Skip to content
OPS // KITitspentest.sh

E-MON

Monkey365

Open-source PowerShell tool for auditing Microsoft 365, Azure, and Entra ID security configuration — subscriptions, tenants, SharePoint, and Teams.

Official siteBack to catalog

OVERVIEW

Monkey365 (github.com/silverhack/monkey365) is an open-source PowerShell tool for auditing the security configuration of Microsoft 365, Azure, and Microsoft Entra ID. It works as a collector-based module: it connects with a provided identity, pulls configuration for the services in scope — subscriptions, resource groups, SharePoint Online, Teams, Entra ID/Azure AD, and Power Platform — and then evaluates that configuration against a built-in set of security rules loosely modeled on CIS and Microsoft's own hardening guidance.

Because it works purely through documented Microsoft Graph and Azure Resource Manager APIs rather than undocumented endpoints, Monkey365 avoids installing any additional Microsoft modules or navigating multiple admin portals by hand — a single authenticated run produces a consolidated report of misconfigurations across the whole Microsoft cloud stack a client uses.

USE CASES

Practical use cases

  • 01

    Auditing an Azure subscription's resource configuration against CIS-style security benchmarks.

  • 02

    Reviewing Entra ID (Azure AD) tenant settings — conditional access, guest access, MFA enforcement — for gaps.

  • 03

    Assessing SharePoint Online and Teams sharing/external-access settings for oversharing risk.

  • 04

    Producing a consolidated Microsoft 365 security posture report for a client engagement.

QUICK START

During a Microsoft 365 / Azure security assessment, to collect and review tenant, subscription, SharePoint, Teams, and Entra ID configuration against known security baselines.

  1. Install the Monkey365 PowerShell module with `Install-Module -Name Monkey365`.
  2. Confirm the client-provided account has the read-only roles needed for the services in scope (Azure Reader, SharePoint/Teams admin roles, etc.).
  3. Run `Invoke-Monkey365` with the relevant `-Instance` (Microsoft365, Azure, or EntraID) and target tenant/subscription.
  4. Export and review the generated report, filtering for high-severity findings first.
Invoke-Monkey365 — bash
Invoke-Monkey365 -Instance Azure -Analysis -ExportTo HTML

BEFORE YOU RUN IT

What to check before running it

Even read-only collection touches every service in scope — agree with the client beforehand on which subscriptions, tenants, and Microsoft 365 workloads are included.

Graph and Azure Resource Manager calls are recorded in Entra ID sign-in logs and Azure Activity Log under the identity used — expect a noticeable spike during a full run.

The built-in rule set reflects the tool's own baseline, not necessarily the client's actual policy — validate flagged findings against the client's documented security requirements before reporting them.

KEEP EXPLORING

View the whole phase →