TenantFabrictenantfabric.com
User & Administrator Manual

TenantFabric

The complete guide to the TenantFabric Microsoft 365 management portal - managing identity, licensing, Exchange, Intune, security and compliance across every customer tenant from one place.

Part 1 · User Guide Part 2 · Administrator Guide 50+ features documented Multi-tenant · GDAP · Microsoft Graph

About TenantFabric

TenantFabric is a multi-tenant management portal for running Microsoft 365 estates on behalf of customers. It connects to each customer's Microsoft tenant through the Microsoft Graph API - using least-privilege application permissions or GDAP delegated access - and gives engineers a single, consistent interface for the work that would otherwise mean logging into dozens of separate Microsoft admin centres.

Everything you see is scoped to the customers you are allowed to access, and every change is written back to Microsoft through Graph and recorded in the audit log. Reporting and dashboards read from a cached snapshot that a background sync refreshes on a schedule, so pages load instantly and you always see when the data was last refreshed.

Identity

Users, groups, roles, administrative units, authentication methods, domains, directory sync.

Licensing

Per-SKU purchased / assigned / available, utilisation and cross-customer usage.

Exchange & collaboration

Mailboxes, shared mailboxes, distribution groups, Teams, SharePoint & OneDrive.

Intune

Devices, policies, apps, reporting, deployment health, Windows Autopilot and updates.

Security

Conditional Access, Secure Score, risky users, mail investigation, Purview compliance.

Automation & MSP tools

Scheduled automations, bulk jobs, configuration drift, tenant comparison, reports.

About the screenshotsEvery screenshot in this manual is taken from TenantFabric's built-in demo environment, which uses simulated customers and Microsoft 365 data - nothing is sent to Microsoft. That is why the amber "Demo mode" banner and "Simulated demo tenant" badge appear. In your live portal those indicators are absent and the data is your customers' real Microsoft 365 estate.

Getting started & the interface

Sign in at your TenantFabric URL with your email address and password. If multi-factor authentication is enabled for your account you will be prompted for your authenticator code; your organisation can also enable Microsoft Entra single sign-on so you sign in with your Microsoft work account (see Entra sign-in).

The shell

Every page shares the same frame:

  • Left sidebar - the navigation, grouped into Customers, Identity, Licensing, Exchange, Collaboration, Intune, Security and Automation. What you see depends on your role and on whether a customer is selected.
  • Customer switcher (top-left) - pick the customer you want to work in. Customer-scoped pages (Users, Devices, Mailboxes…) only appear once a customer is selected; MSP-wide pages (Dashboard, All Customers, Fleet Overview) are always available.
  • Global search (top centre, ⌘K / Ctrl-K) - jump to a user, group or device across the selected customer.
  • Context bar - under the header on a customer page, showing the tenant ID, primary domain and live Connection status (Healthy / Degraded / Not connected).
  • Notifications (bell) and your account menu (initials, top-right).
Roles decide what you can doTenantFabric is role-based. Read-only roles can view and export but not change anything; engineer roles can make changes; owner/administrator roles manage the organisation itself. Items marked MSP / admin in this manual need an MSP role; items marked Everyday are available to any engineer with the relevant read or write permission. The full matrix is in the Roles & permissions appendix.

Part 1 - User Guide

Part 1 covers the day-to-day work an engineer does inside a customer's tenant: identity and licensing, Exchange and collaboration, Intune, and security. Unless noted, each page is scoped to the customer selected in the switcher.

Dashboard

Dashboarddashboard.readEveryday

The dashboard is your morning overview across every customer you can access. The KPI strip totals customers, connected tenants, users, licensed users, devices, MFA coverage, open security alerts and failed jobs. Below it, the Customers table gives one row per tenant - connection status, user and licence counts, device count (with non-compliant in red), MFA %, Secure Score and open alerts - so you can see at a glance which tenant needs attention.

The right-hand Connection health donut breaks tenants down by Healthy / Degraded / Unhealthy / Not connected, and surfaces Microsoft service-health incidents. The lower panels list compliance & configuration warnings ("things that need an engineer"), recent alerts, recent jobs and recent activity.

