Start here
Before you sign in with Microsoft
Consent screens are the moment of maximum doubt, so here is the whole sequence in advance — what we ask for, what we do with it, and how to remove us.
The free health check asks for read access only. We cannot change anything in your directory — not by accident, and not if we wanted to.
The sequence
Four steps, in this order.
01
You consent to read-only access
A global administrator approves the application. The permissions are listed before you click, and they are read-only: we can list users, groups, devices, licenses and sign-in dates. We cannot create, change or delete anything.
02
We read the directory
The read runs against Microsoft Graph and takes minutes, not days. Nothing is written back. We store identifiers, role and access assignments, and the findings — not a copy of your directory.
03
You get your first report
Ghost accounts, unused licenses with their monthly cost, data quality issues and duplicate devices — each finding with the evidence behind it. That is what free delivers, permanently. There is no trial clock.
Open the sample report and click through it →04
Every finding shows its work
Click a finding and you get the named accounts, the sign-in events behind them, the exact rule that produced it, and what closing it releases in licenses and money.
Read and write are two separate acts.
Nothing in the free plan can change your directory. The day you want the platform to execute orders — create an account, assign a license, close an offboarding — you grant a second, separate consent, and you see exactly what it adds before you approve it.
How to remove us again
Entra portal → Enterprise applications → Entra Logic → Properties → Delete.
Access ends immediately. Data we have read is deleted within 30 days, or right away if you ask.
We put this here so you know it before you start, not so you have to go looking for it afterwards.