Home · Business · IT, Data & Security · Cybersecurity

PARTLY

As of 13 August 2026, AI can only partly check your Microsoft 365 security settings.

This still needs a person who signs their name to it.

Can you do it?

15 minutesto a draft.

1 hourto something you’d act on.

Cost, all in£0

Skill neededpower-user

Who has to check ita colleague

What the alternative costsNo priced alternative is provided in the supplied tool data.

If this goes wrong, you can miss a security weakness or apply a setting that disrupts access, email, devices or business operations.

What to actually do

  1. Hand it to a person

    The route this page recommends

    A person who owns the outcome does this end to end, worth it when the failure is dear.

  2. Use a tool built for this

    Second choice
  3. Do it yourself

    The distant third

    A chat interface, power-user skill, and roughly 1 hour until you can act on the result.

    How to actually do it

    1. Open the Microsoft 365 admin and security portals with an administrator or read-only reviewer and list which services are in scope, such as identity, email, devices and data protection.
    2. Export or record the relevant current settings and policies, removing passwords, access tokens, personal data and other secrets before sharing any material.
    3. Write down the organisation's requirements, accepted risks, user groups, devices, third-party connections and any recent security incidents or configuration changes.
    4. Paste the requirements and sanitised evidence into the prompt, keeping each export or screenshot labelled with its Microsoft 365 area and collection date.
    5. Ask the chatbot to produce the evidence table, missing-data list and remediation plan, and reject any finding that is not tied to supplied evidence.
    6. Open the Microsoft 365 area named for each finding and compare the AI's claimed value with the live setting and the current Microsoft documentation.
    7. Ask a colleague with Microsoft 365 security knowledge to confirm the high-risk findings and proposed rollback steps before anyone changes production settings.
    8. Apply approved changes through the normal change process, record the before and after values, and test sign-in, email, devices and affected services.

    Prompt

    Act as a Microsoft 365 security review assistant, not as an administrator. Analyse only the settings, exports, screenshots and policy requirements pasted below. Do not claim to have accessed Microsoft 365, do not invent settings or Microsoft features, and do not recommend changes that are not supported by the supplied evidence. Identify missing data before reaching a conclusion.
    
    Produce:
    1. A table with each supplied setting, its observed value, the security purpose, whether it appears aligned with the stated requirements, and the evidence used.
    2. A separate list of possible weaknesses, with severity described as low, medium or high only where the evidence supports it.
    3. For every possible weakness, explain what could be affected, what additional fact would confirm it, and the exact Microsoft 365 admin area where a colleague should check it.
    4. A remediation plan that starts with low-risk, reversible checks and clearly separates investigation from changes.
    5. A list of assumptions, omissions and findings that require a qualified security professional.
    
    Do not tell me to disable security controls without explaining the risk and rollback. Do not include secrets, access tokens or personal data in your answer. Treat this as a review aid, not a security certification.
    
    Organisation type and requirements:
    [BRIEF DESCRIPTION]
    
    Microsoft 365 settings exports, screenshots or reports:
    [PASTE EVIDENCE HERE]
    
    Known incidents, constraints or recent changes:
    [PASTE DETAILS HERE]

    Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.

What it gets wrong

  • AI cannot see the complete live tenant unless you give an approved tool access, and pasted exports can omit important settings or dependencies.
  • AI cannot know which security baseline, risk tolerance or compliance obligations your organisation has unless you provide them.
  • AI cannot safely distinguish every deliberate exception from an insecure configuration in a complex tenant.
  • AI cannot take responsibility for an outage, account lockout, data exposure or missed control after its recommendation is followed.
  • AI cannot replace a security review that requires evidence from connected identity, endpoint, email and third-party systems.

What caps this at PARTLY: private data access, verification cost and legal accountability.

How we scored this

Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.

AxisScore (0–2)
Output1
Inputs1
Verification1
Liability1
Effort delta1
Total5 / 10

FAQ

Can ChatGPT access my Microsoft 365 security settings?
Not from a normal chat unless you provide an approved integration with the required permissions. It can analyse exports, screenshots and reports that you paste, but it should not be given passwords, tokens or unrestricted administrator access.
Can AI tell me if my Microsoft 365 tenant is secure?
Partly. AI can organise supplied settings and identify apparent gaps against requirements you provide, but it cannot establish that the whole tenant is secure without complete evidence, current documentation and human review.
Is it safe to let AI change my Microsoft 365 security settings?
Do not let a general chatbot make unreviewed production changes. Use it to prepare a change plan, then have an authorised administrator check the setting, rollback method and impact before applying it.
What should I give AI to check Microsoft 365 security?
Give it sanitised settings exports or screenshots, the areas in scope, your security requirements, accepted exceptions and relevant recent changes. Leave out passwords, access tokens and unnecessary personal data, and ask it to identify missing evidence rather than fill gaps by guessing.

Nearby answers

Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.

The newsletter

AI news, new answers and product picks, straight to your inbox.