Skip to content
Vantage Central

You are handing us keys to your clients’ tenants

That deserves a straight answer rather than a badge wall. Here is exactly how access works, what the platform can and cannot do, and what is written down about every action taken inside it.


Six decisions that shape everything else

Credentials never leave the server

Microsoft credentials and refresh tokens are encrypted at rest. Access tokens are used server-side only and never reach the browser, so there is nothing sensitive in the page for an extension or a shared screen to pick up.

Read-only where it matters

Conditional Access is viewable, never editable. You can read a tenant’s policies in plain language, with IDs resolved into real names, but the product has no path to change them, by design.

Every action is attributable

Who did it, when, and to whom, logged for every action taken in the platform. Records stay attached to the right person even after an account is renamed during offboarding, which is exactly when audit trails usually break.

Destructive actions are deliberate

Wipes, deletions and offboarding require explicit confirmation. Nothing irreversible happens from a single mis-click, and nothing runs on a schedule you did not set.

Scoped access per person

Super Admin and Admin roles, with per-user restrictions on which tenants each of your staff can see. A technician who only looks after three clients only sees those three.

Passwords are not emailed

Generated passwords are shared as expiring, one-time links rather than sitting in plain text in an inbox forever. The link dies after it is opened.


How the platform gets in, and how you get it out

There is no proprietary connector and no privileged back channel. Access is granted through Microsoft, held by Microsoft, and revocable by you.

  • Tenants connect via the standard Microsoft admin-consent flow, the same one every M365 tool uses.
  • No agent to install, on servers or on endpoints.
  • Permissions are the ones Microsoft grants at consent, and no more.
  • You can revoke the platform’s access from your own tenant at any time, without asking us.
  • Each organisation can enforce single sign-on through its own Microsoft Entra ID.
  • Self-service password reset happens by emailed code, not by a support ticket.

Security you get, not just security you have

The same rigour applies outward. These checks run continuously against the tenants you manage, whether or not anyone remembers to look.

Users without MFA

Including admins left unprotected, and outdated methods still registered.

Suspicious sign-ins

Impossible travel, repeated failures, new countries, out-of-hours activity, legacy protocols.

Device compliance

Non-compliant, unencrypted and stale devices flagged by a background scan.

Unfinished offboarding

Accounts still licensed, still in groups, still able to sign in, then fixed in bulk.


Asked by nearly everyone

Is my clients’ data safe?

All Microsoft credentials are encrypted at rest. Access tokens never reach the browser. Every action is logged with who did it and when.

Will it break my tenants?

Sensitive areas such as Conditional Access are strictly read-only. Destructive actions always require explicit confirmation.

How long does setup take?

Connecting a tenant uses the standard Microsoft admin-consent flow. Minutes, not days, and no agent to deploy.

Do my clients need training?

No. They fill in a branded web form. That is the whole experience for them.

Have a security questionnaire or a specific requirement to meet? Send it over and you will get a straight answer, including where the answer is no.

Look at it yourself

The demo runs on entirely fictional data with no connection to Microsoft, so you can click every button in it, including the ones you would be cautious with in a real tenant.