TenantFabric MSP dashboard
Dashboard - KPI strip, per-customer posture table and connection-health donut.
  • Click any customer row to open that customer's overview.
  • Red counts (e.g. 482 (37!) devices) flag non-compliant or at-risk items - click through to the relevant page.
  • "View all alerts", "All jobs" and "Audit log" links jump to the full lists.

Customer overview

Customer ▸ Overviewdashboard.readEveryday

Selecting a customer and clicking Customer Overview (or a row on the dashboard) opens the per-tenant home page. It summarises the tenant in tiles - total users (with disabled/guest breakdown), licensed users, mailboxes, groups, Teams, SharePoint sites, Intune devices (with non-compliant count) and app registrations - then shows Security status, Configuration status, Devices by platform, a Licences table (purchased / assigned / available / utilisation), internal Notes and Recent activity.

Use Sync now (top-right, MSP) to queue an immediate refresh of this tenant's cached data.

Customer overview page
Customer overview - the single-tenant home with posture tiles, licences and notes.

Users

Identity ▸ Usersusers.read users.writeEveryday

The Users page lists every account in the tenant with status, assigned licences, MFA state, department and last sign-in. Search and the column filters narrow the list; Export downloads it.

Creating & bulk-creating users

  • Create user - opens a form for display name, UPN, password options and initial licences/groups.
  • Bulk create (CSV) - upload a CSV to provision many accounts at once; the result runs as a background job.
Users list
Users - searchable directory with status, licences, MFA and last sign-in; Create and Bulk-create in the top-right.

The user detail page

Click any user to open their record. Tabs across the top cover Overview (profile & account), Licences, Groups, Authentication, Devices, Mailbox, OneDrive, Teams, Roles, Sign-ins and Audit history. The action buttons give you the common lifecycle tasks:

ActionWhat it does
EditChange profile fields (name, job title, department, usage location, etc.).
Reset passwordSet a new password; optionally require change at next sign-in. Can be delivered securely via Password Pusher.
Verify identityIssue a Temporary Access Pass (TAP) and run through identity-verification for a help-desk caller.
Travel bypassTemporarily exempt the user from the UK geolock Conditional Access policy for legitimate travel.
OffboardStart the leaver workflow - disable, revoke sessions, reset password, convert mailbox, remove licences (see Offboarding).
Actions ▾Further tasks: enable/disable, revoke sessions, reset MFA, delete, manage group membership.
User detail page
User detail - the tabbed record with lifecycle actions. The Account panel shows created date, last sign-in, password age, source (Cloud / on-prem) and registered MFA methods.
SafetyDestructive or outward-facing actions (reset password, offboard, delete, disable) ask for confirmation and are written to the audit log with your name. Reset passwords are never shown in plain text in chat or logs - use Password Pusher to hand them over.

Offboarding

Identity ▸ Offboardingusers.read users.writeEveryday

Offboarding packages the standard leaver steps into one reviewed workflow. Click Offboard a user, pick the account, then choose which steps to run: disable the account, revoke all active sessions, reset the password, remove licences, convert the mailbox to shared, delegate mailbox/OneDrive access to a manager, and remove group memberships. The job runs in the background and is fully audited.

Offboarding page
Offboarding - start the leaver workflow and pick the steps to apply.

Groups

Identity ▸ Groupsgroups.read groups.writeEveryday

Lists security, Microsoft 365 and distribution groups with type, email, member count, assigned licences and creation date. Create group makes a new security or M365 group. Open a group to manage its membership, owners, group-based licensing and settings.

Groups list
Groups - every group with type, members and group-licensing at a glance.

Directory roles

Identity ▸ Rolesroles.read roles.writeEveryday

Shows Microsoft Entra directory-role assignments in the customer tenant - Global Administrator, User Administrator, Exchange/Intune/Security/SharePoint Administrator and more - with the members in each. Use Assign to add a user to a role. Watch the Global Administrator count: too many is a security finding, and break-glass emergency-access accounts should be the only unlicensed admins.

