Privacy
What we store
Your account, your workspace, the clients and assets you add, and the results of each check: scores, findings, their history and the notes and decisions your team records. This is what makes trends, verification of fixes and a shared queue possible. Only members of your workspace can read it.
Microsoft 365 checks
Checks run with your own Microsoft sign-in and read-only permissions. They read tenant settings, role assignments, app consent grants, license counts, SharePoint sharing settings, device compliance, and each user's sign-in and MFA registration status. Exchange checks read mailbox forwarding settings, inbox rule definitions, mail flow rules and audit configuration by relaying a fixed list of read-only commands through our server to Microsoft; your token is used for that request only and never stored. Checks never read the contents of email, files, calendars or chats, never see passwords, and change nothing. The resulting findings and user list are saved to your workspace.
Fixes, onboarding and offboarding
Changes happen only when a member of your workspace reviews them and presses approve. Microsoft then asks that person to sign in and grant the specific permission the change needs; the change runs with their token in their browser (Exchange changes are relayed through our server the same way as checks). Tokens are never stored. We record what was changed, by whom and when, so it can be reviewed and, where possible, undone.
24/7 monitoring
If a Global Administrator turns on monitoring, they approve a separate, read-only app permission for the tenant. Every 15 minutes our server reads directory audit events, sign-in locations and inbox rule definitions, and stores only the alerts it raises plus a list of countries each person has signed in from. It never reads message contents. Remove it any time from Entra › Enterprise applications.
Mailbox investigations
An investigation reads sign-in history, mailbox settings, message trace and the audit log for the mailbox you choose, using your own sign-in. It lists the IDs of messages accessed from suspicious locations but never opens their contents. Results stay in your browser unless you export them.
Domain checks
Our server reads the domain's public DNS records, its website certificate and its public registry entry. Nothing private is involved.
Removing data
Remove a client or asset from your workspace at any time. To close your account and erase everything, contact us and we'll delete it.
TenantWard is in early access. This page will be expanded into a full privacy policy before general availability.