The list
Everything the platform does, in one long list.
31 features, grouped by what you are trying to get done, each with a description that tells you what it actually is. The ones marked in the free plan need read-only access and nothing else.

See your directory
Everything in this group runs on read-only access. Nothing is changed, and you can remove the app in four clicks.
Free health check
In the free planA scored report on your tenant, about ten minutes after consent.
Sign in with Microsoft, approve read access, and the platform counts what is actually in the directory: users, groups, devices, licenses and sign-in activity. The result is a score out of 100 with the findings behind it, not a PDF someone wrote about you. You can rerun it whenever you want.
Ghost account detection
In the free planAccounts still enabled after the person left.
Leaving dates get recorded in HR and never reach the directory. The report lists every account that is still enabled with no recent sign-in, together with the last sign-in date, the groups it still belongs to and the licenses still assigned to it.
Unused license cost
In the free planWhat you pay each month for licenses nobody signs in with.
Assigned licenses are matched against actual sign-in activity and priced per month. The number is the one you can take to a budget meeting: this many seats, this much money, these people. Removing them is a one-click order once you upgrade — the reading of them is free.
Data quality findings
In the free planMissing managers, empty departments, inconsistent naming.
Every rule you might want to automate later depends on attributes being present and consistent. The platform grades the attributes that matter — manager, department, company, employee ID, usage location — and shows you which records break them before you build anything on top.
Device and duplicate review
In the free planThree device registries, no synchronization between them.
Entra ID, Intune and Autopilot each keep their own list, and after five years of Microsoft 365 they disagree. The review lines them up, flags stale and duplicated records, and proposes the ones safe to clean up.
Findings with the evidence attached
In the free planEvery finding opens on the objects behind it.
A finding you cannot verify is an opinion. Each one opens on the exact accounts, groups or devices that triggered it, with the Graph properties used to decide, so your own admin can check the claim in the portal in a minute.
Orders and approvals
The order is the change. A manager describes what they need, an approver sees the exact effect and the cost, and the platform executes it.
New employee orders
Paid planOne form: role, company, start date, access package.
The line manager fills in what they already know, and the platform derives the rest — account, groups, licenses, device policy, mailbox. There is no retyping into a second system, because the request and the execution are the same record.
Offboarding that finishes
Paid planDisable, revoke sessions, strip licenses, handle devices, close the record.
Disabling an account blocks new sign-ins and nothing else. The offboarding order runs the full sequence Microsoft documents as separate steps — session revocation, group removals, license removals, device deactivation, mailbox handling — and does not close until each one has reported back.
Approval with the effect shown
Paid planThe approver sees the change, the reason and the monthly cost.
Approvers are asked to approve an outcome, not a ticket title. The screen shows the concrete change, who asked, the sentence of justification they wrote, and what it adds to the monthly bill. Approvals are logged with all of it attached.
Self-service catalogue
Paid planWhat employees may ask for, and who decides.
Access packages, applications, licenses and equipment are published as a catalogue with an owner and an approval route each. If nobody owns it, it is not in the catalogue — which turns out to be the fastest way to find the access nobody has been responsible for.
Order queue
Paid planEvery open order, across every tenant, in one list.
Type, requester, tenant, status, age and assignee in a single view. Ageing orders surface on their own instead of waiting for someone to ask about them in a status meeting.
Employee app
Paid planRequests, approvals, equipment and licenses on the phone.
Approvers approve from the phone, employees see what they have and what they have asked for, and relevant organisational contact lists can be synchronised to the phone's own address book for anyone who opts in.
Rights and delegation
Zero standing rights for people. The platform holds the permissions, and it can only do what an approved order asks for.
No standing admin rights
Paid planNobody keeps a permanent Global Administrator role.
The right moves from twelve people who can do anything at any time to one service that can only execute approved orders. Break-glass accounts stay where they belong, documented and monitored, rather than being the everyday way of working.
Access rules matrix
Paid planWho may request, who approves, what is written down.
Rules are expressed per company, department and order type, and the matrix shows the whole thing on one screen. When someone asks why a request went to a particular approver, you can point at the row.
Delegation without portal access
Paid planService desk and local IT get scope, not roles.
Instead of handing out administrative units and custom roles in the Entra portal, delegation is expressed in the order model: this group may run these order types for these companies. They never sign into the portal, so there is nothing to misconfigure there.
Permission transparency
In the free planEvery Graph permission listed, graded and explained.
You can see exactly which Microsoft Graph permissions the app holds, why each is needed and what it is used for. Read consent and write consent are separate steps, and you can live on read-only for as long as you like.
