> For the complete documentation index, see [llms.txt](https://docs.cipp.app/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.cipp.app/user-documentation/dashboard.md).

# CIPP Dashboard

Welcome to the CIPP Dashboard. This page gives you both an overview of your client tenants and a way to assess them against security baselines. It is laid out in tabs, with different information on each.

What the dashboard shows depends on the tenant selector. Choose a single tenant and you get that tenant's detail. Choose **All Tenants**, which is also where you land before picking a tenant, and the page swaps to an estate-wide view.

{% hint style="warning" %}
Much of the dashboard is built from data cached in CIPP's reporting database, refreshed by a scheduled job. The first time you load the dashboard for a tenant you may see little or nothing until that job has run. Use **Refresh** to collect the data immediately rather than waiting.
{% endhint %}

## Walkthrough

{% @storylane/embed subdomain="app" url="<https://app.storylane.io/share/zt4porabti6d>" linkValue="zt4porabti6d" %}

## All Tenants View

Under All Tenants the dashboard is built entirely from cached data, with no live Graph calls, and is organised into three bands. Almost every figure links through to the page where you can investigate it.

### Portfolio

A row of totals for tenants, users, mailboxes, and devices under management, each with the per-tenant average on hover. Selecting a tile opens the matching list page across all tenants.

If the cache has never run, a note appears here in place of the figures.

### Security Posture

<details>

<summary>Secure score</summary>

The portfolio average, how many tenants it covers, and the movement since the previous measurement, along with the best and worst scoring tenants. **View** opens the [Secure Score](/user-documentation/tenant/administration/securescore.md) page, which shows a full estate view under All Tenants.

</details>

<details>

<summary>Identity posture</summary>

How many of your tenants are failing at least one identity check, followed by the checks failing across the most tenants. Counts are of tenants rather than users. **View** opens the [Identity](/user-documentation/dashboard/identity.md) tab.

</details>

<details>

<summary>Mail hygiene</summary>

SPF, DKIM, DMARC, and DNSSEC coverage across the domains that have been analysed, shown as coverage meters with the domain count. **View** opens the [Domains Analyser](/user-documentation/tenant/standards/domains-analyser.md).

</details>

<details>

<summary>Standards alignment</summary>

The portfolio average alignment score, with tenants grouped into bands of 90% and above, 75 to 89%, 50 to 74%, and below 50%. **View** opens the [Standards & Drift Alignment](/user-documentation/tenant/standards/alignment.md) page.

</details>

### Operations and Triage

Four tiles cover what needs attention right now.

| Tile                                   | Description                                                                                                                                                             |
| -------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Tenants logging errors today           | Tenants with Error or Critical log entries today, with the total entry count. Opens the [Logbook](/user-documentation/cipp/logs.md).                                    |
| Delegations expiring within 30 days    | GDAP delegations nearing expiry, noting how many of those have no auto-extend. Opens GDAP [Relationships](/user-documentation/tenant/gdap-management/relationships.md). |
| High-risk checks failing               | High-risk test failures and how many tenants they span. Opens the [Identity](/user-documentation/dashboard/identity.md) tab.                                            |
| Standards deviations awaiting approval | Deviations pending approval and the number of tenants involved. Opens [Standards & Drift Alignment](/user-documentation/tenant/standards/alignment.md).                 |

Below the tiles, three cards surface the tenants behind those numbers.

<details>

<summary>Tenants needing attention</summary>

Tenants ranked worst first by delegation state and error activity, so the ones in trouble surface without hunting.

</details>

<details>

<summary>Delegation expiry horizon</summary>

GDAP and CSP relationships grouped by time remaining: expired, 0 to 7 days, 8 to 30 days, 31 to 90 days, and over 90 days.

</details>

<details>

<summary>Cache freshness</summary>

Counts of tenants that are fresh, stale, or never cached, alongside the tenants that have not synced recently. This catches tenants that quietly stopped collecting data, which would otherwise show as misleadingly clean elsewhere on the dashboard.

</details>

The Identity, Devices, and Custom tabs also switch to cross-tenant views under All Tenants.

