DOCUMENTATION

Getting started with EntraGUARD

From installation to your first audit report, in minutes.

Installation

EntraGUARD is a standalone Windows application. Download the archive from the demo page, unzip it into the folder of your choice, then launch EntraGUARD.exe. No system installation or administrator rights are required.

Requirements: Windows 10/11 (64-bit). The application needs no external database or service to deploy.

Demo mode

On first launch, EntraGUARD offers a demo mode that runs on a fictitious tenant with realistic data. It's the fastest way to explore the application — every module, every framework and every export — without connecting your real environment.

Connect a tenant

To audit your real environment, EntraGUARD automatically provisions a Microsoft Entra connector. From the Connectors :

  1. Create a company (client) and select “Connect Entra ID”.
  2. Sign in once with an administrator account to authorise the provisioning.
  3. EntraGUARD creates the app registration, generates a certificate and requests read-only permissions.
Provisioning is guided and automatic. You don't need to do anything manually in the Azure portal.

Run an audit

From the Audit screen, select the frameworks to assess (Entra ID, AD, Azure, etc.) and start the run. The 283 controls execute in parallel and the score updates in real time. A full audit usually takes a few minutes.

Understand the score

EntraGUARD computes a weighted compliance score. Each control is ranked by criticality:

  • L1 — core control, weighted ×3.
  • L2 — hardening control, weighted ×1.
  • A control in warning state counts for half of its points.

The overall and per-framework scores therefore reflect the real importance of the gaps, not a simple percentage of ticked boxes.

Export a report

From a completed audit, export an executive PDF report (cover page, summary, action priorities, full detail) or additional formats: HTML, Excel, CSV, JSON. Les rapports can be customised with your organisation's logo and contact details.

Permissions

EntraGUARD only requests Microsoft Graph permissions read-only (for example Directory.Read.All, Policy.Read.All, RoleManagement.Read.Directory, SecurityEvents.Read.All). No write permission is ever requested: the audit cannot modify your environment.

Frameworks covered

The audit covers 9 Microsoft frameworks: Entra ID, Active Directory, Azure, Exchange Online, SharePoint, Teams, OneDrive, Defender and Purview. The controls are aligned with the CIS, ANSSI, NIST and ISO 27001.

FAQ

Can the audit modify my tenant?

No. EntraGUARD operates strictly read-only.

Where is audit data stored?

Locally, on your machine. No third-party server processes your security results.

Is the demo time-limited?

The demo gives access to the application on a fictitious tenant. To audit a real environment, a licence is required — see the Pricing.