Admin access, handled like it matters.
TenantWard works inside your Microsoft 365 or Google Workspace. This page lists every permission it asks for and why, how changes are kept safe, and what happens to your data.
Checks are read-only
A Microsoft 365 check signs in with your own admin account. Microsoft shows these permissions on its consent screen before you approve, and you can remove the app any time from Entra › Enterprise applications.
| Permission | Why |
|---|---|
| Directory.Read.All | Users, groups, admin roles, licenses and app consents, so checks can name who has what. |
| Policy.Read.All | Security defaults, Conditional Access and user permission settings. |
| AuditLog.Read.All | Each person's last sign-in and MFA registration status. |
| SecurityEvents.Read.All | Microsoft Secure Score, shown alongside our own checks. |
| SharePointTenantSettings.Read.All | How far files can be shared outside the company. |
| DeviceManagementManagedDevices.Read.All | Whether managed devices are compliant and encrypted. |
| Exchange.Manage (read cmdlets only) | Mailbox forwarding, inbox rule definitions, outbound policies and audit settings. Never message contents. |
Google Workspace checks are read-only too
A Google Workspace check signs in with a super admin account. Google lists these read-only permissions before you approve. The token stays in your browser, expires within the hour, and is never sent to our servers.
| Permission | Why |
|---|---|
| admin.directory.user.readonly | Users, admins, 2-Step Verification status and last sign-in, so checks can name who's exposed. |
| admin.directory.domain.readonly | Your domains, so each one gets its email and domain checks. |
| admin.directory.customer.readonly | Your organization's name and primary domain. |
| admin.reports.audit.readonly | The last 30 days of sign-in alerts and third-party app approvals. Never message or file contents. |
| cloud-identity.policies.readonly | Security settings: 2-Step Verification enforcement, Drive sharing, Gmail forwarding. |
Changes ask for permission only when you make one
Write permissions are never part of the first sign-in. When you approve a specific change, Microsoft asks for just the permission that change needs, and the change runs in your browser with your own sign-in. Exchange commands go through our relay, which accepts only a fixed list of commands and parameters.
| Permission | Why |
|---|---|
| User.ReadWrite.All | Block or allow sign-in, sign people out, add people, change licenses. |
| User-PasswordProfile.ReadWrite.All | Set a temporary password when you reset one. |
| UserAuthenticationMethod.ReadWrite.All | Remove sign-in methods when you reset someone's MFA. |
| GroupMember.ReadWrite.All | Add or remove people from groups and Teams. |
| Policy.ReadWrite.ConditionalAccess / .Authorization | Turn on security defaults, create report-only sign-in policies, restrict app approval. |
| DelegatedPermissionGrant.ReadWrite.All | Revoke an outside app's access when you choose to. |
| SharePointTenantSettings.ReadWrite.All | Tighten external sharing when you choose to. |
| Exchange.Manage (approved write cmdlets) | Mailbox type, forwarding, automatic replies, mailbox access, outbound forwarding policy, the External tag. |
24/7 monitoring is a separate, read-only approval
If a Global Administrator turns on monitoring, they approve these read-only application permissions for the tenant. Our server then checks every 15 minutes and stores only the alerts it raises and the countries each person normally signs in from.
| Permission | Why |
|---|---|
| AuditLog.Read.All | Directory changes and sign-ins, every 15 minutes. |
| Directory.Read.All | To resolve who an alert is about. |
| MailboxSettings.Read | Inbox rule definitions, to catch rules that forward or hide mail. |
| User.Read.All | To list the mailboxes to watch. |
Automatic incident response is opt-in and narrow
If you choose to let TenantWard contain a hijacked account automatically, a Global Administrator approves a separate app with only these permissions. It can’t read mail, reset passwords or delete anything. You choose the triggers and actions, name people it must never lock, and set a limit on how many accounts it can lock in an hour. Global Administrators are never blocked automatically, and every action can be reversed from the incident.
| Permission | Why |
|---|---|
| User.EnableDisableAccount.All | Block sign-in for an account that looks taken over, and restore it. |
| User.RevokeSessions.All | End every open session, so a stolen session stops working. |
| MailboxSettings.ReadWrite | Switch off (never delete) an inbox rule that forwards or hides mail. |
How changes stay safe
- Every change is a fixed, tested script from TenantWard’s catalog. Nothing outside the catalog can run.
- Each change is graded routine, careful, disruptive or restricted, and shows what will change, who’s affected, what might stop working and how to undo it.
- The current settings are backed up before every change. If the backup fails, nothing runs.
- After a change, TenantWard reads the setting again to confirm it took effect.
- New sign-in policies are created in report-only mode first. Disruptive changes need you to confirm you’ve read the rollback plan. Restricted changes, such as deleting accounts, are never one-click.
- Every change is recorded with who approved it and when, and most can be undone in one click.
- Where TenantWard uses AI, it explains and drafts for a person to review. It never writes or runs a change.
Your data
- We store check results, findings and their history, the change history, settings backups and the people list from your last check. Only members of your workspace can read them, enforced by row-level security in the database.
- We never read or store the contents of email, files, calendars or chats.
- We never store Microsoft tokens. Temporary passwords are shown once and never saved.
- Data is encrypted in transit and at rest with our hosting providers (Vercel for the app, Supabase for the database).
- Remove a client or asset any time. To close your account and erase everything, contact us.
Audits
TenantWard is in early access and has not yet completed an independent audit such as SOC 2. We’ll publish the report here once it exists. Our checks follow public standards, including the CIS Microsoft 365 benchmark and CISA’s secure configuration baselines.
Found a security issue? Please tell us before disclosing it publicly. See also our privacy page.