TechKher Discovery Platform (SaaS)
Budget: $300.0
FIXED /
⭐ 0.00 (0)
India
node.js, react-js, docker, saas, python, microsoft-windows-powershell, microsoft-active-directory
Qualifiche preferite
- Tipo di talent: Agenzia
- Esperienza: Intermedio
- Inglese: Fluente
- Job Success: 90%+
- Guadagni min.: $10,000+
TechKher Services is building a commercial SaaS environment discovery platform. It will be sold and delivered from our website as a hosted product.
The platform connects to a customer's Microsoft cloud tenant — and, in hybrid deployments, their on-premises infrastructure — and produces a complete, structured inventory of the environment. The primary market is merger & acquisition technical due diligence and pre-migration assessment: the situation where a business has acquired another business and needs a defensible, comprehensive picture of what they've just bought before planning integration.
We are not starting from zero. We have a working desktop discovery tool, built in Python with a PowerShell orchestration engine, already proven against live production tenants. Its Exchange Online, Entra ID, SharePoint, mail flow and application discovery modules are debugged and running today. That codebase and its PowerShell discovery logic will be handed to the selected agency at kickoff as the foundation. Your job is to re-platform it as a multi-tenant SaaS product and extend coverage to the full scope below — not to reinvent the discovery logic we've already proven.
Critical constraint: the platform is 100% read-only. It must never create, modify, or delete any object in a connected environment. Every consent scope requested must be read-only. This is a product guarantee we make to customers and it is non-negotiable.
Part 1 — Microsoft Cloud Discovery (Complete Coverage)
The requirement is everything. If Microsoft exposes it in a cloud service and it's relevant to understanding or migrating an environment, we want it inventoried.
Entra ID / Identity
Users and groups, with sync source (cloud-only vs directory-synced), attribute completeness, UPN suffix inventory
Administrative units, group types (security, M365, dynamic, mail-enabled), dynamic membership rules
MFA registration and enforcement state, per-user authentication methods, passwordless / FIDO2 / Windows Hello adoption
Sign-in activity, last successful sign-in, stale and never-used accounts
Conditional Access policies with full condition, control, session and named-location detail — plus report-only policies
Authentication methods policy, authentication strengths, legacy auth usage
Directory role assignments, PIM eligible and active assignments, PIM policy settings, access reviews
Guest / B2B users, external collaboration settings, cross-tenant access policies, B2B direct connect
Enterprise applications, app registrations, service principals, OAuth2 consent grants, app roles
Sensitive and high-risk scope flagging, credential expiry on app registrations
Identity Protection risk detections, risky users and sign-ins (P2)
Entitlement Management: access packages, catalogs, connected organizations
Custom security attributes, self-service password reset and group configuration
Tenant branding, licensing model, domain inventory and verification state
Exchange Online
Mailbox inventory — user, shared, room, equipment, discovery, scheduling — sizes, item counts, quotas, archive and auto-expanding archive state
Mailbox permissions: Full Access, Send As, Send on Behalf, folder-level and calendar delegates
Auto-forwarding, inbox rules with external forwarding, mailbox audit configuration
Distribution groups, mail-enabled security groups, dynamic distribution groups, M365 groups, mail contacts, mail users
Mail flow: transport rules with conditions/actions/exceptions, inbound and outbound connectors, accepted and remote domains
Anti-spam, outbound spam, anti-malware, anti-phishing, Safe Links, Safe Attachments policies and rule associations
Retention policies and tags, litigation and in-place holds, journaling rules
Mobile device policies and mailbox device inventory, ActiveSync and OWA policies
Address lists, offline address books, email address policies
Public folder hierarchy and mailboxes
Organisation config, sharing policies, availability address spaces
Message trace summary statistics and mail volume profile
SharePoint Online & OneDrive for Business
Site inventory: template, storage used and quota, last activity, lock state, hub associations
Site collection administrators, group and permission structure, unique permission inventory
Tenant and site-level external sharing configuration, anonymous link policy and expiry
Sharing links inventory and external user access exposure
