CloudSignLab

Help centerYour security program

Automatic checks of Microsoft 365, Google Workspace and AWS

Connect your cloud accounts read-only and get daily checks as evidence for your controls, with tasks when something fails.

Updated September 29, 2026

In this section: Your security program

Automatic checks looks at the security settings of your Microsoft 365, Google Workspace and AWS accounts once a day and shows the results as evidence for your controls. It is for owners and admins, if your package includes it; the number of connections depends on the package. Access is always read-only: CloudSignLab never changes anything in your accounts.

Connect Microsoft 365

  1. Open Automatic checks in the organization menu.
  2. On Microsoft 365, click Connect and sign in with a Global Administrator account of your Microsoft Entra ID tenant. The sign-in tells CloudSignLab which tenant is yours; only a Global Administrator can connect it.
  3. Microsoft shows the read-only permissions CloudSignLab asks for. Click Accept for your organization.
  4. You come back to CloudSignLab and the first checks run straight away.

Connect Google Workspace

  1. On Google Workspace, click Connect and sign in with a super admin account.
  2. Allow the read-only access (users, security settings and sign-in reports).
  3. You come back to CloudSignLab and the first checks run.

Connect AWS

AWS uses a role instead of keys, so no passwords or keys are exchanged.

  1. On AWS, click Connect. A window shows the CloudSignLab account ID and your external ID, each with a copy button.
  2. In the AWS console, open IAM > Roles > Create role, choose AWS account > Another AWS account and enter the CloudSignLab account ID.
  3. Tick Require external ID and paste your external ID.
  4. Attach only the AWS managed policy SecurityAudit (read-only) and create the role, for example named CloudSignLabChecks.
  5. Copy the role's ARN, paste it into CloudSignLab and click Test and connect. The role is tested before it is saved, including that it refuses a wrong external ID (this test shows as one refused attempt in your CloudTrail).

Reading the results

Each check is Passing, Failing, Could not check (usually a missing permission) or Not applicable. A failing check shows how to fix it and up to 20 affected accounts or regions. Checks run about once a day; Run now starts them at once (at most every 10 minutes).

When a check starts failing, CloudSignLab opens a task, tells the owners and admins, and sends the Automatic check failing event to your integrations. When the check passes again, the task is closed.

Evidence on controls

Each check is linked to controls of the control library and to NIS2 Article 21(2) and ISO 27001 codes. On a control, the Automatic evidence panel shows the latest results of the linked checks, so an auditor sees that the control works in practice. Everyone who can read controls can see it.

Disconnecting

Click Disconnect on the account. The results are deleted and, for Google, access is revoked straight away. For Microsoft, also delete the CloudSignLab app under Enterprise applications; for AWS, delete the role you created.

What is stored

Only the results: status, counts, and the names of up to 20 failing accounts. Results are kept for 90 days. The Google access token is stored encrypted. Nothing else from your accounts is copied.

See also

Automatic checks of Microsoft 365, Google Workspace and AWS | CloudSignLab