Optional categories are off until you choose. You can change or withdraw your choice using Cookie settings in the footer.

XRENN Labs s.r.o.

Security guides

Microsoft 365 discovery: what public tenant evidence can establish

Microsoft 365 is optional infrastructure. A domain that does not use it should not receive a penalty or a bonus for that choice. The question is what the available evidence actually establishes.

Editorial author: XRENN Labs s.r.o. · Updated:

A tenant signal is not a complete security picture

Microsoft documents MX and Autodiscover DNS records for connecting domains to its services. Those records support mail delivery and client configuration; they do not reveal the full set of internal identity policies. A leftover record may outlive the configuration it originally served.

Sources: Microsoft Learn — Microsoft 365 domain DNS records

What our scanner measures

We combine public identity-discovery responses with domain realm and Autodiscover evidence. An explicit tenant-not-found response is different from an inaccessible source. A stale Outlook CNAME alone does not establish tenant registration. Conflicting observations are retained instead of being turned into a confident conclusion.

What requires authorized internal access

Public discovery does not verify MFA enforcement, Conditional Access, administrator roles, mailbox rules or recovery procedures. We do not attempt passwords, enumerate mailboxes or infer another company's Azure application from a guessed domain prefix. These questions belong to a separately authorized configuration review.

Choose the next step from the evidence

If absence is verified, the module is marked Not Configured and excluded from scoring. If a lookup fails, that is not proof of absence or successful remediation. If a tenant is detected, confirm who administers it and agree on the internal review scope. Do not change Microsoft DNS records solely to make a discovery label appear.

Validate the change at the correct layer

After a domain configuration change, compare a new public scan with the previous observation and verify the intended service in its administration interface. Evidence of internal protections should come from that authorized review, not from a tenant ID or public realm name. Keep both scopes explicit in the final handover.

Editorial method and primary sources

These explanations are checked against the implemented scanner scope and the references below. They distinguish public observations from checks requiring authorized internal access. A content update is not a customer audit or an independently certified review.

Related guides

Expert guarantor

Cybersecurity, NIS2 & AI with Guarantor.

Direct contact with the expert guarantor for ISO 27001 ISMS, new Czech Cyber Security Act (ZKB 264/2025 Sb.) / NIS2 compliance, penetration testing, and world-class AI security.

Whether you are addressing the requirements of the new Czech Cyber Security Act (ZKB 264/2025 Sb.), the European NIS2 directive, ISO/IEC 27001 certification, or securely deploying frontier AI models and offline EdgeGuardian appliances, send your project inquiry to schedule an expert consultation.

Expertise & Diplomas

ISO/IEC 27001:2023 Lead Auditor

Information Security Management (ISMS), audit certification, and security policy implementation.

MBA Cybersecurity Academic Degree

Master of Business Administration – strategic and technical cybersecurity governance.

NIS2 & ZKB 264/2025 Sb. Compliance

Guarantor of compliance with the new Cyber Security Act and EU NIS2 directive.

AI & LLM Security Frontier AI

World-class frontier LLM model security, AI Red Teaming, and EdgeAI defense.