Free community tool · Public beta
Run AdminSecOps in your browser
Explore a Microsoft security assessment using fictional sample environments or analyse a compatible evidence package locally in your browser. Your evidence is processed on this device and is not uploaded to palanikumar.net.
Current scope
One assessment across the Microsoft environment
The beta contains 99 controls across Microsoft Entra ID, Microsoft 365, Exchange Online, Intune, Azure, Active Directory, AD CS, Group Policy and the local Windows host. Missing, failed or unauthorised evidence is reported as not assessed rather than passed.
The browser version runs the same assessment engine as the local application. There is no server component that receives your evidence.
- Read-only collectionCollection wrappers allow approved read operations only.
- Processing on your deviceIn the browser version, evidence is read and evaluated in the page itself.
- No telemetryNo analytics, cookies, remote logging or automatic report upload.
- Evidence integritySHA-256 manifests detect modified evidence packages.
- Actionable outputFindings include remediation, rollback and validation guidance.
In the browser
Start with a fictional sample
Contoso and Fabrikam are invented organisations used to demonstrate the product. Nothing in them describes a real tenant. Open a sample to see findings, priorities and remediation guidance before you consider your own environment.
- Explore Contoso — a fictional hybrid organisation across Microsoft 365, Entra ID, Intune, Azure and Active Directory.
- Explore Fabrikam — a fictional on-premises organisation: Active Directory, AD CS, Group Policy and Windows.
- Import an evidence package — a .zip produced by the AdminSecOps Collector, read in your browser only.
- Export a report — JSON or HTML, saved from the page to your own device.
Privacy and safety
Privacy and safety guidance
Evidence is processed locally in your browser. Do not use a shared or untrusted computer. Assessment evidence can contain account identifiers, security settings and weaknesses.
The browser application is delivered as static files. It has no server API, and its content security policy prevents the page from making network connections at all. Assessments stay in the memory of the browser tab and disappear when you close or refresh it, unless you explicitly choose to keep them on the device. That choice can be reversed at any time with Delete local data in the application.
There are no analytics, no telemetry, no cookies and no remote logging. Reports you export are generated in the page and saved by your own browser.
Evidence and reports can reveal account identifiers, security configuration and weaknesses. Store them in an access-controlled location and delete them when they are no longer needed. Never attach live evidence, reports, logs, screenshots, credentials, tokens or tenant identifiers to email, a public forum or an issue tracker.
AdminSecOps is a point-in-time configuration assessment. It is not a penetration test, compliance certification or guarantee of security. The collectors are read-only; remediation commands shown in the report can change configuration and require separate review, approval and testing.
Evidence
How to collect evidence
The browser application analyses the fictional samples and compatible AdminSecOps evidence packages. Browser restrictions prevent a web page from inspecting Active Directory, AD CS, Group Policy or Windows hosts, so collecting evidence from a real environment is a separate, read-only administrative operation performed with the AdminSecOps Collector in PowerShell 7.
- Test in a non-production environment first.
- Confirm you are signing in to the tenant you intend to assess: pass the expected tenant ID, and review every requested permission before you approve it.
- Run the collection. It performs read operations only and writes a single evidence package.
- Review the package, then store it securely and delete it when it is no longer needed.
- Open the evidence package in the browser application, or in the local application, to see the findings.
Advanced: collect evidence from your environment
The download contains the collector, the documentation and the source of the local application. Collection requires PowerShell 7 and administrative read access; the included documents list the exact permissions and the known limitations. Most visitors do not need this download — the samples and the browser application need nothing but this page.
About this project
An independent community project
This is an independent personal and community project. It is not affiliated with or endorsed by any current or former employer or technology vendor.
Reproducible defects are welcome at mail@palanikumar.net, with synthetic or redacted examples only. Never send live evidence, reports, credentials or tenant identifiers.
