Compliance reports
Compliance scenario coverage
See which Conditional Access scenarios your tenant covers, which have gaps, and export evidence for client deliverables.
Create your account, set up a workspace, and get 14 days of Pro - connect tenants, detect drift, and run impact analysis. No credit card required.

Scenario-based, not certification
Policytab evaluates live CA policies from your latest snapshot against a library of security scenarios - administrator MFA, legacy auth block, device compliance, and more.
CIS, NIST, ISO, and HIPAA control references are manual orientation mappings to help MSPs talk to clients about coverage. They are not automated certification against those frameworks.
- Per-tenant scenario gap report with severity
- Hygiene, naming, orphaned groups, and license-gap reports
- CSV exports on Enterprise
- Scheduled compliance digests to your channels on Enterprise
Covered or missing, by severity
Each scenario resolves to a binary state against your snapshot: covered or missing. There is no partial-credit score to argue about - either an enforced policy satisfies the scenario or it does not.
Scenarios are grouped into Critical, Recommended, and Optional buckets so you triage the gaps that matter first. A missing administrator-MFA scenario reads differently than a missing optional hardening control, and the report keeps them separate.
- Binary covered / missing per scenario - no fuzzy scoring
- Critical, Recommended, and Optional severity buckets
- Evaluated against the same snapshot drift and impact analysis use
- Per tenant - one customer's coverage never bleeds into another's report
Framework crosswalk is advisory
The CIS, NIST, ISO, and HIPAA mappings are a crosswalk: they point a covered scenario at the control families it commonly supports, so you can hand a client evidence in language their auditor recognizes.
Policytab does not claim your tenant is compliant with any framework. It tells you which CA scenarios are covered and lets you map that to controls yourself. The honesty is deliberate - a scenario report you can defend beats a compliance badge you cannot.
Compliance scenario coverage
Scenario coverage reports for Entra CA policies. Gap analysis against common security scenarios with manual CIS, NIST, and ISO control orientation.