
Michigan security scanning laws require review beyond whether a tool changes or destroys data. MCL § 752.795(a) addresses intentional unauthorized access to acquire property or otherwise use computer services, and the statutory definition of access includes communicating with computer resources.
Evidence before outreach · Part 11: Michigan. Research date: October 6, 2026. Preliminary statutory analysis, not legal advice or clearance. Related definitions, exceptions, decisions and method-specific application need further counsel review.
- Michigan security scanning laws are not limited to destructive conduct.
- Section 752.795(a) includes access to acquire property or otherwise use computer services.
- Section 752.792 defines access to include communication and resource use.
- The aggregate-loss definition includes specified verification expenditures, not automatic liability for any complaint.
- SCOUTz prospect intelligence keeps public index evidence separate from authorized Microsoft 365 review.
Why does read-only leave the service-use question open?
Read-only can describe a tool's intention while leaving the legal question unanswered. Michigan's access and service-use language illustrates why a review needs the actual request record, not only a promise that no settings were changed.
An MSP should also avoid making investigation costs sound like automatic liability. The conduct elements and connection to an offense remain part of the analysis.
What should MSPs review under Michigan security scanning laws?
The official MCL § 752.795 text, consulted October 6, 2026, begins with intentional conduct without authorization or exceeding valid authorization. Paragraph (a) includes access to acquire, alter, damage, delete or destroy property or otherwise use computer-program, computer, system or network services.
The official definitions in § 752.792 define access to include instructing, communicating with, storing data in, retrieving or intercepting data from or otherwise using computer resources.
Do not infer that communication by itself establishes an offense. The definition and the conduct provision must be read together, with the applicable authorization and mental-state requirements.
| Provision | Statutory issue | Question for the method review |
|---|---|---|
| § 752.792(1) | Access includes communication and resource use | Which resource received the interaction? |
| § 752.795(a) | Intentional unauthorized access and listed purposes or service use | What authorization applied and what was used or acquired? |
| § 752.795(b) | Specified instruction or program insertion-related conduct | Did the method introduce the conduct described in the text? |
| § 752.792(2) | Aggregate amount includes defined loss and verification expenditure | What loss is connected to the alleged offense? |
The table highlights statutory distinctions. It does not determine how a particular collector is classified.
Which source or prospect service did the collector use?
Reading an existing third-party index involves a different request from contacting the indexed service. Querying published DNS is another interaction. Web requests, service enumeration and testing require their own entries.
For a Michigan-connected workflow, preserve:
- The source and relevant timestamps.
- The destination of each request.
- The information obtained or service used.
- The permission basis and agreed scope.
- Any limits, objections or withdrawal.
- The result and the facts left unknown.
A hostname found in an index does not establish that your team accessed the host or retrieved its content. Do not turn that reference into a claim about current availability or sensitive data without supporting evidence and appropriate permission.
Is service use limited to successful intrusion?
The text's phrase otherwise use the service is a reason to analyze direct requests rather than assuming that only exploit execution matters. But broad wording is not a prediction that every ordinary public interaction violates the law.
Counsel should examine the actual services and permissions, related definitions and relevant decisions. The business purpose of prospecting does not replace that review.
Read-only describes the intended effects. It does not tell you whether the service use was permitted.
Verification expenditure requires context
Section 752.792(2)'s aggregate-amount definition includes direct or indirect loss and actual expenditure to verify that systems were not altered, acquired, damaged, deleted, disrupted or destroyed by the access. It also addresses aggregation of separate incidents within the stated course-of-conduct conditions.
That definition does not create a freestanding civil remedy for every investigation bill. An alleged offense, qualifying loss and the provision in which the definition operates must be assessed. Do not copy California's civil-remedy wording into a Michigan summary.
This installment does not complete the separate civil-remedies or penalty analysis. Its purpose is to make the access and service-use questions visible without inventing conclusions.
Proof: apply the described SCOUTz boundaries
SCOUTz's free domain review relies on public records and passive enumeration, as described by the team. Reports state that indexed means publicly discoverable and that no request was sent to verify the indexed observation.
The deeper Microsoft 365 assessment follows prospect authorization and full sign-up through a permission-based connection. The team describes read-only access without content reads, exploit checks, brute-forcing or authentication testing.
Those facts distinguish the workflow from an intrusive test. They do not establish an exception for every Michigan interaction or use of information. Confirm which collectors operate, what permissions were approved and who receives the resulting evidence.
Practical review boundaries
Maintain an approved-method inventory. Any change from reading a source index to verifying its targets should trigger a new review. The collection behavior has changed even if the report uses the same labels.
Before protected access, confirm the organization, tenant, authorizing person, requested permissions and assessment purpose. A successful technical connection is not an unlimited grant for unrelated use.
After an objection, suspend disputed direct activity and retain the request and permission records. These are suggested controls, not a claim that every public lookup requires written consent under Michigan law.
What remains unresolved
This article reviews §§ 752.792 and 752.795 from the official source. It does not settle the interpretation of every related definition or exception, identify a controlling decision for SCOUTz's exact methods, or complete civil and jurisdictional analysis.
Counsel should review the full applicable framework and the actual request inventory. Assess commercial-email and advertising requirements separately from computer access.
FAQ
Does Michigan law concern only destructive hacking?
No. Section 752.795(a) includes acquisition and computer-service use within its intentional unauthorized-access framework.
What does Michigan's access definition include?
Section 752.792(1) includes communicating with and otherwise using computer resources, among other acts.
Does every public request become an offense?
No such conclusion is established here. The conduct elements, authorization and applicable interpretations need review.
Does a verification expense automatically create a civil claim?
Not from the aggregate-amount definition alone. The alleged offense, qualifying loss and possible civil remedies need separate analysis.
Can an MSP call indexed evidence a current exposure?
Not without support for that conclusion. Keep the index source, date and verification limit visible.
Is this Michigan legal clearance for SCOUTz?
No. It is preliminary statutory research with related provisions, decisions and method-specific application still requiring review.
One last thing
The most useful assurance is a reproducible fact: this source was queried, this evidence was returned and this prospect resource was not contacted for verification. A broad harmless label cannot replace that record.
Use the methods guide to distinguish source use from direct target requests, and the state index to see research limits. The permission overview separates collection from outreach. SCOUTz's methodology preserves evidence states. Compare Michigan's service-use focus with Massachusetts's notice and continuation language.
Does Michigan's loss definition settle a federal claim?
No. 18 U.S.C. § 1030(e)(11), (g) supplies a separate federal loss definition and conditional civil remedy. Section 1030(a)(2)(C), (a)(5) still requires its particular conduct elements. A service-use concern or verification expense does not automatically establish them.
The federal source is the official 2024 edition, effective January 6, 2025; current-2026 comparison remains pending. DOJ Justice Manual § 9-48.000 C is charging guidance, not immunity from a Michigan or federal civil claim.
Sources
Statutes: official MCL §§ 752.792(1)–(2), 752.795(a)–(b), linked near claims. The official source was consulted October 6, 2026; consultation alone is not an exhaustive amendment reconciliation. Federal § 1030(e)(11), (g), (a)(2)(C), (a)(5) uses the dated official edition above.
Court decisions: no holding is asserted; decisions interpreting service use and related loss remain pending.
Agency guidance: DOJ Justice Manual § 9-48.000, not a research immunity.
Product sources: SCOUTz methodology and the team's description. Sources consulted October 6, 2026; related exceptions, exhaustive amendment comparison, civil and jurisdictional analysis and exact-method clearance remain incomplete.
