How Orbit works
The methodology behind every number, the frameworks it references, the permissions it needs, and what happens to your data.
Orbit is built by Planet IT, a Microsoft Solutions Partner for Security, Modern Work and Infrastructure (Azure).
Access Orbit has
- Read-only, always. A Global Administrator consents once, then Orbit reads your Entra ID, Intune, Teams, SharePoint, Exchange, Purview, Copilot and licensing configuration via Microsoft Graph using read-only, least-privilege permissions (email authentication is checked against your domains' public DNS records). It can never change anything.
- Admins only. Orbit's health-check data is limited to users with an administrator role (Global Admin/Reader, Security Admin/Reader); everyone else is turned away at sign-in.
- Consent is standing, and yours to revoke. Admin consent lets Orbit read your tenant whenever you run a health check, without asking again each time. You can end that access yourself, at any moment, in one step: in the Microsoft Entra admin centre, open Enterprise applications, select Orbit and delete it. Orbit's access stops immediately. No need to contact Planet IT.
Permissions Orbit requests
The read-only Microsoft Graph permissions a Global Administrator consents to during onboarding: least privilege, expanded only as new features need it.
| Permission | Access | What it's used for |
|---|---|---|
Application.Read.All |
Read-only | Read app registrations and their credentials to check for expired or expiring secrets and certificates. |
AuditLog.Read.All |
Read-only | Read sign-in activity and authentication-method registration to flag inactive accounts, MFA gaps and unusual sign-in locations. |
DeviceManagementApps.Read.All |
Read-only | Read Intune mobile application protection (MAM) policies. |
DeviceManagementConfiguration.Read.All |
Read-only | Read Intune device configuration profiles, compliance policies, security baselines, endpoint security and update policies. |
DeviceManagementManagedDevices.Read.All |
Read-only | Read Intune-managed device inventory, compliance, sync and encryption state. |
DeviceManagementServiceConfig.Read.All |
Read-only | Read Intune device enrollment configuration. |
Directory.Read.All |
Read-only | Resolve user, group and role names, and read directory settings such as password protection and consent configuration. |
Organization.Read.All |
Read-only | Read your organization's display name and hybrid status. |
Policy.Read.All |
Read-only | Read Conditional Access policies, authentication methods and consent policies. |
Reports.Read.All |
Read-only | Read Microsoft 365 usage reports (Teams and SharePoint site activity, Exchange mailbox usage and Copilot usage) to flag dormant and externally-shared content. |
SecurityEvents.Read.All |
Read-only | Read your Microsoft Secure Score, shown on the dashboard beside Orbit's own score. |
SensitivityLabels.Read.All |
Read-only | Read the tenant's Microsoft Purview sensitivity labels to check content classification is in place. |
SharePointTenantSettings.Read.All |
Read-only | Read the tenant's SharePoint and OneDrive settings: external sharing, device sync and session controls. |
Your data stays in your tenant
- Your configuration is never stored. Policies, users, devices, settings: everything the reports examine is read live from Microsoft Graph each time and never copied to Orbit's servers. What Orbit does keep is listed in full below.
- Cached in your browser, not ours. To keep the dashboard fast, report content and the small score numbers are cached in your own browser session (a signed cookie and your browser's session storage), on your machine, not our servers.
Exactly what Orbit keeps
Your configuration is read live from Microsoft Graph, held only in memory while your report is built, and never written to disk. The complete list of what Orbit does store about your organisation is below; there is nothing else. All of it lives encrypted in Planet IT's Azure storage, is visible only to your organisation and Planet IT's operators, and is deleted on request when you leave the service.
| What | Exactly what's kept | Why |
|---|---|---|
| Access record | Your sign-in domain, Microsoft tenant ID, your plan status (trial, active or suspended), and first- and last-sign-in timestamps. | To know who may use Orbit and manage your trial or subscription. |
| Daily score history | One snapshot per day of your health-score numbers: the per-hub scores and the overall (e.g. “Intune: 74”), plus your licensed-user count (how many enabled members hold a core suite licence). Never the findings, settings or configuration behind them. | To draw your trend on the History page and show Planet IT your latest overall score. |
| Nothing else | No tenant configuration, no policies, no user lists, no device inventories, no report contents. | Read live from Microsoft Graph on demand, then discarded. |
What Orbit checks
Orbit reads your Microsoft 365 configuration live via Microsoft Graph, read-only (plus public DNS for email authentication), and evaluates roughly 130 individual checks across eight hubs: Entra ID, Intune, Teams, SharePoint, Exchange, Purview, Copilot and Licensing. Each check compares what's actually configured against Microsoft's own best-practice guidance.
Check results
| Result | Meaning | Points earned |
|---|---|---|
| pass | Meets Microsoft's recommendation. | Full points |
| partial | The right control exists but is narrower or weaker than recommended. | Half points |
| absent | The control is missing. | None |
| not licensed | Your licences don't include this feature (e.g. Entra ID P2 risk policies on a Business Premium tenant). Shown for reference and excluded from scoring entirely. You're never penalised for something you can't buy at your tier. | Excluded |
Severity weighting
| Severity | Weight | Typically |
|---|---|---|
| critical | ×4 | Identity takeover and data-exposure controls: MFA coverage, legacy authentication, admin count, encryption, anonymous sharing. |
| high | ×3 | Strong hardening: phishing-resistant methods, risk policies, email authentication, endpoint security policies. |
| medium | ×2 | Good practice and governance: expiry policies, guest governance, update profiles. |
| low | ×1 | Hygiene and housekeeping: naming policies, empty groups, dormant content. |
Effort labels
| Label | Meaning |
|---|---|
| Quick fix | A settings toggle in the admin centre — minutes. |
| Moderate | A policy that needs planning, piloting or a rollout — days. |
| Project | A structural change (e.g. separating admin accounts) — weeks. |
Framework references: CIS & Cyber Essentials
Where a check corresponds to a recognised framework control, it carries a reference chip:
- CIS 5.2.2.3 — the CIS Microsoft 365 Foundations Benchmark v7.0.0. The chip shows the recommendation ID on the same subject as the check.
- CE · User access control — Cyber Essentials. The chip names which of Cyber Essentials' five technical control areas (firewalls, secure configuration, security update management, user access control, malware protection) the check evidences. Around thirty checks carry one: MFA coverage and account hygiene, lockout and password policy, device compliance and baselines, update management, antivirus and firewall policy. Cyber Essentials Plus tests the same five controls with independent verification.
Three honesty rules apply to every chip:
- Nearest control, not equivalence. The chip points to the framework requirement on the same subject; Orbit's exact thresholds aren't always identical, and a passing check is never certification evidence. Cyber Essentials assessment covers devices and scope beyond what a 365 tenant can show.
- Control identifiers only. Orbit references CIS recommendation IDs and CE control-area names; the CIS benchmark itself is CIS's copyrighted work, available free from cisecurity.org, and the Cyber Essentials requirements are published by the NCSC.
- No chip means no honest anchor. Some checks have no counterpart: Intune depth lives in CIS's separate Intune benchmark, licensing/adoption checks are cost governance rather than security controls, and Cyber Essentials doesn't require things like disk encryption or phishing-resistant MFA, so those checks don't claim it. Orbit doesn't stretch a mapping to fill the gap.