Beacon scans every Azure, AWS, and Google Cloud account you manage every 6 hours, surfaces the gaps, and ships the reports — all from one platform.
Includes checks mapped to CIS Microsoft 365 Benchmark, CIS AWS Foundations, CIS GCP Foundation, NIST CSF, and ISO 27001:2022
Beacon handles the full lifecycle, from scanning to remediation guidance to client reporting, without the manual work.
Beacon runs the full check suite against every managed Azure tenant every 6 hours. Critical findings surface within minutes. No manual intervention, no missed windows.
100 Azure, 44 AWS and 46 GCP checks — identity, Conditional Access, NSG rules, Key Vault, storage, Defender for Cloud, EOL OS, Intune, M365, DevOps — via native read-only cloud APIs. Browse the full catalog.
Five checks across unenrolled devices, non-compliant endpoints, stale sync, unsupported OS builds, and missing Windows Update rings.
Exchange, SharePoint, and Teams: DKIM, DMARC, legacy authentication, anonymous sharing links, and external federation policy.
Seven checks: stale recommendations, active high/critical alerts, workload protection gaps, and regulatory compliance score.
Seven checks: public ADO projects, over-privileged service connections, branch protection, pipeline secrets, and unpinned GitHub Actions.
Four role levels with team-based access scoping. Every MSP's data completely isolated.
Configurable SLA targets per client and severity. Automatic breach detection and alerts.
Growth+: share a read-only URL with each client showing their score, active findings, and resolved activity. MSP controls exactly what's visible.
Pro+: aggregate findings from every client in one table. Bulk acknowledge, assign, or suppress up to 500 findings at once.
Growth+: hourly job creates ConnectWise, HaloPSA, or Freshservice tickets for any finding that has passed its SLA due date.
Growth+: per-client MTTR, SLA breach rate league table, and weekly opened-vs-resolved bar chart across 30/60/90-day windows.
Weekly or monthly reports emailed directly to clients. Findings, score trends, and remediation guidance included.
Push findings to ConnectWise, HaloPSA, or Freshservice per client. HMAC-signed webhooks for Slack, Teams, and custom integrations.
Integrate with Microsoft Entra ID or any SAML 2.0 provider. TOTP MFA for local accounts. AES-256-GCM encryption at rest.
HMAC-SHA256 chained log. Provide auditors evidence of control operation without exposing raw data.
Credentials, notification channel secrets, PSA API keys, and report recipient emails all encrypted at rest. GET responses return masked values.
Self-service org deletion (Article 17) and structured data export (Article 20). Rate-limited to 5 exports per org per day.
Configure a custom scan interval for each client. Default is 6 hours; shorter intervals available on Growth and Pro plans.
Full REST API with machine-to-machine tokens for automation. Build dashboards or feed findings into your ITSM workflow.
Beacon pulls installed software from the tools you already run — Intune, Defender, your RMM, ServiceNow, Topdesk, Jamf, SCCM — matches every version against published vendor lifecycle dates, and tells you exactly what's unsupported, what's approaching end-of-life, and what it will cost to fix. No spreadsheets, no per-product setup.
Nine inventory connectors feed one trusted asset graph — deduplicated across sources, with per-feed health so a silently-dead connector surfaces instead of quietly skewing a report.
Each asset gets a composite risk score — exploited-in-the-wild (CISA KEV), business criticality, exposure — and an auto-derived SLA due date, so the remediation queue is ordered by what actually matters.
A branded lifecycle report with the EOL forecast, budget and recommended upgrade projects — the deliverable you present at the quarterly review and bill for.
A dedicated EOL/lifecycle platform like ScalePad or Liongard is a second vendor, a second agent and a second bill. Beacon reads the sources you already connect for compliance — lifecycle is part of the same continuous scan. See the comparison.
Give every client a read-only portal that shows their live compliance score, open findings, and resolved activity — under your brand, on your URL. It turns the work Beacon already does into a visible, billable service your clients can see month after month.
Most MSPs weigh four options for cloud compliance. Here's the short version of where Beacon pulls ahead. See the full honest comparison.