Directory roles
Directory roles - privileged role membership in the customer tenant.
Don't confuse the two "Roles"This page manages Microsoft Entra roles inside the customer tenant. Your TenantFabric roles (who can do what in this portal) are managed under Settings ▸ Roles.

Administrative units

Identity ▸ Administrative Unitsadmin_units.readEveryday

Administrative units (AUs) scope admin permissions to a subset of the directory - for example separating Staff from Students in a school. This page lists the tenant's AUs; Show members expands the users and groups each one contains.

Administrative units
Administrative units - directory scopes such as Staff and Students.

Authentication

Identity ▸ Authenticationusers.auth_methods.readEveryday

A tenant-wide view of authentication posture. MFA registration shows how many users are not registered (with a click-through to the list) and how many admins lack MFA. The Authentication methods policy section shows which methods are enabled, and flags phone-only users ahead of Microsoft's retirement of SMS/voice sign-in. Use Edit to adjust the methods policy.

Authentication page
Authentication - MFA registration gaps and the authentication-methods policy.

Domains & email authentication

Identity ▸ Domainsdomains.readEveryday

Lists the tenant's verified domains with their status and services, and - importantly - the email authentication health of each: SPF, DKIM and DMARC, with an overall verdict. This is the quickest way to spot a domain that can be spoofed. Re-check re-runs the DNS lookups.

Domains page
Domains & organisation - verified domains plus SPF / DKIM / DMARC status per domain.

Directory sync

Identity ▸ Directory Syncusers.readEveryday

Shows the health of on-premises directory synchronisation (Entra Connect / Cloud Sync): whether sync is enabled, the last sync time, and any sync errors or accounts that have drifted. Check now refreshes the status. For cloud-only tenants this simply confirms no on-prem sync is configured.

Directory sync page
Directory sync - on-premises synchronisation status and last run.

Licences

Licensing ▸ Licenceslicenses.readEveryday

Every subscribed SKU in the tenant with purchased, assigned and available seats, a utilisation bar and status. It's the fast answer to "do we have a spare licence?" and "what are we over-/under-buying?". Over-utilised SKUs (no seats left) and nearly-exhausted SKUs are highlighted. For the cross-customer view, MSP users have Usage (all customers).

Licences page
Licences - per-SKU purchased / assigned / available and utilisation.

Exchange Online - mailboxes

Exchange ▸ Mailboxesmailboxes.readEveryday

The Exchange Online hub, with tabs for User mailboxes, Shared mailboxes, Distribution groups and Usage. Each mailbox shows its primary address, aliases, sign-in enablement and last activity. From here you manage shared-mailbox delegation, distribution-group membership, and mailbox settings such as automatic replies and forwarding.

Exchange Online mailboxes
Exchange Online - user mailboxes, with tabs for shared mailboxes, distribution groups and usage.

Microsoft Teams

Collaboration ▸ Teamsteams.readEveryday

Lists the tenant's Teams with membership and settings, and lets you drill into a team to see its channels, owners and members. Use it to audit sprawl, find ownerless teams and review guest access.

Microsoft Teams page
Microsoft Teams - teams, owners and membership.

SharePoint & OneDrive

Collaboration ▸ SharePoint & OneDrivesharepoint.readEveryday

Shows the tenant's external sharing posture, the Sites list (owner, file count, storage used, last activity) and OneDrive usage. Use it to review sharing settings, find large or dormant sites, and keep an eye on storage.

SharePoint and OneDrive page
SharePoint & OneDrive - external sharing, sites and OneDrive storage.

Intune - devices

Intune ▸ Devicesintune.read intune.writeEveryday

The managed-device inventory: device name, OS, compliance state, ownership, primary user, serial and last check-in. Filters (including the Compliance sidebar shortcut that pre-filters to non-compliant) narrow the list. Open a device for its full record and remote actions - sync, restart, remote lock, rename, retire and wipe - each gated by the appropriate permission (intune.write / intune.wipe) and confirmed before it runs.

Devices inventory
Devices - managed-device inventory with compliance, ownership and last check-in.

