Nothing on your endpoints changes.
The scanner enumerates, parses and reports. It cannot modify registries, certificates, processes or TLS configuration. Remediation stays in your hands; Shorfall verifies it.
No new agents: the Defender sensor you already run finds every weak certificate, legacy protocol and quantum-vulnerable key. Each becomes an owned fix that closes only on evidence.
Most estates still run SHA-1 certificates, TLS 1.0 kept alive for one vendor, and thumbprints pinned in web.config. Nobody knows who owns half of it, so every hardening change risks the application nobody remembers. Defender already sees most of the evidence.
The long game is harvest now, decrypt later: RSA and ECC keys guarding data that must stay confidential for years. The inventory is no longer optional:
Microsoft's own guidance is a six-stage lifecycle and a manual integration project. Shorfall runs it for your Defender estate.
One template into your subscription; one script gives the web app's own managed identity read-only Defender roles. First inventory within the hour. No Shorfall identity, no agent, nothing on endpoints.
Machine.Read.All, AdvancedQuery.Read.All and Vulnerability.Read.All, held by your identityAdvanced Hunting refreshes the passive inventory. Where telemetry is not enough, the published read-only script runs through Live Response, only on the servers you select. Metadata leaves the endpoint; secrets never do.
CryptoDiscovery.ps1, read-only, hash recorded on every inspectionDefender network telemetry becomes a dependency graph: which processes consume each weak service, over which port, with which certificate. You see the blast radius before anything changes.
DeviceNetworkEvents: source process, target service, bound certificateFindings become recommendations grouped by what changes them: one certificate, one policy, one application, each with plain-sentence drivers and an owner. The graph orders the waves: consumers verify first, later waves stay locked until they do.
Drivers, not bare scores. AIVD, CWI and TNO PQC Migration Handbook methodMark a change done and Shorfall re-inspects, closing the recommendation only when the evidence is gone. Findings carry a lifecycle: new, fixed, reintroduced. Your readiness trend is evidence, not opinion.
A certificate is easy to rotate. The services that pin, trust, and negotiate against it are not. Shorfall maps every consumer of a weak service from Defender network telemetry, then orders the migration so consumers prove they accept the replacement cryptography before the service changes.
No bare scores. Five programs report coverage-normalized percentages with a target and a trend. Every recommendation lists the drivers behind its tier. Inventory exports as CSV or a CycloneDX 1.6 CBOM.
The scanner enumerates, parses and reports. It cannot modify registries, certificates, processes or TLS configuration. Remediation stays in your hands; Shorfall verifies it.
No private keys, no file contents, no tokens, no payloads. Findings carry algorithm, key size, location and confidence, nothing an attacker could use.
The scanner's source and SHA-256 are on the release feed. Shorfall keeps it current in your own Live Response library, or you upload it yourself, and every inspection records the hash of what actually ran.
Deployed into your Azure subscription from a readable template. Defender roles sit on your own managed identity, evidence in your Cosmos DB, no call home. Delete the resource group and Shorfall is gone.
Deploy Shorfall in your tenant and the passive assessment starts on your estate. The Community edition is free for your own tenant, no device caps, registered to your organisation; service providers operating it for clients need a licence.
Dependency resolved. You reached the end of the graph.