Skip to content

Watchmont Capabilities ​

Watchmont is the security management platform behind our Microsoft 365 service. It watches every connected tenant around the clock, alerts us when something looks wrong, lets our engineers act in seconds, and turns all of that into plain English reports you can share with your leadership.

This page is a tour of what we can do for you with it. Nothing here needs your staff to install anything or log in anywhere. Your organisation is connected once through a Microsoft admin consent and Watchmont works from there.

Read-only by default

Everything listed under "what we see" runs with read permissions only. Actions that change something in your tenant (revoking a share, blocking a sign in, resetting a password) require the Read/Write connection tier and an engineer role, and every action is written to an audit log.

Files, sharing and data leaving your business ​

This is the area we get asked about most: who can see your files, how they got access, and what happens when someone shares or takes something they should not.

What we see ​

CapabilityWhat it gives you
Tenant-wide permissions auditEvery SharePoint site, every document library, every permission entry. Flags external users, anonymous links, group grants and inherited access. Exports to CSV and branded PDF.
Shared files sweepItem-level scan of individual files and folders shared outside the organisation, with the exact link type (anonymous, anyone with the link, specific guest).
Sharing links overviewPer-site counts of anonymous, guest and member links so the riskiest sites surface first.
Recent library sharesWho granted what, to whom, and when, sorted newest first. Grants older than a year are flagged as stale.
Files shared to personal email addressesAlerts on files shared to Gmail, Outlook.com, iCloud, Yahoo and similar consumer accounts, naming the file and the recipient address.
Stale external sharesLong-forgotten external shares surface as alerts. Shares whose file or owner no longer exists are cleaned up automatically rather than nagging you.
Mass file deletion detectionHourly sweep of every site and OneDrive recycle bin. A user deleting more than a set number of files in a day raises a high alert naming the user, the sites and example files. Built for the leaver who empties a library on the way out.
Mass download detectionUnusual bulk downloads (the "zip the whole library to a personal laptop" pattern) raise an alert with a sample of the affected files.
Storage drill downPer-site folder sizes, deleted items still holding space, and version history bloat, for tenants running out of SharePoint storage.
SharePoint usage reportSites, files, storage, activity and external sharing per site.

What we can do about it ​

  • Revoke an external share from the alert. When an alert names a file, one click finds it, lists every share on it and removes the external access. No hunting through SharePoint.
  • Remove direct permissions and sharing links on any library, and grant read or read/write access by email, from the SharePoint management page.
  • Manage site membership. Add or remove owners and members of any team site.
  • Restore deleted files from the recycle bin within Microsoft's 93 day window, and apply retention where a client needs it.
  • Lock down unmanaged devices. A ready-made Conditional Access template gives web-only, view-only access to SharePoint from personal PCs, with the SharePoint settings it depends on documented alongside it.
  • Encrypted view-only labels. One-click creation of a sensitivity label that encrypts files so only your staff can open them, with no edit, copy, print, save-as or forward rights. Guests and external addresses get nothing, even if the file leaves the tenant.
  • Purview DLP visibility. See which tenants have no data loss prevention policies at all, and review DLP alerts in the same feed as everything else.
  • Mailbox forwarding and inbox rules. Every rule that forwards or redirects mail outside the organisation, or silently deletes or hides mail, is listed per tenant and can be disabled from the portal.
  • Email trace. Search Exchange message traces for the last ten days to confirm exactly what was sent, to whom, and whether it was delivered.

Identity and access ​

What we see ​

  • Every user with licence, MFA status, admin roles, last successful sign in, mailbox usage and sign in state. Filters for admins without MFA, never signed in, inactive 30/60/90 days, guests, shared mailboxes and more.
  • MFA coverage measured against licensed staff, so the number means what your board thinks it means.
  • MFA red flags. Sign ins where the password was correct but MFA blocked the attempt. This is the strongest early signal of a stolen password or a push-fatigue attack.
  • Cross-client threat correlation. An attacker IP failing MFA at two or more of our clients is surfaced across the estate, so what hits one client protects the rest.
  • Sign in logs with targeted search by user, app or IP, conditional access outcome, device compliance and location.
  • Risky users as flagged by Microsoft Identity Protection.
  • Passkey readiness. Who still relies on SMS or voice MFA ahead of Microsoft's retirement dates, and who would be locked out with no other method.
  • Blast radius. Pick any account and see what a compromise of it could reach: admin roles, groups, SharePoint and OneDrive access, files they have shared externally and mailboxes they can read.
  • Enterprise apps and OAuth consents, including which third-party and AI apps have been granted access to your data and by whom.
  • New users appearing in a tenant, so unexpected accounts are noticed.

