Skip to main content

Dashboard

The Dashboard is the first screen you see after signing in. It sums up your tenant's security posture at a glance: a plain-language assessment, three separate scores, framework compliance rates, a breakdown by area, and the most critical findings.

Executive summary

At the top of the screen there is a short summary written in plain sentences. It pulls together the overall posture, the highest-risk areas, the number of open and critical findings, and any problems on the licensing side. It is written to be read without a technical background, so you can pass it to management as is.

Three scores, three different things

The Dashboard shows three scores side by side, and each measures something different. It matters not to mix them up.

Microsoft Secure Score is Microsoft's own score. It appears both as points (e.g. 609 / 1208) and as a percentage, compared against the industry average. Controlio does not produce this score; it reads it straight from Microsoft.

Exposure Score is Controlio's measure of your attack surface. It is a risk value out of 100, and the higher it climbs the more exposed your environment is. Next to it you see a risk level (low, medium, high) and Controlio's coverage rate.

Compliance Score is the overall compliance percentage that comes out of evaluating the 184 controls. It reduces how many controls passed to a single number.

In short, Secure Score is Microsoft's view, Exposure Score is your attack surface, and Compliance Score is the result of your control scan.

Framework compliance

Below the scores there are four cards: CIS Benchmark, NIST 800-53, ISO 27001 and Microsoft Security Baseline. Each card shows the compliance percentage for that framework and how many controls were met (e.g. 26 / 59). A single scan produces all four. You can find how the mapping works on the Framework Mappings page.

Compliance by area

The controls are summarized category by category in donut charts: identity, device, application, security operations and others. Each donut shows the score and the control count for that area. You spot the weakest area at a glance and start there.

Critical findings

On the right, the highest-severity findings are listed. Each row carries a short description and the related control code (e.g. IAM-01). Click a finding to reach its detail and what you need to do about it. You can find exactly what a control checks and its result criteria in the Control Reference.

Tenant license view

The lower part of the Dashboard shows your tenant's license state. At the top are the organization name, the domains and the license tier; next to them are five numbers: paid licenses, trials, suspended, total users and utilization rate. The utilization bar changes color as it fills and turns red once it passes ninety percent. If a license is suspended or a trial is about to end, a risk alert appears right below.

Under that, the subscriptions are listed as cards. Each card shows the subscription's name, its type (paid, trial, suspended, free) and the assigned/total seats. Click a subscription to open its detail.

Subscription security features

This section shows, one by one, which security features your current licenses unlock. Each feature is marked with a dot: green means on, amber means off, and next to it is the license that provides it. So you see at a glance which protection is available and which needs a higher license. License-related risks, such as a trial ending or a suspended subscription, are also tracked by the GOV controls (GOV-01, GOV-02).

The Dashboard only shows

No value on the Dashboard writes anything to your environment. Every number here is the result of the read-only scan.