CybrOak maps every Intune-managed device to CIS, SOC 2 & ISO 27001 controls and generates the white-label evidence pack your auditors — and your clients — actually want. No agent, just Graph consent.
Sample data — illustrative
Endpoints
128
Compliant
81%
Findings
57
Plugs into the Microsoft stack you already run
You already pay for Intune. CybrOak turns its raw telemetry into a prioritized, fixable security posture — without ripping anything out or installing an agent.
One Graph API connection maps your whole fleet to CIS, SOC 2 & ISO 27001 and produces the white-label evidence packs MSPs hand to clients. No agent, no E5 required.
01
Every device finding mapped to CIS Controls v8, SOC 2 & ISO 27001 — with pass/fail status and a coverage score per control. Not a dashboard: actual control evidence.
02
One click → a branded PDF mapping the fleet to CIS / SOC 2 / ISO, plus CSV and full action log. Hand it to an auditor — or white-label it for a client.
03
Every client tenant in one view. Per-client posture, white-label compliance reports, and per-client billing — built for MSPs, not single companies.
04
BitLocker, Defender, Firewall, stale, non-compliant, OS end-of-life, active threats, and missing security patches (CVE exposure) — grouped by rule with severity.
05
Push the fix straight to Intune. Live per-device progress, fully audit-tracked — so the evidence trail writes itself.
06
Just read-only Graph consent — whole fleet visible in 60 seconds. Works on Microsoft 365 E3 / Business Premium; no Defender P2 or E5 upgrade needed.
Anyone can edit a PDF. CybrOak evidence packs are tamper-evident: each one carries a registered Evidence ID and a cryptographic fingerprint, so an auditor can independently confirm it's genuine and unaltered — something few Intune tools offer.
Unique Evidence ID
Every pack is registered the moment it's generated.
SHA-256 fingerprint
Prove the file wasn't altered, byte for byte.
Public verification
Auditors confirm authenticity — no login, no account.
White-label for clients
MSPs hand each client a pack they can independently trust.
SHA-256 · 03633885cc4a3def9b1e7a2c4d5f6081…
Sign in with Microsoft. CybrOak requests read-only access to your managed devices via Graph API. Admin consent unlocks the whole fleet — no per-device agent.
We pull every Intune-managed device, compute a 0-100 risk score, and run all enabled rules. You see the fleet x-ray inside 60 seconds.
Click Apply Fix on any finding. CybrOak pushes the Intune policy assignment, watches per-device progress, and resolves the finding once compliance confirms.
Enable scheduled sync, point a Slack/Teams webhook at the tenant, and let CybrOak do the watching. Weekly digest goes to inboxes; the audit log captures everything.
Book a 20-minute live demo and we'll connect a sample Intune tenant, score the fleet, and push a remediation — start to finish — on the call.
Fleet risk score
82/100
▲ 6 since last week
Devices
248
Findings
17
Critical
3
You're handing a security tool access to your endpoints — so we built CybrOak to ask for as little as possible, and to be easy to walk away from.
CybrOak requests read-only Microsoft Graph scopes via Entra OAuth. We read your posture — we don't silently change your devices.
Nothing is installed on a single endpoint. We connect once to your tenant through the Graph API — that's the whole footprint.
Access tokens are encrypted at rest, and every customer's data is fully isolated from the next. No shared anything.
Pull consent from Microsoft Entra at any time and CybrOak instantly loses all access to your tenant. You stay in control.
One predictable price per plan — never per seat, never per agent. Start free with up to 25 devices, no card required. Every paid plan includes a 14-day trial.
Free
Up to 25 devices
See your real posture in a minute. No card, no time limit.
Start freeStarter
Up to 100 devices
For growing SMBs that want automation and alerting.
Start 14-day trialGrowth
Up to 500 devices
For compliance-minded teams that need the full picture.
Start 14-day trialBusiness
Up to 1,500 devices
For teams that live and die by audits.
Start 14-day trialRunning an MSP, or more than 1,500 devices?
Multi-tenant console across all your clients, white-label reports, per-client billing, and per-device volume pricing.
No — it sits on top of it. Intune still manages your devices; CybrOak reads that data through the Graph API and turns it into a risk score, prioritized findings, and one-click fixes. You keep everything you already have.
Still have a question?
No card, no agent, no E5. Sign in with Microsoft and your CIS / SOC 2 / ISO evidence pack generates itself.