Last updated
Read-only Microsoft Cloud (Entra/Azure/M365) compliance assessment toolkit.
$ winget install --id Stells.EntraChecks --exact --version 1.8.0Run in Command Prompt, PowerShell, or Windows Terminal. Prompts for any agreements.
EntraChecks uses EXE (NSIS). The silent install switches are /S.
EntraChecks_1.8.0_x64-setup.exe /S
For Intune admins
Automated application patching for Microsoft Intune. Pckgr keeps a curated library of 1,000+ apps continuously up-to-date in your tenant via Microsoft Graph - no manual repackaging, no chasing vendor sites.
Start free 30-day trialNo credit card required.
EntraChecks runs read-only security and compliance checks across Microsoft 365 and Azure environments, then produces analyst-friendly HTML, CSV, JSON, and Excel reports. Modules cover Conditional Access, MFA, Identity Protection, Intune, Microsoft Secure Score, Defender for Cloud regulatory compliance, Azure Policy, Microsoft Purview Compliance Manager, on-premises Active Directory, hybrid identity correlation, and SOC 2 readiness. The desktop app is a thin Tauri shell over the same PowerShell engine the CLI uses; all checks are read-only and never modify your tenant.
| Architecture | Type | Scope | Install | Download |
|---|---|---|---|---|
| x64 | EXE NSIS | machine | Direct |
Copy a command tailored to that specific architecture, type, and scope - useful when winget would otherwise pick a different default.
No known CVEs for EntraChecks.
Coverage is best-effort and depends on a winget package mapping to an NVD CPE entry. Absence here is not a guarantee of safety.
More from David Stells or browse security, compliance, azure.