## Overview Tab

With a single tenant selected, the Overview tab opens with a row of controls, then the tenant's detail cards.

### Page Controls

<details>

<summary>Portals</summary>

Quick links to the Microsoft portals for the selected tenant. Which portals appear is controlled by the **Portal Links Configuration** settings on the [User Preferences](/user-documentation/shared-features/menu-bar/user-settings.md) page.

{% hint style="warning" %}
These links take you out of CIPP, and require your own account, not the CIPP service account, to hold GDAP permissions for the resource.
{% endhint %}

</details>

<details>

<summary>Executive Summary</summary>

Generates a client-friendly summary report from CIPP's data, suitable for presenting to the client. It is fully brandable via [Branding](/user-documentation/cipp/settings/branding.md), and you can choose which sections to include before generating.

</details>

<details>

<summary>Report Builder</summary>

Opens the [Report Builder](/user-documentation/tools/report-builder.md), where you can use the data collected by CIPP's test suites to produce custom client-facing reports.

</details>

{% hint style="info" %}
On narrower screens **Executive Summary** and **Report Builder** collapse into a single **Dashboard Reports** menu.
{% endhint %}

### Test Suite Controls

The test suite you select drives the assessment figures on this tab and the contents of the Identity, Devices, and Custom tabs.

<details>

<summary>Select a test suite</summary>

Choose which suite to assess the tenant against. Custom suites you have created are listed alongside the built-in ones. The refresh icon beside the box reloads the list of suites, which is useful after creating one.

The dashboard opens on your preferred suite, falling back to the instance-wide preference and then to Zero Trust Network Access if neither has been set. To choose your preferred starting suite, set **Default test suite on the Home page** on the [User Preferences](/user-documentation/shared-features/menu-bar/user-settings.md) page.

</details>

<details>

<summary>Create Suite</summary>

Build your own suite by selecting from the available Identity, Device, and Custom tests. Give it a name and description, choose the tests, and it becomes selectable alongside the built-in suites.

</details>

<details>

<summary>Refresh</summary>

Collects fresh data for the tenant. You are asked what to refresh:

| Mode                                       | Description                                                 |
| ------------------------------------------ | ----------------------------------------------------------- |
| Cache & Tests (full refresh)               | Collects tenant data and then re-runs the tests against it. |
| Cache only (collect tenant data)           | Refreshes the collected data without re-running tests.      |
| Tests only (re-run against existing cache) | Re-runs the tests against the data already collected.       |

A full refresh can take up to two hours. Tests-only is much faster where the cache is already populated. The work runs in the background, so you may need to return to the dashboard once it completes.

</details>

<details>

<summary>Edit</summary>

Edits the selected custom test suite. Built-in suites cannot be edited, and the button is unavailable when one is selected.

</details>

<details>

<summary>Delete</summary>

Deletes the selected custom test suite. Built-in suites cannot be deleted, and the button is unavailable when one is selected. Deletion cannot be undone.