OneDrive inventory per user, storage consumption, sharing configuration, orphaned OneDrives
Term store / managed metadata, content types, site designs and scripts
Retention and DLP policy application, sensitivity label application on sites
Storage trend and growth profile, largest sites and libraries
Access control policies (unmanaged device, IP location), OneDrive sync restrictions
Microsoft Teams
Teams inventory: membership, owners, guests, privacy, orphaned and inactive teams
Channels — standard, private, shared — with membership and associated site
Teams policies: messaging, meeting, calling, live events, app permission and setup, app catalog
Teams Phone: voice routing, dial plans, call queues, auto attendants, phone number inventory, emergency addresses
Federation and external access configuration, guest access settings
Teams apps installed and app permission grants
Usage and activity profile per team
Microsoft Intune / Endpoint Manager
Managed device inventory: ownership, platform, OS build, enrolment type, compliance state, last check-in, encryption state
BitLocker: encryption status per device, recovery key escrow presence, BitLocker policy configuration, FileVault equivalent for macOS
Compliance policies with full setting detail and assignment scope
Device configuration profiles, settings catalog policies, administrative templates, security baselines
Endpoint security policies: antivirus, firewall, disk encryption, EDR, attack surface reduction, account protection
App protection and app configuration policies (MAM), managed app inventory
Application inventory, deployment types, assignment and install status
Windows Autopilot profiles and device registrations
Enrolment restrictions and configurations, device categories
Windows Update rings, feature update and driver update profiles, Windows Update for Business reports
Conditional Access integration, device compliance dependencies
Scripts and remediations, Endpoint Analytics
Apple / Google enrolment token and certificate expiry (APNs, VPP, DEP)
Microsoft Defender Suite
Defender for Office 365: policy inventory, threat protection status, Safe Links/Attachments coverage, quarantine policy, priority accounts
Defender for Endpoint: onboarded device inventory, onboarding method, sensor health, ASR rule configuration and exclusions, vulnerability and exposure summary, device risk levels
Defender for Identity: sensor inventory and health, monitored domain controllers, detection configuration
Defender for Cloud Apps: connected apps, discovered shadow IT summary, policy inventory, OAuth app governance
Defender for Cloud: secure score, recommendations, regulatory compliance posture, defender plan coverage per subscription
Microsoft Secure Score with full control breakdown and improvement actions
Incidents and alerts summary, custom detection rules
Threat and vulnerability management: exposed devices, missing patches, software inventory
Microsoft Purview / Compliance
DLP policies, rules and locations across all workloads, including endpoint DLP
Sensitivity labels, label policies, auto-labelling policies, encryption and marking configuration
Retention policies, retention labels and label policies, adaptive scopes
Records management, disposition review configuration
eDiscovery cases (Standard and Premium), holds and search inventory
Communication compliance policies, insider risk policies
Information barriers, segments and policies
Unified audit log state, retention policy, audit log search configuration
Data lifecycle management, Compliance Manager score and assessments
Data classification: trainable classifiers, sensitive info types, content explorer summary
Power Platform
Environment inventory: type, region, Dataverse presence, security group scoping
Power Apps inventory (canvas and model-driven), owners, sharing, connector usage
Power Automate flow inventory, owners, connectors, run history summary, orphaned flows
Custom and standard connector inventory, connection references
DLP policies and connector classification per environment
Power BI workspace inventory, datasets, gateways, capacity assignment, sharing exposure
Power Pages / Portals inventory
Capacity consumption and licence allocation
Dynamics 365
Instance and environment inventory with version and region
Deployed applications and solutions, managed vs unmanaged, dependency mapping
Security roles, business units, teams, field-level security profiles
Entity/table inventory, custom entities, record volumes
Integrations, plug-ins, custom workflows and Azure-registered services
Licence assignment and consumption per app
Note: this uses the Dataverse Web API and Power Platform Admin API, not Microsoft Graph. Your proposal should reflect that you know this.