Intune - policies & applications

Intune ▸ Policies / Applicationsintune.readEveryday

The Policies tab lists compliance policies, configuration profiles and settings-catalog policies with their type, platform and last-modified date. The Applications tab lists the apps deployed through Intune. This is the configuration catalogue; for how those policies and apps are actually landing on devices, use Deployment health and the reporting pages below.

Intune policies
Intune - compliance policies, configuration profiles and settings-catalog policies.

Intune - reporting & device configuration issues

Intune ▸ Reportingintune.readEveryday

The operational answer to "which devices need an engineer?". KPI tiles cover total devices, per-platform counts, compliance %, "need attention", stale / no check-in, encryption and management issues. The Compliance donut breaks devices into compliant / non-compliant / error / grace / unknown. The Devices needing attention table lists every device with a detected issue, worst-first, filterable by status, platform and free text, with an adjustable stale threshold (7–90 days). Select a device to see why each issue was raised and the Graph field behind it, then open the device for live detail.

Intune reporting
Intune reporting - device KPIs, a compliance donut and the prioritised "needs attention" list.
Honest by designIssue detection is computed from the cached device object only, so it's instant and never invents data. Deeper per-device checks that need extra Graph calls are shown live on the device page. Every report here also exports to CSV / Excel / PDF from Reports.

Intune - deployment health

Intune ▸ Deployment Healthintune.readEveryday

Roll-up status for what's actually deploying, with a live per-device drill-down. Tabs:

  • Applications - assigned apps with installed / failed / pending counts and an install-health %.
  • Compliance - compliance policies with compliant / non-compliant / error counts; unassigned policies flagged.
  • Configuration - configuration profiles with success / error / conflict counts.
  • Scripts - device-management scripts; run states loaded live per script.

Select any row to load the affected devices live. The KPI strip at the top surfaces failing apps, compliance issues, config failures and script counts.

Intune deployment health
Deployment health - app install success, policy results and script run states, each with a device drill-down.

Intune - Windows Autopilot

Intune ▸ Windows Autopilotintune.readEveryday

A health dashboard and troubleshooting view for Autopilot-registered devices. KPIs cover registered devices (deployed / awaiting), devices needing attention, devices with no deployment profile and devices with no Group Tag. Tabs:

  • Devices - serial, model, Group Tag, assigned profile, user and a computed health status (Ready / Awaiting deployment / Attention / Error). Expand a flagged device to see exactly why.
  • Profiles - deployment profiles with mode, join type, assignment and per-profile device counts.
  • Group Tags - devices grouped by Group Tag, with the profiles each maps to.
  • Issues - the Devices view filtered to only devices with a problem.
Windows Autopilot page
Windows Autopilot - registered-device health, deployment profiles and Group-Tag reporting.
Awaiting vs errorA device that hasn't contacted Intune yet shows as Awaiting deployment, not as an error - Microsoft only reports its profile assignment once it checks in during OOBE. Genuine problems (no/failed profile, blocked enrolment, missing Group Tag) are flagged explicitly with the Graph field behind each.

Intune - updates & OS versions

Intune ▸ Updatesintune.readEveryday

Two views. OS versions shows the OS/version spread across all managed devices, with a Windows feature-release roll-up (e.g. Windows 11 24H2 / 23H2, Windows 10 22H2) and a servicing status - Current / Supported / Ending soon / End of life. Windows 10 is flagged end-of-life (support ended 14 October 2025). Update policies lists Windows Update rings and feature / quality / driver update profiles with assignment status and key settings.

Intune updates and OS versions
Updates - OS-version distribution with Windows feature-release servicing status, plus update rings and profiles.

Conditional Access

Security ▸ Conditional Accessconditional_access.readEveryday

Lists the tenant's Conditional Access policies with their users, applications, grant controls, state and last-modified date. The Geolock panel manages a UK-only sign-in restriction (with the per-user travel bypass), and Named locations and tenant identity settings round out the page. Use New policy or Use existing policy to deploy from a template. Conditional Access requires Entra ID P1, which the page checks for.

