In development. Pilot partners wanted.

Show what broke, who fixed it, and how fast.

Check each client's Microsoft 365 against Essential Eight, SMB1001 and the questions insurers commonly ask. Being built for Australian MSPs.

Talk to us How it will work

Concept animation. Six kinds of setting are read from Microsoft 365 and DNS: multi-factor sign-in, admin accounts, legacy sign-in, device patching, macro policy and email DNS records. They are evidence for four of the eight Essential Eight strategies. Two more need a person to attest, and two are outside Mendtrail's view. SMB1001 (Bronze and Silver) and insurer questions are covered in part in the same way.

Concept animation. Sample data.

Every fix leaves a trail.

What changed, when, who fixed it and how long it took. Kept as evidence.

Client A Sample client

  1. Multi-factor sign-in Changed 19 days ago. Fixed in 1 day by Alex T.
  2. Legacy sign-in Changed 13 days ago. Fixed in 6 days by Sam R.
  3. Email DNS records Changed 4 days ago. Open for 4 days Not yet fixed
Concept. Sample data.

Read once, mapped across frameworks.

One reading can be evidence for parts of Essential Eight, SMB1001 and the questions insurers commonly ask.

Choose a setting to see what it is evidence for

Multi-factor sign-in is evidence for Multi-factor authentication, and for parts of SMB1001 and insurer questions.

Admin accounts are evidence for Restrict administrative privileges, and for parts of SMB1001 and insurer questions.

Legacy sign-in is evidence for Multi-factor authentication, and for parts of SMB1001 and insurer questions.

Device patching is evidence for Patch operating systems, and for parts of SMB1001 and insurer questions.

Macro policy is evidence for Restrict Microsoft Office macros, and for parts of SMB1001 and insurer questions.

Email DNS records are outside Essential Eight. They are evidence for parts of SMB1001 and insurer questions.

Essential Eight

Outside this framework

  • Patch applicationsOutside view
  • Patch operating systems
  • Multi-factor authentication
  • Restrict administrative privileges
  • Application controlNeeds a person
  • Restrict Microsoft Office macros
  • User application hardeningOutside view
  • Regular backupsNeeds a person

SMB1001

Bronze and Silver

Insurer questions

Evidence for this partNeeds a personOutside Mendtrail's view

Concept. Sample mapping, not the final catalogue.

A name and a date for what software can't see.

Some things can't be read from Microsoft 365, like a tested backup restore. A named person signs them off, and the sign-off expires.

Sample attestation

Backup restore tested

Jordan P. IT lead

96 days left

Valid until 14 Jan 2027

How it will work.

  1. Connect

    Read-only access to each client's Microsoft 365.

  2. Check

    Settings will be read again every day, and changes recorded.

  3. Report

    Plain-English reports for owners and insurers.

Concept illustrations.

Careful by design.

Help shape Mendtrail.

We're looking for a few Australian MSPs to pilot it with us.

Talk to us

hello@mendtrail.com