Microsoft 365 Core / Tenant
Tenant configuration, organisation profile, verified domains and DNS state
Licensing: SKU inventory, assigned vs available, service plan breakdown, group-based licensing, licence waste analysis (unlicensed enabled users, licensed disabled users, duplicate/overlapping SKUs)
Service health and message centre summary
Microsoft 365 Groups inventory, expiration and naming policies, creation restrictions
Viva module inventory where deployed (Engage/Yammer, Insights, Learning, Connections)
Copilot licence assignment and readiness signals
Booking, Forms, Planner, To Do, Stream, Whiteboard and Loop tenant configuration
Usage analytics: per-workload adoption and active user profile
Azure
Tenant, management group hierarchy, subscription inventory with state and offer type
Resource group and full resource inventory by type, location and tag
RBAC: role assignments at every scope, custom role definitions, inherited and PIM-eligible assignments
Azure Policy: assignments, initiatives, compliance state, exemptions
Cost and consumption summary per subscription and resource group
Compute: VMs with size, OS, disks, extensions, availability configuration; VM Scale Sets; Azure Virtual Desktop host pools, session hosts, app groups, workspaces, FSLogix configuration
Storage: storage accounts, replication, access tiers, public access configuration, lifecycle policies
Networking: VNets, subnets, NSGs and rules, route tables, peerings, VPN and ExpressRoute gateways, Azure Firewall, Front Door, App Gateway, Private Endpoints, DNS zones
Data: SQL servers and databases, Cosmos DB, Storage, managed instances, backup and DR configuration
App services: App Service plans, web apps, function apps, containers, AKS clusters
Identity & security: managed identities, Key Vaults with access policy/RBAC model and secret expiry, Defender for Cloud plan coverage
Operations: Log Analytics workspaces, retention, diagnostic settings coverage, Automation Accounts, Recovery Services Vaults and backup item state
Resource locks, tags and tagging compliance, orphaned resources (unattached disks, unused IPs, empty resource groups)
Part 2 — On-Premises Discovery (Hybrid Deployments)
Read this section carefully — this is where most bidders fail.
On-premises environments are not reachable from a cloud-hosted SaaS backend. Domain controllers, Exchange servers and SharePoint farms sit behind corporate firewalls with no inbound path from the internet.
Required approach: a downloadable collector agent — a signed PowerShell module or lightweight compiled binary — that the customer runs inside their own network under a delegated read-only account. It performs local discovery, produces structured JSON, and either uploads the result to the platform over an authenticated outbound HTTPS channel or is manually imported by the customer.
The collector must:
Run under a standard domain user with delegated read rights — not require Domain Admin
Be code-signed and verifiable, with a published hash — enterprise customers will scan it before running
Show clear local progress and produce a readable local log
Support fully offline operation with manual JSON upload, for air-gapped or restricted networks
Never transmit anything the customer hasn't seen — the JSON output must be inspectable before upload
Be self-contained where possible, minimising module prerequisites on the target server
If your proposal doesn't address this architecture, I will assume you haven't understood the requirement and won't shortlist you.
Active Directory — Full Discovery
Forest and domain topology, functional levels, schema version, FSMO role holders
Domain controller inventory: OS, roles, GC status, replication status and errors, SYSVOL replication method (FRS vs DFSR)
Sites, subnets, site links, site link bridges, replication topology and latency
Complete OU structure with delegation and inheritance blocking
Group Policy Objects: inventory, links, scope, WMI filters, security filtering, delegation, full settings export, unlinked and orphaned GPOs
User, group, computer, contact, service account and gMSA inventory with attribute analysis
Stale, disabled, never-logged-on, password-never-expires, no-password-required and SPN-bearing accounts
Privileged group membership: Domain Admins, Enterprise Admins, Schema Admins, Account Operators, Backup Operators, plus nested membership expansion
AdminSDHolder, protected accounts, Kerberos delegation configuration (unconstrained, constrained, RBCD)
Trust relationships: direction, type, transitivity, SID filtering, selective authentication
DNS: zones, AD-integrated zones, conditional forwarders, scavenging configuration, stale records
Password, account lockout and fine-grained password policies
Certificate Services: CA inventory, templates, enrolment permissions, certificate expiry
LAPS deployment state, DFS namespaces, file share inventory where in scope
Schema extensions and custom attributes
