TenantIQ

Getting started with TenantIQ

Connecting your Microsoft 365 tenant takes about five minutes. TenantIQ only reads your data — it never changes anything in Microsoft 365 or Azure.

1. Approve TenantIQ (Global Administrator, once)

A Global Administrator approves TenantIQ for your organization. Open the link below, sign in with your admin account, review the permissions and click Accept.

Approve TenantIQ for my organization ↗

If we add a permission later, we'll ask you to open this link again so new features work for you.

2. Sign in

Go to tenantiq.tech/login and sign in with your work Microsoft 365 account (personal Outlook or Hotmail accounts aren't supported). Only Global Administrators and Global Readers can open the dashboard, because it shows organization-wide data. To give a colleague read-only access, assign them the Global Reader role in the Microsoft Entra admin center.

New organizations are reviewed before activation — you'll see “Pending approval” until then. Paid plans are activated automatically.

3. Run your first sync

Click Start First Sync. It usually takes under a minute. After that, TenantIQ syncs automatically every night (2:00 AM UTC), and you can click Sync Now any time.

4. Show real names in usage reports (important)

By default Microsoft 365 hides user names in usage reports. TenantIQ then can't tell who is inactive, so inactive-license waste isn't counted. To fix it, a Global Administrator opens Microsoft 365 admin center → Settings → Org settings → Reports, unticks “Display concealed user, group, and site names in all reports”, saves, and clicks Sync Now in TenantIQ. TenantIQ shows a reminder banner until this is done.

5. Azure Cost (Enterprise plan, optional)

To see Azure spending, give TenantIQ read access to cost data on each Azure subscription:

  1. Azure portal → Subscriptions → select the subscription → Access control (IAM)
  2. Add → Add role assignment → choose Cost Management Reader (the plain Reader role isn't enough)
  3. Members → User, group, or service principal → search for TenantIQ → Review + assign

Repeat for each subscription, then click Sync Now. Azure cost data can lag by up to 24 hours.

What needs which Microsoft license

Some views depend on Microsoft products your organization may not have. TenantIQ shows these as “unavailable” — never as a false all-clear.

License, waste, users, subscriptionsAny Microsoft 365 business or enterprise plan
MFA coverageWorks on every plan (full registration report with Entra ID P1)
Self-service password reset statusEntra ID P1 — included in Microsoft 365 Business Premium, E3, E5
Risky users, risky sign-ins, PIMEntra ID P2 — included in Microsoft 365 E5
Defender alerts and incidentsMicrosoft Defender — Defender for Business is included in Business Premium; Defender for Office 365 / Endpoint in E5
DevicesMicrosoft Intune — included in Business Premium, E3, E5
Azure CostAn Azure subscription plus the role assignment in step 5

Permissions TenantIQ requests

All are read-only.

User.Read (delegated)Sign you in
Directory.Read.AllUsers, groups, admin roles, devices and subscriptions
Organization.Read.AllYour organization's name and purchased licenses
Reports.Read.AllMicrosoft 365 usage activity — who is actually using their licenses
AuditLog.Read.AllMFA and password-reset registration report
UserAuthenticationMethod.Read.AllMFA status per user when you don't have Entra ID P1
Policy.Read.AllConditional Access, security defaults and authentication policies
Policy.Read.PermissionGrantWhether users can consent to apps themselves
Application.Read.AllExpiring app secrets and certificates
SecurityEvents.Read.AllMicrosoft Secure Score and its improvement actions
SecurityAlert.Read.AllMicrosoft Defender alerts
SecurityIncident.Read.AllMicrosoft Defender incidents
IdentityRiskyUser.Read.AllUsers flagged as risky by Identity Protection (Entra ID P2)
IdentityRiskEvent.Read.AllRisky sign-ins detected by Identity Protection (Entra ID P2)
RoleEligibilitySchedule.Read.DirectoryPrivileged Identity Management eligible roles (Entra ID P2)
DeviceManagementManagedDevices.Read.AllIntune device inventory and compliance
DeviceManagementConfiguration.Read.AllIntune compliance policies
DeviceManagementApps.Read.AllIntune app protection policies (iOS / Android)
SharePointTenantSettings.Read.AllSharePoint external sharing level
MultiTenantOrganization.Read.AllMulti-tenant organizations and MSP setups

Removing TenantIQ

Delete TenantIQ under Microsoft Entra admin center → Enterprise applications to revoke access instantly, then email us to delete your stored data (see our Privacy Policy).

Questions? Email support@tenantiq.tech.