Built for MSPs running Microsoft Intune

Turn Intune into
audit-ready compliance.

CybrOak maps every Intune-managed device to CIS, SOC 2 & ISO 27001 controls and generates the white-label evidence pack your auditors — and your clients — actually want. No agent, just Graph consent.

Start free — no card
No credit cardNo agent — just Graph consentMulti-tenant for MSPs

Sample data — illustrative

app.cybroak.com/dashboard
86Score
CIS v8SOC 2ISO 27001

Endpoints

128

Compliant

81%

Findings

57

BitLocker encryption disabled12 devices
Defender antivirus off5 devices
Stale — no sync in 14 days9 devices
OS end-of-life3 devices

Plugs into the Microsoft stack you already run

Microsoft IntuneMicrosoft GraphEntra IDMicrosoft 365Defender for Endpoint
· Why CybrOak

Intune stores the data. CybrOak makes it make sense.

You already pay for Intune. CybrOak turns its raw telemetry into a prioritized, fixable security posture — without ripping anything out or installing an agent.

Native Intune alone
With CybrOak
A raw device list spread across half a dozen Intune blades
One 0–100 fleet risk score and a ranked list of exactly what's wrong
You hunt for misconfigurations by hand, device by device
We surface them grouped by rule — with the Intune policy path to fix each
No history when a control silently flips off
Daily drift snapshots with alerts the moment posture regresses
Compliance evidence means screenshots at audit time
One-click CIS / SOC 2 / ISO 27001 evidence pack, exported in seconds
· Platform

Compliance evidence your auditor accepts — straight from Intune.

One Graph API connection maps your whole fleet to CIS, SOC 2 & ISO 27001 and produces the white-label evidence packs MSPs hand to clients. No agent, no E5 required.

01

Framework-mapped compliance

Every device finding mapped to CIS Controls v8, SOC 2 & ISO 27001 — with pass/fail status and a coverage score per control. Not a dashboard: actual control evidence.

02

Audit-ready evidence packs

One click → a branded PDF mapping the fleet to CIS / SOC 2 / ISO, plus CSV and full action log. Hand it to an auditor — or white-label it for a client.

03

Multi-tenant MSP console

Every client tenant in one view. Per-client posture, white-label compliance reports, and per-client billing — built for MSPs, not single companies.

04

Findings + CVE exposure

BitLocker, Defender, Firewall, stale, non-compliant, OS end-of-life, active threats, and missing security patches (CVE exposure) — grouped by rule with severity.

05

One-click remediation

Push the fix straight to Intune. Live per-device progress, fully audit-tracked — so the evidence trail writes itself.

06

No agent. No E5 required.

Just read-only Graph consent — whole fleet visible in 60 seconds. Works on Microsoft 365 E3 / Business Premium; no Defender P2 or E5 upgrade needed.

· Only on CybrOak

Evidence your auditor can verify — not just a PDF you exported.

Anyone can edit a PDF. CybrOak evidence packs are tamper-evident: each one carries a registered Evidence ID and a cryptographic fingerprint, so an auditor can independently confirm it's genuine and unaltered — something few Intune tools offer.

  • Unique Evidence ID

    Every pack is registered the moment it's generated.

  • SHA-256 fingerprint

    Prove the file wasn't altered, byte for byte.

  • Public verification

    Auditors confirm authenticity — no login, no account.

  • White-label for clients

    MSPs hand each client a pack they can independently trust.

See a verified example
Example
Authentic CybrOak evidence pack
OrganizationContoso Ltd
GeneratedJun 7, 2026
Devices assessed248
SOC 2 coverage80%

SHA-256 · 03633885cc4a3def9b1e7a2c4d5f6081…

· Workflow

From sign-in to SOC 2 in four steps.

1

Connect your tenant

Sign in with Microsoft. CybrOak requests read-only access to your managed devices via Graph API. Admin consent unlocks the whole fleet — no per-device agent.

2

First sync runs

We pull every Intune-managed device, compute a 0-100 risk score, and run all enabled rules. You see the fleet x-ray inside 60 seconds.

3

Fix what matters

Click Apply Fix on any finding. CybrOak pushes the Intune policy assignment, watches per-device progress, and resolves the finding once compliance confirms.

4

Set and forget

Enable scheduled sync, point a Slack/Teams webhook at the tenant, and let CybrOak do the watching. Weekly digest goes to inboxes; the audit log captures everything.

· See it live

Watch CybrOak x-ray a fleet in real time.

Book a 20-minute live demo and we'll connect a sample Intune tenant, score the fleet, and push a remediation — start to finish — on the call.

Explore the live demo
app.cybroak.com/dashboard
B+

Fleet risk score

82/100

▲ 6 since last week

Devices

248

Findings

17

Critical

3

BitLocker
92%
Defender
78%
Firewall
64%
OS up-to-date
41%
· Security

Trusted with your fleet by design.

You're handing a security tool access to your endpoints — so we built CybrOak to ask for as little as possible, and to be easy to walk away from.

Read-only access

CybrOak requests read-only Microsoft Graph scopes via Entra OAuth. We read your posture — we don't silently change your devices.

No agent, ever

Nothing is installed on a single endpoint. We connect once to your tenant through the Graph API — that's the whole footprint.

Encrypted & tenant-isolated

Access tokens are encrypted at rest, and every customer's data is fully isolated from the next. No shared anything.

Revoke in one click

Pull consent from Microsoft Entra at any time and CybrOak instantly loses all access to your tenant. You stay in control.

· Pricing

Flat monthly pricing. No surprises.

One predictable price per plan — never per seat, never per agent. Start free with up to 25 devices, no card required. Every paid plan includes a 14-day trial.

Free

$0/mo

Up to 25 devices

See your real posture in a minute. No card, no time limit.

Start free
  • All built-in detection rules
  • Fleet risk score
  • Manual sync
  • Watermarked sample evidence pack

Starter

$79/mo

Up to 100 devices

For growing SMBs that want automation and alerting.

Start 14-day trial
  • All built-in detection rules
  • Fleet risk score
  • Scheduled auto-sync
  • Slack & Teams alerts
  • Custom rules
  • 90-day drift history
  • CSV exports
Most popular

Growth

$249/mo

Up to 500 devices

For compliance-minded teams that need the full picture.

Start 14-day trial
  • Everything in Starter
  • One-click remediation
  • Compliance evidence packs
  • Unlimited drift history
  • Priority support

Business

$599/mo

Up to 1,500 devices

For teams that live and die by audits.

Start 14-day trial
  • Everything in Growth
  • All frameworks: CIS · SOC 2 · ISO 27001
  • Audit-ready PDF evidence packs
  • SSO / SAML
  • White-glove onboarding

Running an MSP, or more than 1,500 devices?

Multi-tenant console across all your clients, white-label reports, per-client billing, and per-device volume pricing.

· FAQ

Questions, answered.

No — it sits on top of it. Intune still manages your devices; CybrOak reads that data through the Graph API and turns it into a risk score, prioritized findings, and one-click fixes. You keep everything you already have.

Still have a question?

Hand your auditor the evidence in 60 seconds.

No card, no agent, no E5. Sign in with Microsoft and your CIS / SOC 2 / ISO evidence pack generates itself.