Exchange Server On-Premises
Organisation configuration, Exchange version, CU and security update level per server
Server inventory, roles, DAG configuration, database copy status and health
Mailbox databases: size, mailbox count, white space, log truncation and backup state, quota configuration
Full mailbox inventory with sizes, item counts, permissions, delegates, forwarding and archive state
Public folder hierarchy, public folder mailboxes and permissions
Send and receive connectors, accepted domains, email address policies, address lists, offline address books
Transport rules, journal rules, transport configuration and message size limits
Virtual directory configuration with internal and external URLs, authentication methods
Certificate inventory with subject, SAN and expiry
Retention policies and tags, mailbox and litigation holds
ActiveSync device inventory and policies
Hybrid configuration: HCW output, hybrid mail flow connectors, OAuth and federation trust state, free/busy configuration, MRS proxy state, Exchange hybrid version compatibility
SharePoint Server On-Premises
Farm topology, servers and roles, build and patch level, farm health
Web applications, content databases with size, site count and status
Site collection inventory: template, storage, quota, last modified, owners, locks
Site and library inventory with permission structure and unique permissions
Service applications: Search, User Profile, Managed Metadata, BCS, Secure Store, Workflow
Installed solutions (WSP), features, add-ins and customisations
Authentication configuration: Classic vs Claims, provider configuration, SAML/ADFS trust
Alternate access mappings, host-named site collections
Search topology, crawl schedules and content sources
Workflow inventory (SP 2010/2013 workflows — flag for migration risk)
Hybrid configuration: hybrid search, hybrid sites, cloud SSA state
Note: requires Shell Admin rights on the farm and local execution on a farm server. Scope this accordingly.
Hybrid Identity
Entra Connect / Cloud Sync: version, server, sync scope, filtered OUs and domains
Sync rules — standard and custom — attribute flow mappings, precedence and modifications
Scheduler state, sync cycle interval, last sync time, export/import errors
Sign-in method: Password Hash Sync, Pass-through Authentication, Federation, Certificate-based
PTA agent inventory, version and health
Seamless SSO state and computer account configuration
ADFS: farm topology and version, relying party trusts, claims provider trusts, claim issuance rules, token signing and decrypting certificates with expiry and auto-rollover state, WAP topology, endpoints, access control policies, extranet lockout
Password writeback, device writeback, group writeback configuration
Hybrid Azure AD Join / Entra Join state, SCP configuration
Duplicate and conflicting object detection between on-premises and cloud
Sync errors: duplicate attributes, invalid characters, orphaned objects, quarantined objects
Source anchor configuration (ObjectGUID vs ms-DS-ConsistencyGuid)
Other On-Premises (where present in hybrid scope)
Skype for Business Server topology and coexistence configuration
On-premises file servers targeted for SharePoint/OneDrive migration — share inventory, size profile, permission structure, path length and illegal character analysis
Part 3 — M&A Due Diligence & Migration Planning Layer
This is what makes it a product rather than a reporting script. Discovery data must be transformed into decisions.
Cross-environment reconciliation — cloud and on-premises data correlated within a single engagement view; source and target tenant comparison where both are connected
Collision detection — duplicate UPNs, conflicting SMTP addresses, existing guest or contact objects in the target tenant referencing the acquired entity's domain, overlapping domain claims, duplicate group names
Migration risk register — unsupported Exchange or SharePoint versions, expiring certificates, unresolved sync errors, legacy authentication dependency, deprecated features in use, path-length and character issues, workflow and customisation blockers
Licensing gap analysis — what the acquired organisation holds today vs what the combined entity would need, with waste and overlap identified
Security exposure summary — external sharing, anonymous links, guest sprawl, over-privileged and stale privileged accounts, legacy auth, unmanaged devices, missing MFA
Complexity and effort scoring — per-workload indication of migration difficulty, with the drivers behind each score exposed
Delta comparison — re-run a discovery against the same environment and diff it against a prior run, so change over time is visible
Engagement-scoped storage — every run stored against a named engagement, retained, versioned and retrievable
Part 4 — SaaS Platform Requirements
This is a commercial product on our website, not an internal tool. It must be built accordingly.
