Assess your M365 tenant's security with ScubaGear, a tool for startup founders, backed by 2.6k+ GitHub stars.
intermediate⏱ 30 minutes💵 Free
2,620 stars373 forksPowerShellQuality 8/10Updated 7/23/2026100% free · open source
What it is
Use ScubaGear to check the security level of your Microsoft 365 (M365) tenant.
What you can make with it
Automations like checking your M365's vulnerability against CISA's baselines and receiving a report.
How it helps
ScubaGear speeds up your security assessment, reducing the time spent on complex security audits so you can focus on growth.
Real use case example
"A founder with a growing M365 tenant uses ScubaGear to assess their security and gets a detailed report, finding some vulnerabilities they can easily fix within a few days."
If you're new
Novice users should pick this up when they first set up their M365 tenant to prioritize security.
If you're senior
Senior engineers and founders reach for ScubaGear when they need to ensure the highest level of security for their M365 tenant quickly and accurately.
Common confusion cleared up
Some users might think ScubaGear is exclusively for advanced users, but it's suitable for intermediate users who want to ensure their M365 tenant's security.
Best inside these AI tools
Any AI Client
Pairs with
CISA's M365 security guidelines
Why we list it on WorkflowStacks: ScubaGear is included because it's a free and open-source tool backed by the US government's cybersecurity agency.
What it does
ScubaGear assesses your Microsoft 365 tenant's security by checking its configuration against CISA's recommended baselines
3Review the generated report to identify areas for improvement
4Use the -OutputFile parameter to save the report to a file: .\ScubaGear.ps1 -TenantId <your_tenant_id> -ClientId <your_client_id> -ClientSecret <your_client_secret> -OutputFile report.csv
5Use the -Baseline parameter to specify a custom baseline: .\ScubaGear.ps1 -TenantId <your_tenant_id> -ClientId <your_client_id> -ClientSecret <your_client_secret> -Baseline Custom
Heads up: You need to have the AzureAD and ExchangeOnlineManagement PowerShell modules installed and configured to use ScubaGear, and you must have the necessary permissions to access your M365 tenant
Saves to your device
Topics
assessment-tool
cisa
contributions-welcome
cybersecurity
m365
open-policy-agent
open-source
powershell
rego
scuba
scubaconnect
security
security-automation
What's inside — free to inspect
No purchase needed
Read the entire source before you build — unlike paid marketplaces that hide it behind a buy button.
8
top-level files
9
folders
41.2M
repo size
CC0-1.0
license
Key files
_config.yml
README.md
File tree
.github/
.regal/
baselines/
docs/
images/
PowerShell/
sample-report/
Testing/
utils/
_config.yml
.gitattributes
.gitignore
CONTENTSTYLEGUIDE.md
CONTRIBUTING.md
LICENSE
README.md
RELEASES.md
Quick Actions
Details
Creator
cisagov
Language
PowerShell
Category
automation
Published
7/21/2022
Are you the creator of this tool? Claim your listing → and earn 85% of every sale.
Related skills
More automation tools founders pair with this one.