What we can do ​

  • Block or enable sign in, disable accounts, reset passwords (with Entra policy checks before we submit), revoke all sessions, reset MFA, issue a Temporary Access Pass.
  • Schedule a block for a set date and time, for example the moment a contract ends.
  • Travel mode. Temporarily exclude a travelling user from location-based Conditional Access policies, with automatic expiry.
  • Manage Conditional Access policies: create from quick-start templates, edit, enforce, set to report-only or disable, and see the full policy in a branded PDF. Security Defaults status is shown alongside, with licence checks before anything is switched off.
  • Manage groups, group owners and members, including mail-enabled and distribution groups.
  • Change usernames and email aliases, keeping mail flowing to the old address.
  • Delegate mailbox access with verification that Exchange actually applied the change.
  • Restore or permanently remove soft-deleted users.
  • Directory role and Azure resource RBAC visibility.

Threat detection and response ​

Alerts ​

  • One feed for Defender XDR, Defender for Cloud Apps, Identity Protection and the Office 365 compliance alert policies, across every client. Microsoft's own portal splits these across several places.
  • Every alert names the affected user, and file alerts name the file and who it was shared with.
  • Known-benign noise (for example Microsoft datacentre sign ins) is suppressed automatically and remains reviewable.
  • Recurring policy alerts can be muted per client, or the source policy in Microsoft can be switched off, from the alert itself.
  • AI triage. An on-demand AI investigation reads related sign ins, live inbox rules, MFA failures and related alerts and returns a verdict, evidence and recommended actions. Recommendations are always executed by a human.
  • Ask Watchmont. Plain-English questions across the estate ("which clients have a global admin without MFA") answered by an AI agent with read-only access.

One-click response ​

  • Contain account. From an alert: block sign in, revoke all sessions, reset the password, disable risky inbox rules, clear mailbox forwarding, optionally disable the user's devices, notify your nominated contacts and raise a ticket. Each step is reported individually and the reversible steps can be released later.
  • Allow or block the sender and resolve in one action for user-reported junk, not-junk and phishing alerts. Tenants can opt in to fully automatic handling of these.
  • Trust an IP from a foreign-location alert so your known office or VPN never trips it again.
  • Notify the customer. Send a templated notice about any alert to your nominated contacts, stamped on the alert so nothing is sent twice.
  • Instant notifications. Per-client opt-in emails the moment a mass deletion, mass download or phishing-simulation compromise is detected, no waiting for a report.
  • Push to HaloPSA to raise a ticket, and see ticket stats in your management report.

Email security ​

  • Domain security. SPF, DKIM and DMARC checked for every domain with a plain-English pass or fail and the DNS fixes we will make.
  • Mailbox rules and transport rules review, with risky rules flagged using the same definition our reports use.
  • Quarantine review and release.
  • Tenant allow and block list management for senders, domains and URLs.
  • Email trace for the last ten days.
  • Mobile devices connected to a mailbox via ActiveSync, with account-only remote wipe.
  • Exchange console for engineers, with read-only cmdlets for diagnostics and admin-gated writes.

Endpoints and devices ​

  • Endpoint security dashboard from Intune and Defender: compliance, enrolment, OS versions, software inventory, vulnerabilities.
  • Compliance and configuration policy creation from templates (update rings, Defender baseline, BitLocker and firewall), plus a full policy editor.
  • Disable device sign in, delete from Intune, retrieve BitLocker recovery keys.
  • Vulnerability management through RoboShadow: critical and high CVEs, patch status, unencrypted devices cross-checked against Intune, end-of-life operating systems, and dark web monitoring of breached staff email addresses.
  • Heimdal endpoint threat prevention, and Atera device cross-reference to find machines missing from either endpoint management or remote support.

Joiners and leavers ​

  • Onboarding wizard. Create a user, clone licences, groups and manager from an existing colleague, and send a welcome email.
  • Offboarding wizard. Convert to shared mailbox, block sign in, revoke sessions, reclaim licences, remove from groups, hand the mailbox and OneDrive to a manager, remove enrolled devices, disable mobile devices. Each step reported.
  • Scheduled sign-in block for a known leaving date, combined with the mass-deletion and mass-download detection above to cover the notice period.

