Technology

What it's built on

Nothing gets installed in your environment and nothing gets changed in it. The monitoring reads official Microsoft APIs from our platform – and you revoke our access in one click, whenever you decide.

How we choose

Four rules we don't bend

Agent-less

No agent, no app to install, no server at your place. If EasyCare 365 ended tomorrow, nothing of ours would be left in your tenant but a line in the audit log.

Read-only

The monitoring holds read permissions only and signs in with a certificate, not a password. It couldn't change anything even if it wanted to. Changes are made by people, through a separate account.

Configuration, not content

We collect configuration states, metrics and events. Never documents, e-mails, messages or passwords – we technically cannot reach them.

Revocable without us

You can see our application in your tenant among the enterprise applications. Deleting it ends access to Microsoft 365 and Azure at once – you don't need our cooperation for it.

We build on nothing you have to have installed, and on nothing that could only be switched off through us.
Where we read from

Data sources – always official Microsoft interfaces

We don't work around anything and we don't guess. When you aren't licensed for a given signal, we say so – and that in itself is a finding, because then you can't see those risks either.

Identity and access
  • Microsoft Graph – directory and roles Who holds admin rights, how they change, whether PIM is running.
  • Conditional Access policies A snapshot of the whole set and a diff against the approved state.
  • Sign-in methods and MFA How many people are actually protected, and by what.
  • Identity Protection Risky accounts and sign-ins – where the customer is licensed for it.
Security and audit
  • Microsoft Secure Score A daily value and a trend, not just a snapshot.
  • Office 365 Management Activity API Unified audit log: admin changes, sharing, app consents.
  • App governance New consents, apps with high privileges, expiring secrets.
  • Microsoft Defender for Cloud Recommendations and score on the Azure side.
Collaboration and data
  • SharePoint Online admin API Per-site sharing configuration, anonymous links.
  • Graph reports Activity and usage – Teams, OneDrive, mailboxes.
  • Guests and external accounts An inventory, and accounts that haven't signed in for a long time.
Operations and Microsoft changes
  • Service Health Incidents that affect your tenant specifically.
  • Message Center Upcoming changes – we filter them by impact on you.
Licences and cost
  • Graph – assigned licences Inactive licensed accounts, waste, approaching expirations.
  • Azure Cost Management and Advisor Cost anomalies and orphaned resources. The “+ Azure” module.
Devices and mail
  • Microsoft Intune Device compliance with policies. Optional module.
  • Public DNS SPF, DKIM, DMARC, MX, DNSSEC, CAA – the only thing readable without consent.
Where it runs

Our side – and where your data sits

Azure Functions

Collector functions run on a timer in our Azure subscription, West Europe region.

Log Analytics

Events and metrics over time. Queries and alert rules are written on top of them.

Blob and Table Storage

Configuration snapshots, baselines and the registry of managed tenants.

Azure Key Vault

Certificate private keys. Authentication by certificate, not password.

Mission control

Our own front-end for the team – tenant traffic lights, the finding queue, drift approval.

Access to your tenantread-only
WhereYour Entra ID → Enterprise applications
WhatOur service principal, read permissions
HowCertificate, key in our Key Vault
DataAzure West Europe, never leaves the EU
EndDelete the app → access ends immediately
The whole access is visible and it's in your hands – not ours.
WHAT WE NEVER DO We don't build on a custom search schema or on anything that would be left behind in your tenant. No machine writes, no content, no data outside the EU.

Start with a free audit

An instant domain check right here on the page, a full tenant audit within 48 hours. Nothing to install, no commitment — and you can revoke our access afterwards.