Conditional Access page
Conditional Access - policies, geolock, named locations and identity settings.

Applications (app registrations & enterprise apps)

Security ▸ Applicationsapplications.readEveryday

Two tabs. App registrations lists the tenant's own registered apps with their credentials, next secret/cert expiry (so you catch an expiring secret before it breaks an integration), audience and warnings. Enterprise applications lists service principals / consented third-party apps. This is where you review OAuth consent risk and credential hygiene.

Applications page
Applications - app registrations with credential expiry, plus enterprise applications.

Security overview

Security ▸ Security Overviewsecurity.readEveryday

The tenant's security posture on one page: Secure Score (current and trend), risky users from Entra ID Protection, prioritised Secure Score recommendations (with a "can enable here" marker where TenantFabric can action it directly), and the live security alerts feed with severity, source, entity and status.

Security overview
Security - Secure Score, risky users, recommendations and the alerts feed.

Mail investigation

Security ▸ Mail Investigationmail.investigateEveryday

The incident-response toolkit for email. Message trace follows a message's path and delivery; Advanced hunting runs KQL-style queries across mail telemetry; and the Tenant Allow/Block List lets you block a sender/domain or remove a delivered malicious message. Use it when a customer reports phishing or a mis-delivered mail.

Mail investigation
Mail investigation - message trace, advanced hunting and the Tenant Allow/Block List.
Outward-facing actionsBlocking senders and removing messages change the live tenant and are confirmed before running and recorded in the audit log.

Compliance (Purview)

Security ▸ Compliance (Purview)security.readEveryday

A read view of Microsoft Purview information governance: sensitivity labels (with sensitivity, scope and whether they're in use), retention labels (retain period and the action taken afterward) and eDiscovery cases with their status. It answers "what data-protection controls does this tenant have configured?".

Compliance (Purview) page
Compliance (Purview) - sensitivity labels, retention labels and eDiscovery cases.

Configuration & drift

Security ▸ Configurationtemplates.readEveryday

Evaluates the customer tenant against an assigned configuration template (your house standard) and lists every checked setting with its expected value, the tenant's actual value and a pass/fail status. Where the two differ, that's configuration drift - the tenant has moved away from your baseline. Evaluate now re-runs the check.

Configuration and drift page
Configuration & drift - the tenant measured against your standard baseline, setting by setting.

Reports

Reportsreports.read reports.exportEveryday

A catalogue of ready-made reports grouped by Licensing, Identity, Security and Devices - licence usage, user and guest counts, inactive users, MFA registration gaps, Conditional Access policies, Secure Score improvements, device compliance, the full Intune reporting set (app deployment, compliance/config health, device configuration issues, Autopilot devices and issues) and the cross-customer Intune fleet overview. Pick a report, choose a customer (or all permitted customers) and any parameters, then run it on screen or export to CSV, Excel or PDF. Exports require the reports.export permission and are audited.

Reports catalogue
Reports - the full report catalogue; every report exports to CSV, Excel or PDF, per customer or MSP-wide.

Jobs

Jobsjobs.readEveryday

Long-running and bulk operations (bulk user create, offboarding, bulk licence changes, scheduled syncs) run as background jobs so the UI never blocks. This page lists each job with its operation, customer, progress, status, who started it and when. Open a job to see per-item results and any errors.

Jobs page
Jobs - progress and per-item results for every background operation.

Notifications

NotificationsEveryday

Your personal notification feed - job completions, alerts routed to you, and system messages. Mark all read clears the unread count on the bell. What generates and routes notifications is configured per-organisation under Settings.

Notifications page
Notifications - your personal feed of job results, alerts and system messages.

Your account settings

Settings ▸ AccountEveryday

Everyone has a personal Account page: edit your profile, change your password, and review and sign out your active sessions. The Security & MFA tab is where you set up your authenticator. The remaining Settings tabs (Members, Roles, Branding, Microsoft 365 app, GDAP, etc.) are organisation-level and covered in Part 2 - they appear only if your role allows.