Multi-Tenant Microsoft Integration
Multi-tenant Entra ID app registration (signInAudience: AzureADMultipleOrgs) with an admin consent flow that onboards a new customer tenant cleanly
Publisher verification configured against our Microsoft Partner Center MPN ID — customers will not consent to an unverified app
Token acquisition per customer tenant via client credentials, with our credentials held in Azure Key Vault and never exposed client-side
Read-only scopes only, with the full requested permission set documented and presented to the customer before consent
Graceful handling of consent revocation and token failure
Per-tenant throttling awareness — Graph throttles per tenant per app; concurrent multi-customer runs must not cascade
Platform Multi-Tenancy
Customer account model: organisations, users, roles (owner / analyst / read-only)
Strict data isolation between customers — enforced at the data layer, not just in application logic
Engagement model: a customer can run multiple engagements, each scoped to a target environment
Invite and team management, SSO login option for our own customers (Entra ID / Google)
Job Orchestration
Fully asynchronous — a complete run takes hours; queueing, worker scaling, progress reporting, resumability and cancellation are all required
Per-module collection status: complete / partial / unavailable, with an explicit reason. Silent gaps are unacceptable. If a module can't run because of missing licensing or insufficient permissions, the report must say exactly that
Retry with backoff on throttling, circuit-break on authorisation failure
Run history, logs and diagnostics visible to the customer
Output — all generated from a single run, no manual re-entry
Interactive dashboard — the primary product surface, with drill-down per module
Exports — Excel (multi-sheet, formatted, filterable), PDF, Word, and self-contained browser-viewable HTML with sortable/filterable tables
Raw JSON per module — versioned, stored per engagement, downloadable
White-label option — customer logo and branding on exported reports
Reports must be generated from the stored JSON data layer, never from live API calls — any format must be regenerable without re-running discovery.
Commercial & Data Protection
Subscription / plan model with usage limits (engagements, runs, retained history) — Stripe integration
Encryption at rest and in transit, tenant-scoped encryption where practical
Configurable data retention and hard-delete on customer request
Platform audit log — who ran what, against which environment, when
Content is never collected: no message bodies, file contents, chat history or document contents
Credentials, secrets and tokens never written into stored data or generated reports
Architecture must support a future SOC 2 / ISO 27001 posture and Microsoft 365 Certification — we don't need certification at launch, but we need not to have to rebuild for it
Preferred Stack
Flexible if you justify your choice, but our existing codebase and expectations point to:
Discovery engine: PowerShell 7 — Microsoft Graph SDK, Exchange Online Management v3, PnP PowerShell, Az, MSCommerce, plus ActiveDirectory, GroupPolicy, Exchange Management Shell and SharePoint Server cmdlets in the collector agent
Backend: Python or Node.js, containerised
Frontend: React
Data: PostgreSQL with JSONB for raw module output; blob storage for exports
Queue: Redis / Celery, or equivalent
Hosting: Azure, containerised and IaC-defined
Collector agent: signed PowerShell module, or Go/.NET binary if you make a case for it
What We Provide
The existing working codebase — Python desktop application with a PowerShell orchestration engine, with production-proven modules covering Exchange Online, Entra ID, SharePoint, mail flow, applications and OAuth, plus capability pre-flight detection, throttle handling with exponential backoff, and multi-format export. This is real, debugged code that has run against live tenants. It is the starting point
Production PowerShell and Graph API discovery scripts from real client engagements
Test tenant access
Detailed per-module field specifications
Fast, consolidated feedback — batched review comments, not drip-fed
Out of Scope
Any write, modify, remediation or configuration-change capability — read-only is absolute
Content collection: message bodies, file contents, chat history, document contents
Actual migration execution — this is assessment and planning only
Certification audits (SOC 2 / ISO / Microsoft 365 Certification) — architecture must support them, achieving them is separate
Apri su Upwork
AI proposal draft
Generate a short cover letter for this job. Edit before sending.
Sign in to generate an AI proposal draft.
Accedi