Admin access, handled like it matters.

TenantWard works inside your Microsoft 365 or Google Workspace. This page lists every permission it asks for and why, how changes are kept safe, and what happens to your data.

Checks are read-only

A Microsoft 365 check signs in with your own admin account. Microsoft shows these permissions on its consent screen before you approve, and you can remove the app any time from Entra › Enterprise applications.

PermissionWhy
Directory.Read.AllUsers, groups, admin roles, licenses and app consents, so checks can name who has what.
Policy.Read.AllSecurity defaults, Conditional Access and user permission settings.
AuditLog.Read.AllEach person's last sign-in and MFA registration status.
SecurityEvents.Read.AllMicrosoft Secure Score, shown alongside our own checks.
SharePointTenantSettings.Read.AllHow far files can be shared outside the company.
DeviceManagementManagedDevices.Read.AllWhether managed devices are compliant and encrypted.
Exchange.Manage (read cmdlets only)Mailbox forwarding, inbox rule definitions, outbound policies and audit settings. Never message contents.

Google Workspace checks are read-only too

A Google Workspace check signs in with a super admin account. Google lists these read-only permissions before you approve. The token stays in your browser, expires within the hour, and is never sent to our servers.

PermissionWhy
admin.directory.user.readonlyUsers, admins, 2-Step Verification status and last sign-in, so checks can name who's exposed.
admin.directory.domain.readonlyYour domains, so each one gets its email and domain checks.
admin.directory.customer.readonlyYour organization's name and primary domain.
admin.reports.audit.readonlyThe last 30 days of sign-in alerts and third-party app approvals. Never message or file contents.
cloud-identity.policies.readonlySecurity settings: 2-Step Verification enforcement, Drive sharing, Gmail forwarding.

Changes ask for permission only when you make one

Write permissions are never part of the first sign-in. When you approve a specific change, Microsoft asks for just the permission that change needs, and the change runs in your browser with your own sign-in. Exchange commands go through our relay, which accepts only a fixed list of commands and parameters.

PermissionWhy
User.ReadWrite.AllBlock or allow sign-in, sign people out, add people, change licenses.
User-PasswordProfile.ReadWrite.AllSet a temporary password when you reset one.
UserAuthenticationMethod.ReadWrite.AllRemove sign-in methods when you reset someone's MFA.
GroupMember.ReadWrite.AllAdd or remove people from groups and Teams.
Policy.ReadWrite.ConditionalAccess / .AuthorizationTurn on security defaults, create report-only sign-in policies, restrict app approval.
DelegatedPermissionGrant.ReadWrite.AllRevoke an outside app's access when you choose to.
SharePointTenantSettings.ReadWrite.AllTighten external sharing when you choose to.
Exchange.Manage (approved write cmdlets)Mailbox type, forwarding, automatic replies, mailbox access, outbound forwarding policy, the External tag.

24/7 monitoring is a separate, read-only approval

If a Global Administrator turns on monitoring, they approve these read-only application permissions for the tenant. Our server then checks every 15 minutes and stores only the alerts it raises and the countries each person normally signs in from.

PermissionWhy
AuditLog.Read.AllDirectory changes and sign-ins, every 15 minutes.
Directory.Read.AllTo resolve who an alert is about.
MailboxSettings.ReadInbox rule definitions, to catch rules that forward or hide mail.
User.Read.AllTo list the mailboxes to watch.

Automatic incident response is opt-in and narrow

If you choose to let TenantWard contain a hijacked account automatically, a Global Administrator approves a separate app with only these permissions. It can’t read mail, reset passwords or delete anything. You choose the triggers and actions, name people it must never lock, and set a limit on how many accounts it can lock in an hour. Global Administrators are never blocked automatically, and every action can be reversed from the incident.

PermissionWhy
User.EnableDisableAccount.AllBlock sign-in for an account that looks taken over, and restore it.
User.RevokeSessions.AllEnd every open session, so a stolen session stops working.
MailboxSettings.ReadWriteSwitch off (never delete) an inbox rule that forwards or hides mail.

How changes stay safe

  • Every change is a fixed, tested script from TenantWard’s catalog. Nothing outside the catalog can run.
  • Each change is graded routine, careful, disruptive or restricted, and shows what will change, who’s affected, what might stop working and how to undo it.
  • The current settings are backed up before every change. If the backup fails, nothing runs.
  • After a change, TenantWard reads the setting again to confirm it took effect.
  • New sign-in policies are created in report-only mode first. Disruptive changes need you to confirm you’ve read the rollback plan. Restricted changes, such as deleting accounts, are never one-click.
  • Every change is recorded with who approved it and when, and most can be undone in one click.
  • Where TenantWard uses AI, it explains and drafts for a person to review. It never writes or runs a change.

Your data

  • We store check results, findings and their history, the change history, settings backups and the people list from your last check. Only members of your workspace can read them, enforced by row-level security in the database.
  • We never read or store the contents of email, files, calendars or chats.
  • We never store Microsoft tokens. Temporary passwords are shown once and never saved.
  • Data is encrypted in transit and at rest with our hosting providers (Vercel for the app, Supabase for the database).
  • Remove a client or asset any time. To close your account and erase everything, contact us.

Audits

TenantWard is in early access and has not yet completed an independent audit such as SOC 2. We’ll publish the report here once it exists. Our checks follow public standards, including the CIS Microsoft 365 benchmark and CISA’s secure configuration baselines.

Found a security issue? Please tell us before disclosing it publicly. See also our privacy page.