Account settings
Account - your profile, password and active sessions.

Part 2 - Administrator Guide

Part 2 is for MSP owners, administrators and senior engineers. It covers onboarding customers and connecting their tenants, the cross-customer MSP tools, automation, and running TenantFabric itself - members, roles, branding, the Microsoft app registration, GDAP and the audit trail. Pages here are marked MSP / admin and need an MSP-level role.

All customers

Customers ▸ All Customerscustomers.readMSP / admin

The master list of every customer in your organisation - domain, status, connection, connection mode, tenant ID, last sync and tags. It's the index you work from; click a customer to enter its context, or use the tags and search to find one.

All customers list
All Customers - the master index of tenants with status, mode and last sync.

Add a customer

Customers ▸ Add Customercustomers.writeMSP / admin

Creating a customer is step one of onboarding. You enter the customer's details (name, primary domain, contact, tags) and - crucially - choose its feature modules and the Microsoft permission level for each: Off, Read or Manage. Those choices drive exactly which Microsoft Graph permissions TenantFabric will request when you connect the tenant, keeping access least-privilege. After creating the customer you connect its tenant (next section).

Add customer form
Add Customer - customer details plus the per-module Off / Read / Manage permission picker.
Modules → permissionsEach module (Users, Groups, Intune, Exchange, Security…) maps to a specific set of Graph scopes. Choosing Read grants the read scopes; Manage adds the write scopes. You can change this later from Tenant Connection, after which the tenant must re-consent.

Tenant connection & consent

Customer ▸ Tenant Connectiontenants.read tenants.writeMSP / admin

This is where a customer's tenant is actually linked to TenantFabric. It shows the live connection Status, the granted application permissions, and a Change features & permissions panel mirroring the module picker. To connect (or re-consent after changing modules) you run the Microsoft admin-consent flow; TenantFabric then verifies which scopes were granted and flags any that are missing. Check health re-tests authentication and permissions; Sync now queues a data refresh.

Tenant connection page
Tenant connection - connection status, granted permissions and the module/permission change panel.
"Degraded" means a scope is missingIf a feature page is empty, check here first. When a module needs a Graph permission the tenant hasn't consented to, the connection shows Degraded and the scope is listed under missing permissions - the affected page will tell you which permission and link you here to re-consent.

Customer settings

Customer ▸ Customer Settingscustomers.writeMSP / admin

Edit the customer's details and tags, and - in the Danger zone - archive or delete the customer. Archiving keeps the record but removes it from active lists; deletion is permanent and confirmed.

Customer settings
Customer settings - details, tags and the danger zone.

Tenant health

Customers ▸ Tenant Healthtenants.readMSP / admin

A cross-customer operations board for connection health. For every connected tenant it shows the authentication status, a details note, the count of missing permissions, and the last health-check and last-sync times. Per-row Check re-tests the tenant and Sync queues a refresh. TenantFabric also runs these health checks automatically every hour.

Tenant health board
Tenant health - authentication, missing-permission counts and freshness for every connected tenant.

Intune fleet overview

Intune ▸ Fleet Overviewintune.readMSP / admin

Every customer's Intune posture on one screen. Fleet KPIs total devices, compliance, devices needing attention, stale devices, Autopilot issues, Windows end-of-life and unassigned update policies across the estate. The per-customer table (sorted worst-first) lets you spot which tenant needs work and click straight into its Intune reporting. An adjustable stale threshold recomputes live, and the whole view exports to PDF or Excel - a ready-made board-level estate report. The companion Usage (all customers) page under Licensing does the same for licences.

Intune fleet overview
Intune fleet overview - cross-tenant device posture with per-customer drill-down and PDF export.

Alerts

Security ▸ Alertsalerts.readMSP / admin

The organisation-wide alert queue - security alerts from Microsoft, risky-user detections, configuration-drift findings and licence-threshold warnings, across all customers. Each alert carries a severity, customer, entity and timestamp. Acknowledge marks an alert as seen; Resolve closes it. Alerts that Microsoft no longer reports are resolved automatically.

