Microsoft + ClaudeOne partner for the cloud you run and the AI you put on top of it.
Avalon Web ServicesMicrosoft · Claude · Security

Six consoles, and nobody with an hour a day to check them

Microsoft 365 security is not one screen. Identity, devices, licences, spend, audit records and threat alerts each live in a different portal, with different retention and different owners. Nobody logs into all six every day, so problems get found late — often after the evidence has expired, because sign-in logs on the free tier of Entra ID are kept for seven days. The answer is not another security product. It is one read-only view that reads all of them on a schedule and tells a business owner what changed. Avalon CloudSec does that, and deliberately nothing else.

Written by
Arif Ali Mughal
Published
Reading time
5 min

01 / 07

Why is Microsoft 365 security spread across so many portals?

Because Microsoft built it that way, and says so plainly. Its own guidance calls the Defender portal the home for security monitoring and then, in the same sentence, adds that you need to access various portals for certain specialized tasks.

For an ordinary business the working set is six: the Microsoft 365 admin center, the Microsoft Entra admin center, the Microsoft Intune admin center, the Microsoft Defender portal, the Microsoft Purview portal and the Azure portal. Each is well built. Each is the only place a particular answer lives.

That is not a complaint about Microsoft. It is a description of the job it creates — a job that, in a company of thirty or three hundred people, usually lands on one person who already has another one.

02 / 07

What each portal is the only place to answer

Read the right-hand column before the middle one. The question is rarely where do I look — someone can always find the screen. The question is whether the answer is still there when they get to it.

PortalThe question it is the only place to answerHow far back you can look
Microsoft 365 admin centerWas that outage ours or Microsoft's?30 days of resolved service-health history.
Microsoft Entra admin centerWho signed in, from where, and who holds admin rights?7 days of sign-in and audit logs on the free tier; 30 days with Entra ID P1 or P2. The premium tier buys detail, not time.
Microsoft Intune admin centerIs that laptop actually meeting policy?Current state only, and a change can take up to 24 hours to appear even when the device is online.
Microsoft Defender portalWas there an alert, and did anyone act on it?180 days for alerts and incidents; 30 days for the raw data behind them.
Microsoft Purview portalWhat happened to that file, mailbox or record?180 days of audit records on the standard tier; one year on the premium tier for Entra ID, Exchange, OneDrive and SharePoint.
Azure portalWhat are we spending, and on what?13 months on screen. The data is kept for at least seven years, but anything older comes out through an API, not the portal.

03 / 07

The evidence expires before anyone gets round to looking

This is the part that turns an irritation into a risk. No two of those portals keep their evidence for the same length of time, and the shortest window belongs to the question people ask most often.

On the free tier of Microsoft Entra ID, sign-in and audit logs are kept for seven days. Not seven days of alerts — seven days of the record of who signed in at all. If somebody asks in week three what happened in week one, the honest answer is that nobody can know any more.

Microsoft is explicit that this cannot be repaired afterwards: Log retention changes aren't retroactive... Data that has already expired can't be recovered unless it was previously archived. Buying a licence in October does not give you September.

A pattern runs through the whole set, and this is our reading rather than something Microsoft states anywhere: the verdict outlives the evidence. Defender keeps the alert for 180 days and the data that produced it for 30. You can still see that something was decided long after you can check why.

HOW FAR BACK EACH SIGNAL SURVIVES 0 7 30 90 180 DAYS ENTRA SIGN-IN + AUDIT — FREE 7 days — the whole record ENTRA SIGN-IN + AUDIT — P1/P2 30 days — P2 buys no more time DEFENDER HUNTING DATA 30 days SERVICE HEALTH HISTORY 30 days DEFENDER ALERTS + INCIDENTS 180 days — the verdict, not the evidence PURVIEW AUDIT — STANDARD 180 days Seven days is the entire window on the free tier, and Microsoft states that retention changes are not retroactive. Read from Microsoft Learn on 12 September 2026. Azure cost data is left off: the portal shows 13 months, well past this scale.
Six portals in one tenant, six different answers to how far back you can look. The bar carrying the question people ask most often — who signed in, and was that normal — is the one you can barely see. Turning on a licence later does not lengthen it retrospectively.

04 / 07

What actually goes wrong

Nothing dramatic, which is exactly why it is hard to get budget for. Someone leaves and keeps a licence and a mailbox for four months. An admin role is handed out for one Tuesday afternoon and never taken back. A laptop drifts out of policy and that particular screen goes unopened. A consent prompt gets clicked and an outside application now reads company mail.

None of these is an incident. Each one is found late, or found by accident — and by the time anyone goes looking, the log that would have explained it has already rolled off.

05 / 07

What one read-only view changes

This is what Avalon CloudSec is for, and it is worth being exact about it.

It connects to your Microsoft 365 tenant with read permissions and nothing else. Every permission it requests is a read permission, and on the Azure side it uses Microsoft's own Reader roles. It cannot change a setting, create a user or delete anything, because it was never granted the ability to.

It reads across those portals every fifteen minutes and puts the answers on one page: who holds admin rights, which accounts are dormant, which licences are assigned to people who have gone, which devices fall outside policy, what outside applications have been allowed to read, and what your Azure spend is doing. Heavier inventories run on a slower cycle, between four and twenty-four hours.

Setting it up is an admin consent flow of roughly thirty minutes. Nothing is installed on any device, and the first data lands the same day.

06 / 07

What it does not do

It cannot fix anything. Every change is still made by your own team, in Microsoft's own screens. The view tells you what to look at and where; it does not reach in.

It is not a SIEM and it is not antivirus, and it does not respond to an incident on your behalf.

Some of what it reports depends on what you already pay Microsoft for: sign-in activity and dormancy need Entra ID P1, and identity-risk detail needs P2. Where the licence is missing, the module says so by name instead of showing you a blank.

One caveat matters more than the others. The count of administrators is a floor, not a total. Microsoft's API returns active role assignments, so anyone who can elevate into an admin role on demand does not appear in it. If your organisation uses that feature, the real number is higher than the screen says — and we would rather tell you that than let you read the number as complete.

07 / 07

Where to start

If you want to know what your own tenant looks like across all six, email support@awservices.org and ask for a read-only review. That is the entire ask: nothing to install, nothing to change, and you keep whatever it finds.

Microsoft, Microsoft 365, Azure, Entra, Intune, Defender and Purview are trademarks of the Microsoft group of companies. Avalon CloudSec is an independent service and is not endorsed by Microsoft.

Primary sources

Want us to run this for you?

Start here

Tell us what'skeeping you upat night.

Most engagements start with a Cloud Health Check — one week, full audit, top-10 findings, 90-day roadmap. Many turn into a longer engagement; either way, you walk away with a prioritized plan you own.