You could build this. Here's what it actually takes.

The data is in your tenant, the Microsoft Graph API is documented, and a competent engineer can pull a first report in a week. That part is true. This page is the honest version of what happens after the first report — where a build usually stops, and when it is the right call anyway.

What you get in week one

A real, useful answer. With read-only Graph access, an engineer can surface how many people have MFA registered, who is sharing files externally, how mail-forwarding rules are being set, and how sign-in risk is distributed. Pulled into a BI layer, that is genuinely more than most organizations can see today, and it is worth having. If your question is "what does our tenant look like right now?", a week of engineering answers it well.

Where it stops

Microsoft's retention window

Behavioral history is retained for a limited period, so what you did not capture is gone permanently. Baselines cannot be reconstructed backwards — the day you start building is the earliest your trend can begin.

Normalisation

A raw event count is not a behavior indicator. Turning signals into something comparable across teams of different sizes and over time — so a rise means a real change, not a headcount change — is the actual work, and it is most of it.

Statistical validity

A before-and-after comparison needs a method that survives an auditor asking how you controlled for seasonality, headcount change and sampling. Without that, the number is suggestive, not defensible.

Privacy architecture

Employee behavioral data has works-council, GDPR and internal-trust implications. The design decisions — what is aggregated, what is never stored, who can see what — are hard to reverse once the pipeline is live.

Maintenance

Graph schemas change. The report is not the product; the ongoing correctness is. Every change upstream is a maintenance event, and the cost is continuous, not one-off.

Nobody owns it

The engineer who built it moves teams. Without a clear owner, a home-built measure quietly rots — and it tends to fail at the moment someone finally asks it for a trend.

Peer-reviewed field research

29–55%

of the variation in phishing susceptibility is attributable to organizational-level factors, not individual ones.

Measured across 83,269 employees in 510 organizations, using their real responses to phishing campaigns.

Petrič, G., & Roer, K. (2022). The impact of formal and informal organizational norms on susceptibility to phishing. Telematics and Informatics, 67, 101766. Licensed under CC BY 4.0.

Organizational-level measurement is a research problem before it is an engineering one. Reading the signal is the easy part; measuring it in a way that holds up is the hard part.

The honest cost comparison

We won't put fabricated numbers on your build — you know your own rates. Weigh the engineering days to build it, the ongoing days to maintain it, and the opportunity cost of the team not doing something else, against a published per-employee price. Then put your own figures into the model and see where the line falls for your organization.

Model your own build-vs-buy numbers in the ROI calculator

When building is the right call

Sometimes it genuinely is, and pretending otherwise would make the rest of this page dishonest. Build it yourself when:

  • you have a one-off question, not an ongoing reporting requirement;
  • your data source is unusual and no product covers it well;
  • you have a data-engineering team with genuine spare capacity and an owner who will stay with it;
  • you have no regulatory obligation to produce a defensible, maintained effectiveness trend.

If several of those are true, a build is a reasonable choice. If none of them are, the ongoing cost usually points the other way.

A query is not a method

Evidence you built yourself still has to answer an assessor's question about method. The clause does not care who wrote the query — it cares whether the measurement is sound and documented.

A query is not a method
What your reports show What the regulation asks for What closes the gap
A dashboard built from your own Graph extractionNIS2 CIR Annex §7 — the effectiveness of risk-management measures is evaluated with a defensible methodA documented, repeatable measurement method that survives review
Raw event counts trended over timeGDPR Art 32(1)(d) — a process for regularly testing, assessing and evaluating effectivenessNormalisation and controls for headcount and seasonality, documented
A report one engineer maintainsDORA Art 13(4) and 13(6) — ongoing monitoring of effectiveness over timeContinuity that does not depend on one person staying in the role

Building it is a legitimate choice. But the assessor's question is about method and documentation — and that is the part that outlasts the first report.

See what an assessor actually asks you to evidence

Questions engineers ask

Can’t a competent engineer just build this from Graph?
Yes, for a first report. A capable engineer can pull security-relevant events from the Microsoft Graph API and produce a useful dashboard in about a week. The gap is not the first report — it is turning raw events into a normalised, statistically defensible trend that survives an audit and keeps working as Graph schemas change.
What does Microsoft’s retention window mean for a build?
Microsoft retains behavioral activity for a limited period, so anything you did not capture is gone permanently and baselines cannot be reconstructed backwards. A build only starts accumulating history from the day it goes live. Praxis Navigator reads the history Microsoft already retains, so you get a behavioral baseline from day one.
When is building it yourself the right call?
When you have a one-off question, an unusual data source, an existing data-engineering team with spare capacity, and no ongoing regulatory reporting requirement. If you need a defensible, maintained, audit-ready trend over years, the ongoing cost usually favours buying.
Does evidence I built myself satisfy NIS2, DORA or GDPR effectiveness requirements?
It can, if the method is sound and documented. Those regimes ask whether your measurement of effectiveness is defensible — how you controlled for headcount and seasonality, how you normalised events — not who wrote the query. Home-built evidence has to answer the same methodological questions a vendor’s does.

Compare it against your own build

Connect Microsoft 365 in 15 minutes and see the behavioral baseline a build would take months to reach — then decide.

Start your free 30-day trial

No credit card. No commitment. Results in 15 minutes, or don't continue.

See the price — published, so you can weigh it against engineering days.

Read what an assessor requires — method and documentation, not who wrote the query.