Alerts queue
Alerts - the cross-customer alert queue with acknowledge/resolve.

Automations

Automation ▸ Automationsautomations.read automations.writeMSP / admin

Automations run a check on a schedule and optionally take action. The list shows each automation's check, schedule, scope (which customers), mode (report-only vs enforce), and last/next run. Run triggers one immediately.

Automations list
Automations - scheduled checks with scope, mode and run history.

Building an automation

The builder is a simple When → Check → Then flow: choose the schedule (When), the condition to evaluate (Check), and one or more actions to take (Then). Scope it to specific customers or all, and choose report-only to trial it safely before enforcing.

New automation builder
New automation - the When / Check / Then builder.
Start in report-onlyRun a new automation in report-only mode first and review what it would have done in Jobs before switching it to enforce.

Configuration templates

Automation ▸ Templatestemplates.read templates.writeMSP / admin

Templates are your house standards - the settings a well-configured tenant should have. Start from a baseline gives you a ready-made starting point (e.g. "Standard School Microsoft 365 Configuration"), or build your own with New template. Assign a template to customers and TenantFabric measures each tenant against it on the Configuration & drift page.

Configuration templates
Configuration templates - reusable baselines that power drift detection.

Tenant comparison

Automation ▸ Tenant Comparisontenants.compareMSP / admin

Compare two (or more) tenants side by side to spot inconsistencies - different Conditional Access, licence mixes, security settings or configuration. Pick the tenants and the areas to compare, then review the differences. Useful for standardising a new acquisition against your reference tenant.

Tenant comparison
Tenant comparison - side-by-side differences between tenants.

Audit logs

Audit Logsaudit.readMSP / admin

Every action taken in TenantFabric is recorded here: time, actor, customer, action, the resource affected, the result and the source IP. It's your accountability trail - who reset whose password, who changed a policy, who exported which report. Filter by customer, actor or action and export to CSV or Excel for evidence.

Audit logs
Audit logs - the full, exportable record of every action and its result.

Settings - members

Settings ▸ Membersmembers.manageMSP / admin

Manage the people who use TenantFabric. The list shows each member's type (MSP or customer), assigned roles, sign-in method, last sign-in and status. Invite member adds a new user and assigns their role(s); Deactivate disables access. Customer-type members are scoped to their own tenant only.

Settings members
Members - portal users, their roles and sign-in status.

Settings - roles (RBAC)

Settings ▸ Rolesroles.manageMSP / admin

Defines what each TenantFabric role can do. Built-in roles range from MSP Owner (everything) down through MSP Administrator, Senior Engineer, Engineer, Helpdesk and Read Only, plus customer-scoped Customer Admin and Customer Read Only. New role creates a custom role with a precise permission set. Permissions are granular (e.g. users.write, intune.wipe, reports.export) so you can grant exactly what a role needs.

Settings roles
Roles - built-in and custom TenantFabric roles and their permissions.

Settings - Microsoft 365 app

Settings ▸ Microsoft 365 apporg.manageMSP / admin

This is TenantFabric's own Microsoft Entra app registration - the identity it uses to call Graph. The page walks through the redirect URIs, delegated and application permissions, and shows the mapping of feature modules → permissions and the Microsoft API dependencies each page relies on (with v1.0/beta version). Test validates the configuration. This is a one-time setup you maintain as modules evolve.

Microsoft 365 app settings
Microsoft 365 app - the Entra app registration, permission mapping and API dependencies.

Settings - GDAP partner

Settings ▸ GDAP partnerorg.manageMSP / admin

If you manage customers through the Microsoft partner programme, connect your GDAP (Granular Delegated Admin Privileges) partner account here. This lets TenantFabric act with delegated admin rights into customer tenants within the granular roles GDAP grants, rather than per-tenant app consent.

GDAP partner settings
GDAP partner connection - link your Microsoft partner account for delegated administration.

Settings - Entra sign-in (SSO)

Settings ▸ Entra sign-inorg.manageMSP / admin

Enable Microsoft Entra single sign-on so your team signs into TenantFabric with their Microsoft work account instead of a separate password. Link with Microsoft connects your organisation's Entra tenant; once enabled, members can use "Sign in with Microsoft".

