Nothing gets installed in your environment and nothing gets changed in it. The monitoring reads official Microsoft APIs from our platform – and you revoke our access in one click, whenever you decide.
No agent, no app to install, no server at your place. If EasyCare 365 ended tomorrow, nothing of ours would be left in your tenant but a line in the audit log.
The monitoring holds read permissions only and signs in with a certificate, not a password. It couldn't change anything even if it wanted to. Changes are made by people, through a separate account.
We collect configuration states, metrics and events. Never documents, e-mails, messages or passwords – we technically cannot reach them.
You can see our application in your tenant among the enterprise applications. Deleting it ends access to Microsoft 365 and Azure at once – you don't need our cooperation for it.
We don't work around anything and we don't guess. When you aren't licensed for a given signal, we say so – and that in itself is a finding, because then you can't see those risks either.
Collector functions run on a timer in our Azure subscription, West Europe region.
Events and metrics over time. Queries and alert rules are written on top of them.
Configuration snapshots, baselines and the registry of managed tenants.
Certificate private keys. Authentication by certificate, not password.
Our own front-end for the team – tenant traffic lights, the finding queue, drift approval.
An instant domain check right here on the page, a full tenant audit within 48 hours. Nothing to install, no commitment — and you can revoke our access afterwards.