Editorial author: XRENN Labs s.r.o. · Updated:
A tenant signal is not a complete security picture
Microsoft documents MX and Autodiscover DNS records for connecting domains to its services. Those records support mail delivery and client configuration; they do not reveal the full set of internal identity policies. A leftover record may outlive the configuration it originally served.
What our scanner measures
We combine public identity-discovery responses with domain realm and Autodiscover evidence. An explicit tenant-not-found response is different from an inaccessible source. A stale Outlook CNAME alone does not establish tenant registration. Conflicting observations are retained instead of being turned into a confident conclusion.
What requires authorized internal access
Public discovery does not verify MFA enforcement, Conditional Access, administrator roles, mailbox rules or recovery procedures. We do not attempt passwords, enumerate mailboxes or infer another company's Azure application from a guessed domain prefix. These questions belong to a separately authorized configuration review.
Choose the next step from the evidence
If absence is verified, the module is marked Not Configured and excluded from scoring. If a lookup fails, that is not proof of absence or successful remediation. If a tenant is detected, confirm who administers it and agree on the internal review scope. Do not change Microsoft DNS records solely to make a discovery label appear.
Validate the change at the correct layer
After a domain configuration change, compare a new public scan with the previous observation and verify the intended service in its administration interface. Evidence of internal protections should come from that authorized review, not from a tenant ID or public realm name. Keep both scopes explicit in the final handover.
Editorial method and primary sources
These explanations are checked against the implemented scanner scope and the references below. They distinguish public observations from checks requiring authorized internal access. A content update is not a customer audit or an independently certified review.