Entra sign-in settings
Microsoft Entra sign-in - enable SSO for your team.

Settings - security & MFA

Settings ▸ Security & MFAMSP / admin

Your personal account security, including setting up an authenticator app for multi-factor sign-in. Organisation policy can require MFA for all members; this is where each member enrols. Set up authenticator starts the enrolment.

Security and MFA settings
Security & MFA - enrol your authenticator for portal sign-in.

Settings - branding

Settings ▸ Brandingorg.manageMSP / admin

White-label TenantFabric with your identity: company and product name, accent colours, and logo & icon. These flow through the portal shell (the sidebar, sign-in page and reports) - which is why the interface in this manual carries the TenantFabric mark. Save branding applies it; Defaults reverts.

Branding settings
Branding - company identity, colours and logo for the whole portal.

Settings - Password Pusher

Settings ▸ Password Pusherorg.manageMSP / admin

Integrates a Password Pusher service so that passwords you reset can be handed to users as a secure, self-expiring link instead of being typed into chat or email. Configure the connection and link behaviour (expiry, views), Test connection, and Save. The "How it works" panel explains the flow.

Password Pusher settings
Password Pusher - secure, self-expiring delivery of reset passwords.

Appendix A - Roles & permissions

TenantFabric roles decide what a member can see and do. Permissions are granular; the built-in roles bundle sensible defaults, and you can create custom roles under Settings ▸ Roles.

RoleTypical useScope
MSP OwnerFull control, including org settings, billing and roles.All customers
MSP AdministratorManage customers, members and automation; not owner-only settings.All customers
Senior EngineerAll customer-facing changes incl. sensitive actions.All / assigned customers
EngineerDay-to-day changes (users, groups, devices, mailboxes).Assigned customers
HelpdeskPassword resets, identity verification, basic user tasks.Assigned customers
Read OnlyView and export, no changes.Assigned customers
Customer AdminA customer's own staff managing just their tenant.Own tenant
Customer Read OnlyA customer viewing their own tenant.Own tenant

Permissions follow a area.action pattern - for example users.read, users.write, intune.read, intune.write, intune.wipe, reports.export, tenants.write, automations.write. A page simply won't appear if your role lacks its read permission, and an action button is hidden or disabled without its write permission.

Appendix B - Microsoft permissions & data freshness

TenantFabric calls Microsoft Graph with least-privilege scopes derived from each customer's enabled modules. Choosing Read on a module grants its read scopes; Manage adds the write scopes. If a tenant hasn't consented to a scope a feature needs, that feature's page tells you which permission is missing and links you to Tenant Connection to re-consent - it never invents data to fill the gap.

Data freshness. Dashboards and reporting read from a cached snapshot that a background sync refreshes on a schedule (shown as "Last synchronised …" on each page). Sync now queues an immediate refresh. Live actions (resets, policy changes, device commands) always go straight to Microsoft in real time and are confirmed and audited.

Multi-tenant isolationEvery query is scoped to the customers your role allows, enforced at the database level by row-level security. A user of one customer can never read another customer's data - this is tested continuously.

Appendix C - Glossary

TermMeaning
TenantA customer's Microsoft 365 / Entra directory.
GDAPGranular Delegated Admin Privileges - Microsoft's partner delegated-access model.
GraphMicrosoft Graph, the API TenantFabric uses to read and change tenant data.
Secure ScoreMicrosoft's measure of a tenant's security posture.
Conditional AccessEntra ID P1 policies controlling who can sign in, from where and how.
TAPTemporary Access Pass - a time-limited passcode for identity verification / passwordless onboarding.
AutopilotWindows device provisioning that configures a new PC automatically at first sign-in.
Group TagAn Autopilot label that drives which deployment profile and groups a device receives.
DriftWhen a tenant's settings diverge from your configuration template.
PurviewMicrosoft's data-governance suite (sensitivity/retention labels, eDiscovery).
Enlarged screenshot