CIPP is a capable open-source toolkit you deploy, secure, update, and keep running yourself — and it's built for the Microsoft estate. Beacon is a managed service: one read-only connection per cloud and it runs itself, across Azure, AWS, and GCP.
Lighthouse gives a baseline Microsoft 365 and endpoint overview of Microsoft tenants only. Beacon adds deep Azure infrastructure checks plus AWS and GCP, with client-ready reports Lighthouse was never built to produce.
Hand-pulled audits cost engineer hours per client and leave issues sitting undetected between reviews. Beacon rechecks every tenant every 6 hours and hands you report-ready findings — no linear overhead as you add clients.
No agents, no extra tooling in the client environment. The Azure checks below use Microsoft Graph and Azure Resource Manager APIs directly; AWS and GCP are scanned the same agentless way through their native read-only APIs. Want every check and its framework mapping? Browse the full Checks Catalog.
No agents. No complex setup. Beacon only needs one read-only connection per cloud account, whatever the provider.
Set up one read-only connection per account: an Azure App Registration, an AWS cross-account IAM role, or a GCP scanner service account. Beacon never asks for write access. See the Azure, AWS, and GCP setup guides.
Beacon runs the full check suite for each provider every 6 hours. Findings are reconciled across scan cycles, so no duplicate alerts. Critical issues trigger immediate notifications.
Fix issues from guided remediation steps, share read-only portals with clients, and schedule automatic compliance reports. Compliance scores update in real time.
Pay for the cloud accounts you manage across Azure, AWS & GCP. Every plan runs all 190 checks every 6 hours — higher tiers add SSO, PSA, the client portal, and the API.
A single manual compliance audit costs thousands in engineer time. Beacon runs the same checks continuously, for every tenant, starting at $59 per month.
Calculate your ROI$180 billed yearly
1 user, 1 cloud account (Azure, AWS or GCP)
$468 billed yearly
Up to 10 cloud accounts across Azure, AWS & GCP
$948 billed yearly
Up to 30 cloud accounts across Azure, AWS & GCP
$1,908 billed yearly
Up to 75 cloud accounts across Azure, AWS & GCP
Unlimited cloud accounts across Azure, AWS & GCP
Card required at checkout. Cancel anytime. Annual billing saves two months. Questions? Contact us.
Every plan includes the full check suite and automatic scanning. The differences are in scale, integrations, and how much you hand straight to clients.
| Feature | Solo | Starter | Growth | Pro | Enterprise |
|---|---|---|---|---|---|
| Cloud accounts (Azure / AWS / GCP) | 1 | 10 | 30 | 75 | Unlimited |
| All 190 security checks | ✓ | ✓ | ✓ | ✓ | ✓ |
| 6-hour automatic scans | ✓ | ✓ | ✓ | ✓ | ✓ |
| Email alerts & scheduled reports | ✓ | ✓ | ✓ | ✓ | ✓ |
| Slack & Teams notifications | — | — | ✓ | ✓ | ✓ |
| SAML SSO | — | — | ✓ | ✓ | ✓ |
| Per-client SLA tracking & webhooks | — | — | ✓ | ✓ | ✓ |
| PSA integration & auto-escalation | — | — | ✓ | ✓ | ✓ |
| Branded client compliance portal | — | — | ✓ | ✓ | White-label |
| Remediation dashboard & MTTR analytics | — | — | ✓ | ✓ | ✓ |
| Cross-client findings & bulk remediation | — | — | — | ✓ | ✓ |
| Custom checks, API access & M2M tokens | — | — | — | ✓ | ✓ |
| White-label reports | — | — | — | ✓ | ✓ |
| Dedicated infrastructure & SLA-backed uptime | — | — | — | — | ✓ |
Beacon is the only multicloud compliance platform designed around how MSPs actually work: managing client accounts across Azure, AWS & GCP, proving compliance, and keeping engineers focused on fixes.
Everything you need to know before getting started.
Explore a pre-loaded environment with 5 sample MSP clients, real findings, and full navigation. No sign-up required, just use demo code BEACON-DEMO.
Read-only. No sign-up required. No data stored.
Beacon runs the full check suite every 6 hours. You get alerts when something needs attention.