ISOC Readiness Assessment
Privacy notice
Draft - pending legal review
eGroup Enabling Technologies ("eGroup") operates the ThreatDefender ISOC Readiness Assessment.
What we read
With the permissions of the account that signs in, and only while the assessment runs, we read: license subscriptions; organization name and domain; Microsoft Defender summary counts (device inventory, configuration assessments, vulnerabilities, email outcomes, workload activity); Microsoft Secure Score and its improvement actions; incident counts and metadata for the last 90 days; and, where visible, Microsoft Sentinel and Log Analytics configuration and 30 days of ingestion volume. We do not read email, file or log content.
What we keep
We keep the generated reports, the aggregated assessment results, and the name and sign-in address of the person who ran it, for 90 days, to deliver the report and follow up on it. Access tokens are used only during the run and are not stored. We do not sell this information.
Who sees it
The person who ran the assessment receives the report. eGroup's security team receives a copy to prepare your readout.
Removing access
You can remove the app at any time: Microsoft Entra admin center > Enterprise applications > "ThreatDefender ISOC Readiness Assessment" > Properties > Delete.