Getting started with TenantIQ
Connecting your Microsoft 365 tenant takes about five minutes. TenantIQ only reads your data — it never changes anything in Microsoft 365 or Azure.
1. Approve TenantIQ (Global Administrator, once)
A Global Administrator approves TenantIQ for your organization. Open the link below, sign in with your admin account, review the permissions and click Accept.
Approve TenantIQ for my organization ↗If we add a permission later, we'll ask you to open this link again so new features work for you.
2. Sign in
Go to tenantiq.tech/login and sign in with your work Microsoft 365 account (personal Outlook or Hotmail accounts aren't supported). Only Global Administrators and Global Readers can open the dashboard, because it shows organization-wide data. To give a colleague read-only access, assign them the Global Reader role in the Microsoft Entra admin center.
New organizations are reviewed before activation — you'll see “Pending approval” until then. Paid plans are activated automatically.
3. Run your first sync
Click Start First Sync. It usually takes under a minute. After that, TenantIQ syncs automatically every night (2:00 AM UTC), and you can click Sync Now any time.
4. Show real names in usage reports (important)
By default Microsoft 365 hides user names in usage reports. TenantIQ then can't tell who is inactive, so inactive-license waste isn't counted. To fix it, a Global Administrator opens Microsoft 365 admin center → Settings → Org settings → Reports, unticks “Display concealed user, group, and site names in all reports”, saves, and clicks Sync Now in TenantIQ. TenantIQ shows a reminder banner until this is done.
5. Azure Cost (Enterprise plan, optional)
To see Azure spending, give TenantIQ read access to cost data on each Azure subscription:
- Azure portal → Subscriptions → select the subscription → Access control (IAM)
- Add → Add role assignment → choose Cost Management Reader (the plain Reader role isn't enough)
- Members → User, group, or service principal → search for TenantIQ → Review + assign
Repeat for each subscription, then click Sync Now. Azure cost data can lag by up to 24 hours.
What needs which Microsoft license
Some views depend on Microsoft products your organization may not have. TenantIQ shows these as “unavailable” — never as a false all-clear.
| License, waste, users, subscriptions | Any Microsoft 365 business or enterprise plan |
| MFA coverage | Works on every plan (full registration report with Entra ID P1) |
| Self-service password reset status | Entra ID P1 — included in Microsoft 365 Business Premium, E3, E5 |
| Risky users, risky sign-ins, PIM | Entra ID P2 — included in Microsoft 365 E5 |
| Defender alerts and incidents | Microsoft Defender — Defender for Business is included in Business Premium; Defender for Office 365 / Endpoint in E5 |
| Devices | Microsoft Intune — included in Business Premium, E3, E5 |
| Azure Cost | An Azure subscription plus the role assignment in step 5 |
Permissions TenantIQ requests
All are read-only.
| User.Read (delegated) | Sign you in |
| Directory.Read.All | Users, groups, admin roles, devices and subscriptions |
| Organization.Read.All | Your organization's name and purchased licenses |
| Reports.Read.All | Microsoft 365 usage activity — who is actually using their licenses |
| AuditLog.Read.All | MFA and password-reset registration report |
| UserAuthenticationMethod.Read.All | MFA status per user when you don't have Entra ID P1 |
| Policy.Read.All | Conditional Access, security defaults and authentication policies |
| Policy.Read.PermissionGrant | Whether users can consent to apps themselves |
| Application.Read.All | Expiring app secrets and certificates |
| SecurityEvents.Read.All | Microsoft Secure Score and its improvement actions |
| SecurityAlert.Read.All | Microsoft Defender alerts |
| SecurityIncident.Read.All | Microsoft Defender incidents |
| IdentityRiskyUser.Read.All | Users flagged as risky by Identity Protection (Entra ID P2) |
| IdentityRiskEvent.Read.All | Risky sign-ins detected by Identity Protection (Entra ID P2) |
| RoleEligibilitySchedule.Read.Directory | Privileged Identity Management eligible roles (Entra ID P2) |
| DeviceManagementManagedDevices.Read.All | Intune device inventory and compliance |
| DeviceManagementConfiguration.Read.All | Intune compliance policies |
| DeviceManagementApps.Read.All | Intune app protection policies (iOS / Android) |
| SharePointTenantSettings.Read.All | SharePoint external sharing level |
| MultiTenantOrganization.Read.All | Multi-tenant organizations and MSP setups |
Removing TenantIQ
Delete TenantIQ under Microsoft Entra admin center → Enterprise applications to revoke access instantly, then email us to delete your stored data (see our Privacy Policy).
Questions? Email support@tenantiq.tech.