</details>

### Available Built-In Test Suites

* **ACSC Essential Eight**: Australian Cyber Security Centre (ACSC) Essential Eight Maturity Model, eight mitigation strategies for adversary defence covering MFA, restricting administrative privileges, application control, patching applications and operating systems, Microsoft Office macro settings, user application hardening, and regular backups. CIPP tests cover what the Microsoft 365, Entra, Intune, and Defender APIs expose; lower-level enforcement controls that cannot be validated from cloud telemetry are flagged as manual.
* **CIS Microsoft 365 Foundations Benchmark v7.0.0**: Center for Internet Security (CIS) Microsoft 365 Foundations Benchmark v7.0.0, a prescriptive technical baseline for securely configuring a Microsoft 365 tenant across the M365 admin centre, Defender, Purview, Intune, Entra, Exchange Online, SharePoint, and Teams.
* **CISA ScubaGear Tests for Exchange Online**: Security configuration assessment tests based on CISA's Secure Cloud Business Applications (ScubaGear) project for Microsoft Exchange Online. These tests validate compliance with federal security baselines.
* **EIDSCA (Entra ID Security Configuration Analyzer) Tests**: Comprehensive security assessment for Microsoft Entra ID covering authorisation policies, authentication methods, consent policies, password policies, and group settings. Based on Microsoft's EIDSCA framework for identity security best practices.
* **Generic Tenant Tests**: Executive-level informational reports covering licensing, MFA posture, secure score trends, and tenant capabilities. These tests provide a clear snapshot of your tenant's current state without pass/fail criteria.
* **Microsoft 365 Copilot Readiness Tests**: Assess tenant readiness for Microsoft 365 Copilot deployment. Tests cover prerequisite licensing, Copilot licence assignment, and active M365 app usage that determines which users would benefit most from Copilot.
* **ORCA (Office 365 Recommended Configuration Analyzer) Tests**: Comprehensive security assessment for Microsoft Exchange Online and Office 365 security configurations. Tests cover anti-spam, anti-phish, anti-malware, safe links, safe attachments, DKIM, transport rules, and other Exchange Online security settings.
* **SMB1001:2026 Cybersecurity Standard**: Dynamic Standards International (DSI) SMB1001:2026, a multi-tiered cybersecurity certification for small and medium-sized businesses, prescribing a five-level pathway across Technology Management, Access Management, Backup and Recovery, Policies/Processes/Plans, and Education and Training. CIPP tests cover the technical controls implementable against a Microsoft 365 tenant (Identity) and via Intune-managed workstations (Devices).
* **Zero Trust Network Access Tests**: Microsoft's comprehensive security assessment covering identity and device compliance, conditional access policies, authentication methods, and endpoint protection aligned with Zero Trust principles.

### Dashboard Cards

<details>

<summary>Tenant</summary>

The tenant's name, tenant ID, and primary domain. The tenant ID can be copied to the clipboard.

</details>

<details>

<summary>Tenant metrics</summary>

Counts of Users, Guests, Groups, Service Principals, Devices, and Managed devices.

{% hint style="info" %}
Each metric is clickable and takes you to the corresponding area of CIPP for a deeper look.
{% endhint %}

</details>

<details>

<summary>Assessment</summary>

How the tenant scored against the selected test suite, broken down by Identity, Devices, and Custom, with an overall figure and a pass, fail, and skip split. The suite's name and description are shown on the card.

</details>

<details>

<summary>Alerts</summary>

Alerts generated for the tenant, with counts for Active and Snoozed. Switch between the two to filter the list, and use the clock icon on a row to snooze an alert or remove an existing snooze. **Manage** opens the [Alert Configuration](/user-documentation/tenant/administration/alert-configuration.md) page.

</details>

<details>

<summary>Secure Score</summary>

The historical trend of the Microsoft Secure Score collected for the tenant.

</details>

<details>

<summary>User authentication</summary>

A chart of user authentication and MFA or Conditional Access status.

</details>

<details>

<summary>All users auth methods</summary>

The authentication methods in use across the tenant's users. Clicking a category jumps to the MFA report with filtering applied, so you can see exactly which users are on that method and who needs moving to something stronger.

</details>

<details>

<summary>License Overview</summary>

The licences present on the tenant, with assigned and available counts.

{% hint style="info" %}
To exclude a licence from this and all other reports in CIPP, add the licence in licenses.md.
{% endhint %}

</details>

## Other Tabs

The [Identity](/user-documentation/dashboard/identity.md), [Devices](/user-documentation/dashboard/devices.md), and [Custom](/user-documentation/dashboard/custom.md) tabs show the results of the test suite selected on this tab, including remediation guidance for failed tests. Each has its own page in this documentation.

**Previous Dashboard Experience** returns you to the [Previous Dashboard Experience](/user-documentation/dashboard/dashboard.md).

***

## Feature Requests / Ideas

We value your feedback and ideas. Please raise any [feature requests](https://github.com/CyberDrain/CIPP/issues/new?template=feature.yml) on GitHub.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.cipp.app/user-documentation/dashboard.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