Posture, compliance and governance ​

  • Security assessment with pass, warn and fail findings, one-click fixes where safe, and history over time.
  • CIS Microsoft 365 Foundations Benchmark v7 as a selectable assessment with 160 checks.
  • Secure Score with Microsoft's own global and similar-size benchmarks.
  • Security posture history with 7 and 30 day trends.
  • Policy drift. Baseline policies per client and automatic detection when Conditional Access, Defender or Cloud App policies drift from the agreed standard.
  • Cloud app policies (Defender for Cloud Apps) with reusable templates pushed to every licensed client.
  • AI visibility. Which AI tools your staff sign in to, which have been granted access to company data, Copilot adoption and idle Copilot licences, and shadow AI seen on managed devices.
  • Cloud discovery. Shadow IT seen from managed endpoints, ranked by risk score, with named users and devices.
  • Global Secure Access network visibility where enabled.
  • GDAP access deep links so engineers land in the right customer admin centre with the right delegated rights.

Reporting ​

  • Management Report. A branded PDF for leadership: headline posture, trends, alerts resolved by month, how you compare, phishing results, SharePoint estate, vulnerability updates, service desk tickets, licence waste, invoices, and an AI-written executive overview. Pick which deep-dive sections to include.
  • Onboarding report for a newly connected tenant: shared files, licence waste, risky rules, account hygiene, domain security.
  • More than fifteen scheduled report types: users, licence optimisation, groups, alerts history, sign in logs, mailbox rules, domain analysis, Teams, endpoint security, M365 apps health, Teams Phone, M365 usage, AI usage, phishing simulations, dark web, and the management summary.
  • Scheduled delivery weekly or monthly to any recipients, with a full send history.
  • Every page in the portal exports the same data to CSV and a branded PDF.
  • Fully white-label: your logo, colours and footer on every report.

Licensing and cost ​

  • Licence optimisation. Unused paid seats, licences on disabled accounts, and utilisation per SKU with friendly product names. Free Teams resource accounts are never counted as waste.
  • M365 usage per service and Copilot adoption, straight from Microsoft's usage reports.
  • Teams Phone call reporting with licensed users who never make calls.
  • Renewal dates and price change notifications from our licensing distributor, reconciled against what is billed so nothing is missed or over-charged.

Networks, backup and telephony ​

  • Cisco Meraki and UniFi network posture, VLANs, client VPN users, content filtering and group policies per client.
  • Acronis backup status and recent job outcomes.
  • 3CX call reporting, extensions and DDIs.
  • Azure subscriptions, resource groups, resources and role assignments.
  • Public status page monitoring.

Integrations ​

Connected once, mapped per client, and folded into the same dashboards and reports:

HaloPSA · Giacom · RoboShadow · Heimdal · uSecure · Acronis · Atera · Cisco Meraki · UniFi · 3CX · Ingram Micro · TD SYNNEX · 20i · Status Pages

Platform and trust ​

  • One-click tenant connection by your Global Admin through a Microsoft consent screen, or a single-use invite link we send you. The exact permission list is published in App Permissions.
  • Three connection tiers: report-only, read-only and read/write. You choose how much we can do.
  • Role and client scoping. Every engineer has a role and a list of clients they may see. Departments can be granted specific sections only.
  • Full audit log of every action taken in your tenant, by whom and when.
  • Tenant isolation enforced server-side on every request.
  • Background sync every few minutes, with nightly report pre-warming so pages open instantly.
  • Secrets held in AWS Secrets Manager, data encrypted at rest, point-in-time recovery on every table, and each partner on a dedicated instance. See the Security Model.

Engineer tools ​

DNS lookup · WHOIS · IP geolocation · email header analysis · tenant lookup · Base64 and JWT decoder · password generator · Exchange console

What Watchmont does not do ​

  • It is not an end-user app. Your staff never see it; they receive reports from us.
  • It does not replace Microsoft licences. Some capabilities (sign in logs, Conditional Access, Defender for Cloud Apps, Defender for Endpoint Plan 2, Purview labels) depend on the tenant holding the relevant Microsoft licence, and the portal tells us when one is missing.
  • It never stores your files or email content. Reports carry names, dates and permission entries, not documents.

Internal & partner documentation.