In development. Pilot partners wanted.
Show what broke, who fixed it, and how fast.
Check each client's Microsoft 365 against Essential Eight, SMB1001 and the questions insurers commonly ask. Being built for Australian MSPs.
Concept animation. Six kinds of setting are read from Microsoft 365 and DNS: multi-factor sign-in, admin accounts, legacy sign-in, device patching, macro policy and email DNS records. They are evidence for four of the eight Essential Eight strategies. Two more need a person to attest, and two are outside Mendtrail's view. SMB1001 (Bronze and Silver) and insurer questions are covered in part in the same way.
Every fix leaves a trail.
What changed, when, who fixed it and how long it took. Kept as evidence.
Client A Sample client
- Multi-factor sign-in Changed 19 days ago. Fixed in 1 day by Alex T.
- Legacy sign-in Changed 13 days ago. Fixed in 6 days by Sam R.
- Email DNS records Changed 4 days ago. Open for 4 days Not yet fixed
Read once, mapped across frameworks.
One reading can be evidence for parts of Essential Eight, SMB1001 and the questions insurers commonly ask.
Multi-factor sign-in is evidence for Multi-factor authentication, and for parts of SMB1001 and insurer questions.
Admin accounts are evidence for Restrict administrative privileges, and for parts of SMB1001 and insurer questions.
Legacy sign-in is evidence for Multi-factor authentication, and for parts of SMB1001 and insurer questions.
Device patching is evidence for Patch operating systems, and for parts of SMB1001 and insurer questions.
Macro policy is evidence for Restrict Microsoft Office macros, and for parts of SMB1001 and insurer questions.
Email DNS records are outside Essential Eight. They are evidence for parts of SMB1001 and insurer questions.
Essential Eight
Outside this framework
- Patch applicationsOutside view
- Patch operating systems
- Multi-factor authentication
- Restrict administrative privileges
- Application controlNeeds a person
- Restrict Microsoft Office macros
- User application hardeningOutside view
- Regular backupsNeeds a person
SMB1001
Bronze and Silver
Insurer questions
Evidence for this partNeeds a personOutside Mendtrail's view
A name and a date for what software can't see.
Some things can't be read from Microsoft 365, like a tested backup restore. A named person signs them off, and the sign-off expires.
Sample attestation
Backup restore tested
Jordan P. IT lead
96 days left
Valid until 14 Jan 2027
How it will work.
-
Connect
Read-only access to each client's Microsoft 365.
-
Check
Settings will be read again every day, and changes recorded.
-
Report
Plain-English reports for owners and insurers.
Careful by design.
Read-only
Designed to read a client's Microsoft 365, never to change it.
AWS in Sydney
Where the service is planned to be hosted.
Microsoft sign-in
Staff will sign in with their Microsoft account.
Deleted on request
Designed so an MSP's data can be deleted on request.
Help shape Mendtrail.
We're looking for a few Australian MSPs to pilot it with us.