InnovaGroup
An Innova Group productWorking build

Echo

Microsoft 365 security operations. One view.

A security operations dashboard that brings alerts, identity risk, device compliance, email threats and incidents into a single console — instead of the half a dozen admin portals they live in today.

Open the dashboard
The Echo security overview, showing severity counts, a secure score trend, alert distribution and a live incident feed.
Try It Yourself

This is the actual dashboard

Not a video, not a click-through, not a picture. This is Echo itself, running in the page. Move through all eight views, drill into an incident, run a collection, sort and filter a table, export it, switch the theme. Everything works because it is the real build — reading fictional data rather than a live tenant.

The real build, reading fictional data. Nothing here is connected to a live tenant.

The Problem

The answer is in there somewhere

Microsoft 365 does not lack security information. It scatters it. Answering “is anything wrong this morning?” means opening these, one at a time, and holding the answer in your head as you go.

Entra admin centreIntuneDefender portalExchange adminPurviewMicrosoft 365 adminService healthSign-in logs

Echo puts all of it on one screen.

What It Does

Eight views, one morning check

Each view answers one question properly rather than showing a tile of everything. Every table drills down, sorts, filters and exports.

The Echo security overview showing critical, high, risky users, MFA missing and non-compliant counts, a secure score trend, alert distribution and a live incident feed.
Overview

The morning check, on one screen

Secure score against a 30-day trend, open alerts by severity, a live incident feed and sign-ins over the last 24 hours. The header states when the last collection ran and when the next one is due, so nothing on screen is of unknown age.

  • Critical, high, risky users, MFA gaps and non-compliant devices at a glance
  • Secure score trended, not just stated
  • Live incident feed with the source against each entry
  • Signals by source — Entra ID, Defender XDR, Intune, Exchange, service health
The Echo identity view showing MFA registration coverage, risky sign-ins over fourteen days and a list of risky users.
Identity

Who can get in, and how hard it would be

MFA registration, risky sign-ins over 14 days and the users behind them. Identity is where most incidents start, so it gets its own view rather than a tile on someone else's dashboard.

  • MFA coverage across the tenant
  • Risky sign-ins trended over 14 days
  • Risky users listed with what triggered them
  • Conditional access coverage and privileged accounts
The Echo devices view showing compliance state, a breakdown by platform and a list of non-compliant devices.
Devices and email

What they get in on, and what is arriving

Device compliance broken down by platform with the machines that have quietly stopped checking in, alongside quarantine, phishing and impersonation detections from Defender for Office 365.

  • Compliance state by platform
  • Stale and non-compliant devices surfaced, not buried
  • Threat detections over 30 days by source
  • Recent detections listed with what was done about them
The Echo incidents view showing open incidents by severity, new incidents over twelve days and a list of open incidents.
Incidents

Ranked by what it puts at risk

Open incidents by severity and the new ones over 12 days, with an alert centre and the policies generating them — so a noisy rule gets fixed rather than ignored.

  • Correlated incidents, ranked by risk not arrival time
  • New incidents trended so a spike is visible
  • Alert centre with configurable policies
  • Drill into any record, then act on it
The Echo compliance view showing framework coverage, coverage by domain and the top control gaps.
Compliance and service health

What you would fail on today

Control coverage mapped to CIS, ISO 27001, NIST CSF and SOC 2, with the top control gaps ranked — next to live Microsoft 365 status and advisories, because half of what looks like a fault is Microsoft having a bad morning.

  • Framework coverage across CIS, ISO 27001, NIST CSF and SOC 2
  • Coverage by domain, with the gaps ranked
  • Live Microsoft 365 service status and advisories
  • Everything exportable to CSV
On A Phone

The same picture, out of hours

Every view reflows to a phone rather than shrinking. Severity counts stack, tables become cards, and the incident feed stays readable one-handed — because the call that matters rarely arrives while you are at your desk.

  • Every view, not a cut-down mobile subset
  • Severity counts and incidents readable at a glance
  • Tables reflow to cards rather than scrolling sideways
  • Light and dark, following the device
Echo's security overview on a phone, with severity counts stacked as cards.
Echo's incidents view on a phone, with open incidents listed as cards.
How It Works

Nothing it doesn’t need

One view, not another portal

The problem is not that Microsoft lacks data — it is that the data is spread across half a dozen consoles. Echo puts what needs attention on one screen.

Read-only, by design

Echo reads through the Microsoft Graph with least-privilege, read-only consent. It reports on your tenant and cannot reconfigure it — there is no setting in Echo that changes anything in Microsoft 365.

Collection, then evaluation

Echo runs a collection against the tenant, then evaluates every signal against its policy engine. The header always says how old the picture is.

Built by people who run tenants

Shaped by what our own engineers check every morning across the estates we manage, rather than by a feature list assembled from a competitor's website.

Built, not mocked up

The demo above is the software itself — every view, every drill-down, every export. What it reads today is fictional data rather than a live tenant, which is the step still ahead of it.

It’s built. You’ve just used it.

Echo is working software, not a concept — every view above is the real thing. What it reads today is fictional data rather than a live tenant, and we’re talking to a small number of organisations about what it should connect to first. If the problem it solves is one you recognise, we want to hear which part of it matters most to you.