft’s own consent screen. A partly-consented scan does not fail: the dimensions it could not read are reported as not assessed and the score is computed from the rest. This list is Schedule 1 of the Data Processing Agreement.

Consent, and taking it back

Pay, accept the agreement, and forward one link to whoever administers your Microsoft 365. They approve; the scan runs; the report arrives by a private link. Nothing is installed and nobody at Vitals signs in to anything.

Revoke it in one click

Open the Microsoft Entra admin centre, go to Enterprise applications, find Innova Group, and delete it. That is the whole procedure. It needs no notice and no permission from us, and the delivery email tells you to do it.

What is kept afterwards

The report, for thirty days, behind a link that then expires. Your name and email for the same period, then removed automatically. Scores, counts and configuration states — nothing that identifies a person or a document — so a second scan can say what changed.

What it will not pretend to know

The report says on its face what it could and could not see. A reader is entitled to the difference between “checked and clean” and “not checked”.

Not assessed is a result

If a signal could not be read — a permission not granted, an endpoint Microsoft only exposes to a signed-in administrator — the check reports that, is left out of the score, and the report says what would unlock it. It is never counted as a pass.

A sample, not an audit

Every site is inventoried. Content is examined in the largest of them, and the report states how many sites that was and what share of your content by volume they hold.

Every finding says how it knows

Observed — read directly from the tenant; the evidence rows are the fact. Calculated — arithmetic over what was read: a difference, a share, a date against a threshold. Inferred — device counts against licence counts, a month of usage in one number, a heuristic for “looks sensitive”; the evidence strongly suggests it and Vitals cannot directly prove it. Not assessed — it could not look. Observed is the norm and carries no label, so everything without one can be trusted as read.