Other tools tell you what's broken.CYBERWHITE deploys the fix.
One click pushes verified Microsoft Graph policies for Essential 8 and SMB1001. Snapshot first, deploy honestly per Microsoft's actual mode (report-only where Microsoft supports it, active for the rest), verify, and roll back any change with a single click if anything looks off.
Plus baseline SOC 2 M365 policies (MFA + access review). NIST CSF, NIST AI RMF and CIS v8 are covered by assessment + CARS prioritisation + evidence collection.
fixes deployed in one click
Drata, Vanta, Secureframe: 0
controls covered
Essential 8, SMB1001 and SOC 2
rollback on any change
Snapshot taken before every deploy
REPORTS vs REMEDIATES
Most compliance platforms find the gap and stop there. You still have to fix it.
Drata · Vanta · Secureframe
Reporting tools
- Scan your tenant for compliance gaps
- Produce reports for auditors
- Show you which controls are failing
- You implement every fix manually in M365
- No snapshot, no rollback, if a policy breaks something, you debug it
CYBERWHITE AutoFix
Remediation engine
- Scan your tenant for compliance gaps
- Produce reports for auditors
- Show you which controls are failing
- Pushes the fix in one click. Verified Microsoft Graph policy library
- Snapshot before every deploy. One-click rollback. Audit trail of every change.
Four steps. Every action. Every time.
No black box, no surprises. Every AutoFix action runs the same disciplined sequence.
Snapshot
Before changing anything, CYBERWHITE captures the current state of the M365 setting via Graph API. Stored as a rollback record with a timestamp.
Execute
Deploys the policy via Microsoft Graph API. Where Microsoft supports it (e.g. Conditional Access), it starts in report-only so you can review impact before enforcing. Other policy types deploy active and can be rolled back instantly.
Verify
Re-queries Graph API to confirm the policy is applied. Verification result + timestamp written to the audit log. No "fire and forget."
Roll back (anytime)
One click restores the snapshot. If a user complains, if the policy needs tuning, if anything looks off, undo in seconds. Audit log records every roll back too.
The AI does the homework. The engine does the deploy.
AutoFix AI never changes your tenant on its own. The deployment is a deterministic, verified policy library with snapshot and rollback. The AI is the expert beside your engineer.
Explains every control
The risk, and the benefit, in your framework's language.
Writes the steps
Manual where Microsoft has no API, automated where it does, with prerequisites.
Proves it worked
Engineer-grade verification steps to confirm the policy is live in M365.
Tailored to your tenant
Specific to your environment, not generic advice.
AI that earns an engineer's trust
Our AI explains and guides, then gets out of the way. It never touches your tenant, never leaves Australia, and is never trained on your data. Built for IT teams who don't hand production to a chatbot.
Hosted in Sydney. Stays in Australia.
Inference runs on private, enterprise Azure OpenAI in the Australia East (Sydney) region. Your tenant configuration and compliance data are processed in Australia and do not leave it. When your auditor asks where the data goes, the answer is simple.
Private. Not public ChatGPT.
This is our own enterprise Azure OpenAI deployment. Your prompts and your data are never used to train any model, never shared with OpenAI, and never pooled with other customers.
Explainability only. No write access.
The AI reads and reasons, it does not act. It explains each control, the risk, the remediation steps and how to verify the fix. It has no path to deploy or change anything in your tenant. Every change is a deterministic policy your engineer approves.
Used only where it earns its place.
We apply AI per control, only where it adds real value: turning a raw gap into a framework-grade plan your engineer can action in seconds. What the control is, why it matters, the exact steps, and how to confirm it works. Not a gimmick bolted on the side.
The AI advises. Your engineer decides. The deterministic engine executes, with a snapshot and one-click rollback on every change. Your IT team gets an expert co-pilot for the thinking, and an auditable engine for the doing.
56 fixes deployed for you. 151 controls covered.
We map 151 remediation actions across Essential 8 (ML1 and ML2), SMB1001 and SOC 2, and CYBERWHITE deploys 56 of them straight into your Microsoft 365 tenant in one click. The rest we scan, license-check, deep-link, or track as attestations, so nothing slips through. Reporting tools hand you the whole list and walk away.
Essential 8 ML1
remediation actions
MFA, patching, macros, admin privileges, application whitelisting, backups
Essential 8 ML2
remediation actions
PIM, ASR rules, conditional access tightening, audit log retention, AppLocker
SMB1001 (Bronze → Diamond)
remediation actions
Defender Antivirus, Windows Firewall, automatic updates, strong password policy, TLS 1.2+
SOC 2 (M365 mapping)
remediation actions
CC6.1 MFA enforcement + access review baseline
What AutoFix does NOT do
NIST CSF, NIST AI RMF and CIS v8 are covered by assessment, CARS prioritisation and evidence collection, but no AutoFix actions today. Same for organisational controls (policies, training, vendor reviews) which can't be deployed via API. For those, CYBERWHITE collects evidence and tracks completion while your team implements.
Not every control is one-click. We tell you which is which.
Every action in our registry is labelled with one of five categories so you know what to expect before you approve a deployment.
graph_deployable
Real Graph API call. CYBERWHITE writes the policy straight into your tenant in one click. 56 of the highest-impact E8 and SMB1001 controls deploy this way (MFA, ASR rules, firewall, patching). Reporting tools deploy none of them.
license_gated
Deployable IF the tenant has the required M365 license (e.g. E5, P2). Otherwise CYBERWHITE shows the manual instructions instead.
detection_only
We can scan and prove compliance, but there's no policy to deploy (e.g. audit logs that are already on by default).
portal_manual
Must be configured in a specific admin portal (e.g. Defender Security Center). CYBERWHITE provides the deep link + step-by-step guide.
attestation_only
Business-process control. Your team attests yes/no with evidence. CYBERWHITE tracks the attestation and reminds you to renew it.
Why this matters
Other tools claim "automated everything." We're honest: not every control fits an API. Knowing which controls we deploy vs which need manual work makes audit prep predictable.
Built for admin access. Designed for trust.
We're asking for write access to your Microsoft 365 tenant. Here's how we make that safe.
You decide what gets deployed
CYBERWHITE never deploys a policy automatically. Every AutoFix requires you to click deploy on a specific recommendation in the dashboard. Without that click, nothing changes in your tenant.
Connect for assessment. Deploy when you're ready. Roll back if you change your mind.
Report-only first
Every Conditional Access policy CYBERWHITE deploys starts in report-only mode. You review impact for 24-48 hours before enforcing.
Standard Microsoft pattern, nothing exotic.
Pre-flight checks
Before deploying, CYBERWHITE checks for conflicts, existing policies, excluded users, tenant-specific risks. Surfaces them in the approval screen.
No surprise overrides of your existing setup.
Full audit trail
Every snapshot, deploy, verify, and rollback is logged with timestamp, actor, tenant ID, and the exact payload sent to Microsoft Graph.
Export to your SIEM or auditor on request.