Access review with a decision attached
Paid planReviewers keep or remove, and the removals become one order.
A review lists every member of a group with when they were added and when they last used the access, and flags the ones that should not be there at all — an account still active after its leaving date, for instance. Decisions create one access change order when the review completes, so nothing is removed before it has been approved.
The audit trail you thought you had
Paid planRequest, reason, approval and result in one record.
Entra ID logs that a change happened and who was signed in. It cannot log why, because nobody told it. Each order keeps the decision and the execution together, so an auditor's question is answered by opening one record rather than correlating three systems.
Groups and multi-tenant
Built for organisations with more than one tenant — after an acquisition, or as a service provider with a hundred clients.
One console, many tenants
Paid planSwitch tenant without switching browser profile.
Every connected tenant with its identity count in one list, one sign-in. No guest accounts in client directories, no separate admin identity per customer, no browser profile per client.
Standards across tenants
Paid planThe same order types and rules everywhere.
Order types, approval routes and naming conventions are defined once and applied to every tenant that should have them, with per-tenant exceptions where reality requires them. New acquisitions get the standard on day one instead of in the consolidation project that never finishes.
IT chargeback
Paid planCost allocated per company, per period.
Licenses and services are attributed to the company that consumes them, so the internal invoice is produced from the directory rather than from a spreadsheet someone maintains. Group hygiene stops being only an access problem and becomes budget control.
Connected business applications
Paid planWhat is attached to the tenant, and who owns it.
Enterprise applications, their consented permissions and their owners in one overview per tenant. Applications with high-privilege consent and no owner are the ones you want to know about before someone else finds them.
Licenses and AI spend
Seat licenses are a fixed cost you can see. AI credits are a metered cost you mostly can't. This group is about attributing both to the company that actually consumes them.
License metering and billing
Paid planSeat products metered, entitled and billed per company.
Copilot, Visio and other seat-based add-ons are attributed to the company using them — entitlement, usage and billing in the same ledger that already runs the identities behind the cost. The internal invoice comes from the directory, not from a spreadsheet someone maintains in April.
AI credits across vendors
Paid planAI usage credits allocated per company — also outside Microsoft.
Microsoft meters Copilot credits inside its own billing. Other AI vendors meter theirs inside their own. Entra Logic allocates AI usage credits to companies and cost centers in one ledger, across vendors, alongside licenses and chargeback — one AI cost line per company instead of one per vendor.
Copilot credit allocation
PlannedPlanned: Copilot credit budgets per company.
Microsoft's spending policies assign Copilot credit budgets through security groups only — so the budget control is exactly as good as the group hygiene underneath it. We plan to allocate Copilot credits per company and per tenant on top of that model, in the same ledger as the rest of this group. This is planned, not shipped. This line changes when it ships.
Automation
Rules replace the scripts that one person wrote and nobody else understands.
Automation rules
Paid planA trigger, a condition, an action, a log line.
Rules are built in the interface, versioned, and run under the platform's identity rather than a service account with a password in a text file. Every run is logged with what it changed and what it skipped.
Replacing script debt
Paid planRetire the PowerShell that runs on somebody's laptop.
Scheduled scripts, service accounts with standing rights and key-person knowledge are the usual state after a few years of Microsoft 365. Rules cover the recurring parts of that work with an owner, an audit trail and a way to turn them off.
HR and joiner-mover-leaver triggers
Paid planChanges in role, company or manager start the right order.
A move is not a new hire and not a leaver, and it is the case most organisations handle worst. Movers generate an order that both grants and removes, with the removals made explicit so the approver has to look at them.
Running it
The unglamorous parts that decide whether a platform survives its first year.
Self-service onboarding
In the free planConsent, read, report. No form and no call.
The whole start is a Microsoft sign-in and a consent screen you can read. If it does not convince you, you close the tab and nobody phones you about it.
Plan and billing in the product
Paid planIdentity count, current plan, cancel yourself.
Pricing is per managed identity with volume steps, shown against your real number rather than a range. Upgrading and cancelling are both buttons in the product.
Removal in four clicks
In the free planEntra portal → Enterprise applications → Entra Logic → Delete.
Access ends immediately. Data we have read is deleted within 30 days, or right away if you ask. This is written on the pages you read before you start, not in a support article you find afterwards.
EU data handling
In the free planEuropean hosting, a data processing agreement, named sub-processors.
The agreement and the sub-processor list are downloadable without a sales conversation, because the people who have to review them are not the people who buy.
The fastest way to check the list is against your own tenant.
Read-only access, about ten minutes, no form and no call. Everything marked as free above is running before you have spoken to anyone here.