Docs

Tenants and the tenant page

The tenant list, everything on a tenant's page, licences and groups, and how sync keeps it up to date.

Every connected tenant has its own page with the users, licences, security findings, groups, mailboxes, sign-ins, apps and policies Tenvara read from it.

The tenant list

Microsoft 365 > Tenants lists every tenant with its Customer, Connection status, Users, MFA (the share with an MFA method registered, or Not known without Entra ID P1), Licences (assigned out of bought) and Last sync. Filter by customer and connection, choose columns, and save views.

The tenant list with connection, users, MFA, licences and last sync for each tenant
The tenant list with connection, users, MFA, licences and last sync for each tenant

Click a tenant to open its page.

The tenant page

The header shows the tenant name, its status, the Customer, main Domain, how it was connected (Admin consent or GDAP) and Last sync. On the right:

  • Sync now reads every area from Microsoft straight away (queued). Keyboard shortcut S.
  • More actions: Copy a new consent link, Copy Microsoft tenant id, Exclude from automation and Remove tenant.
A tenant's overview tab with users, MFA, security posture, licences and what it is licensed for
A tenant's overview tab with users, MFA, security posture, licences and what it is licensed for

The tabs are:

Tab What it shows
Overview Users, MFA registered, administrators and guests; the posture score with the worst failing checks; licences; what the tenant is licensed for; recent changes
Users The tenant's users, as in Users, groups and mailboxes
Licences Every subscription, bought and assigned
Findings The security checks and frameworks, see Security findings
Groups Security, Microsoft 365, dynamic, distribution and mail-enabled security groups
Mailboxes Mailboxes, forwarding and inbox rules
Sign-ins Sign-ins worth a look, risk and directory activity, see Sign-ins, apps and policies
Apps Enterprise apps and the permissions they were granted
Policies Conditional Access policies, templates and named locations
Actions Every change made to this tenant through Tenvara, with undo
Email The tenant's mail domains, see Email security
Settings Connection details, the roles Tenvara holds and the sync history

Licensed for

The Licensed for block on the overview lists what Microsoft says the tenant has: Entra ID P1, Entra ID P2, Intune, Exchange Online, Defender for Office 365 and the Audit log. This decides what can be checked. For example, sign-in logs and Conditional Access need Entra ID P1, and risky users need P2. A check that needs something the tenant does not have is shown as not applicable rather than failing.

Licences

The Licences tab lists every subscribed licence with Bought, Assigned, Unused and Status, using friendly names (for example Microsoft 365 Business Premium rather than SPB). Free and self-service offers that Microsoft lists with huge seat counts are shown apart and left out of every total.

When the customer's licences are billed through a licence source, a second table compares them: Supplied, what the tenant has, Assigned, Unused, Orphaned (supplied but not in the tenant), Over, Reclaimable and the Waste a month in money. See Reconciling against Microsoft 365.

A tenant's licences, with the comparison against licence subscriptions and the monthly waste
A tenant's licences, with the comparison against licence subscriptions and the monthly waste

Tenvara raises an alert when a tenant has more of a licence assigned than it bought, and clears it when it is back within.

Groups

The Groups tab lists every group with its Kind (Security, Microsoft 365, Dynamic, Distribution list, Mail-enabled security), Members and Owners. Filter by kind.

A tenant's groups with kind, members and owners
A tenant's groups with kind, members and owners
  • Press New group to create a security, Microsoft 365, dynamic (with a membership rule, needs Entra ID P1), distribution or mail-enabled security group.
  • Open a group to see its members and owners, add and remove them, edit its name, description and visibility, or delete it.
  • Distribution lists and mail-enabled security groups are changed through Exchange. Dynamic groups keep their own membership, so people cannot be added or removed by hand.
  • A deleted Microsoft 365 or security group can be restored with undo; a deleted distribution list cannot.

Sync

Tenvara reads each tenant in areas, each on its own schedule:

Area How often What it reads
Directory Regularly Organisation, domains, licences, administrator roles, users, MFA registration, groups and members
Security settings Every 4 hours Security defaults, Conditional Access, authentication methods, consent and guest settings, SharePoint and Teams settings, Secure Score, risky users, Intune devices, enterprise apps, Exchange security settings
Exchange Every 12 hours Mailboxes, sizes, automatic replies, forwarding, inbox rules and permissions
Sign-ins and risk Every 30 minutes Failed, legacy and risky sign-ins, risk detections and directory audit events
Email (DKIM) Every hour DKIM signing for the tenant's domains

After every sync the security checks run again. Sync now runs every area at once.

The Settings tab shows the Sync history, newest first: each area, when it ran, how long it took, how many requests it made and what it read. Parts Microsoft would not give are listed, so a gap is never mistaken for a clean result.

A tenant's settings tab with the connection, roles held and sync history
A tenant's settings tab with the connection, roles held and sync history

Note: A user who disappears from Microsoft is kept as deleted, never removed, and nothing is removed after a failed or empty read. Intune devices are matched to your Tenvara devices by serial number within the customer; nothing new is created in Devices.

Was this page helpful?

Thanks for the feedback.