Microsoft 365 console for MSPs
Your clients’ Microsoft 365 operations, in seconds. Not in ten portals.
EasyTenant is the console that runs everyday Microsoft 365 operations — passwords, 2FA, licenses, shared mailboxes, delegations — across all your client tenants, from a single interface.
30 days free, no card, no commitment. The demo opens without an account.
- No password or token stored
- Minimal data access
- Revocable consent
Sample ticket
Sarah Bennett forgot her password.
- 09:04:02Search “sarah” — 4 tenants scanned
- 09:04:06s.bennett@harding-co.com selected
- 09:04:11Password reset started
- 09:04:19Temporary password delivered
Action recorded in the audit log — technician, tenant, timestamp.
- 9M365 and Exchange operations
- 1consent link per client
- 0agents to install
- 30 dfree trial, no credit card
Time saved
The same request, two ways to handle it
A forgotten password at a client. On top, the portal-by-portal route; below, the same task in EasyTenant. Typical scenario: one password ticket, Microsoft portals, no session open.
- Find the client access≈ 55 s
- Sign-in + MFA≈ 75 s
- Admin navigation≈ 60 s
- Operation≈ 50 s
- Search → act≈ 20 s
Your console session is already open: the tenant is selected, not signed into again. Your own times will vary.
The operations
Nine operations, ready to go
Everything a technician usually does portal by portal, brought together in a single interface. The times shown are rough orders of magnitude, for the task alone, once the tenant is selected.
Password reset
A new password, generated and temporary or not.
2FA reset
Clear MFA methods and generate a Temporary Access Pass.
License management
Assign and remove Microsoft licenses per user.
Shared mailboxes
Create shared mailboxes in a few clicks.
Delegations
Full access and send-as on your clients’ mailboxes.
Block and restore
Suspend an account, then reactivate it when needed.
Mailbox conversion
Convert between a user mailbox and a shared mailbox.
Out-of-office reply
Internal and external messages, ongoing or for a set period.
Account deletion
Handle an employee’s departure cleanly, end to end.
Shared mailboxes, delegations and conversions go through Exchange Online — included, no add-on module.
All features in detailGetting started
How does a tenant join your console?
From adding a client to the first operation, with no install and no heavy setup.
The client approves a link
You send a consent link. An administrator of the target tenant approves it once. Nothing to install.
The tenant shows up
The client tenant joins your console, alongside all the others.
You take action
Pick the user, run the operation, and the result comes back in seconds.
The multi-tenant fleet
Built to manage many clients at once
Beyond individual operations, the console keeps an eye on your whole fleet of tenants and control over who does what.
Cross-tenant search
Type a name in the search bar: the console runs a global search across all your client tenants.
Per-tenant license view
Each client’s license estate on one screen: subscriptions, licenses assigned or still available.
Per-technician permissions
Each operation is granted separately: everyday tasks for the whole team, sensitive actions reserved for whoever you decide.
Administrator account protection
Two settings to pick from: an operation targeting an administrator account in a client tenant waits for the owner’s approval, or stays refused to everyone.
Explore EasyTenant in more detail
Security
Security shown, not promised
You handle your clients’ identities. The architecture is designed so one tenant can never touch another, and to keep as little data as possible.
The console → tenant link
Walls between tenants
Select a tenant: the others stay out of reach. The tenant ID comes from the authenticated session, never from the request.
What passes through — never kept
- Operation verified, then executed
- Microsoft Graph response, shown only once
- One timestamped line in the audit log
What does not exist at EasyTenant
- Stored passwords
- Persisted access tokens
- Client secret
- Mailbox content
Permissions
What the client tenant grants, line by line
In your client tenants, EasyTenant declares these Microsoft permissions and nothing else. The list is published so your security review can read it before you send the consent link.
| Permission | What it allows |
|---|---|
| Application — Microsoft Graph | |
| User-PasswordProfile.ReadWrite.AllRead and write | Reset a password and set a temporary one. |
| UserAuthenticationMethod.ReadWrite.AllRead and write | Reset 2FA and issue a temporary access pass. |
| LicenseAssignment.ReadWrite.AllRead and write | Assign and remove licenses. |
| Organization.Read.AllRead-only | Read the licenses the tenant holds. |
| User.ReadWrite.AllRead and write | Read and write the tenant’s accounts: cross-tenant search, creation, blocking, deletion and restore. |
| MailboxSettings.ReadWriteRead and write | Turn the out-of-office reply on and off. |
| AuditLog.Read.AllRead-only | Read the audit and sign-in logs. EasyTenant only reads the 2FA registration report there. |
| RoleManagement.Read.DirectoryRead-only | Read the tenant’s directory roles. EasyTenant checks its own and spots privileged accounts before a sensitive operation. |
| Application.ReadWrite.OwnedByRead and write | Manage the applications EasyTenant owns, so it can remove itself from the tenant the day you disconnect it. |
| Application — Exchange Online | |
| Exchange.ManageAsAppRead and write | Administer Exchange Online. EasyTenant sticks to shared mailboxes, delegations and mailbox conversion, which Microsoft Graph cannot do. |
| Delegated — the only one, for a single step | |
| RoleManagement.ReadWrite.DirectoryRead and write | Grant EasyTenant its three directory roles during onboarding. An admin token that lives only for that call. |
| Never requested | |
| Directory.ReadWrite.All | Write access to the whole directory. |
| Mail.Read | Reading email. |
| Files.ReadWrite | File access, in any of its variants. |
| The permission is not enough: several operations also require a directory role granted to EasyTenant in the client tenant (Authentication Administrator, User Administrator, Exchange Administrator). Without it, Microsoft refuses the call. | |
| Access tokens live in memory for at most an hour and are never written down. For each tenant, EasyTenant keeps only its Microsoft identifier, the consent state and its revocation date. No password, ever. | |
Pricing
Priced by fleet size. Never per user, never per technician.
Three plans based on how many tenants you manage — everything else is unlimited.
30-day free trial included
Starter
or €490/year — 2 months free
Up to 15 client tenants
- All Microsoft 365 and Exchange operations
- Unlimited technicians
- Complete audit log
- No commitment, cancel anytime
Advanced
or €990/year — 2 months free
Up to 50 client tenants
- All Microsoft 365 and Exchange operations
- Unlimited technicians
- Complete audit log
- No commitment, cancel anytime
Unlimited
or €1,990/year — 2 months free
Unlimited client tenants
- All Microsoft 365 and Exchange operations
- Unlimited technicians
- Complete audit log
- No commitment, cancel anytime
Past the included count, adding another tenant requires a higher plan. Tenants already connected stay accessible.
See the console before creating an account
The full app, on sample data. No account, no card.
Frequently asked questions
Do I need to install anything at each client?
No. A client tenant administrator approves consent once, through a link you send them. No agent or software to deploy.
How is this different from the Microsoft admin center or Lighthouse?
Lighthouse focuses on monitoring and requires GDAP prerequisites. EasyTenant is action-oriented — the everyday tasks — brought together for all your tenants in a single interface, with no heavy setup.
What data does EasyTenant keep?
Only what’s needed: each tenant’s consent, your technician accounts and an audit log of operations. No password, no access token and no mailbox content. Your users’ data stays in the client’s Microsoft tenant.
Does the free trial require a credit card?
No. The 30-day trial starts without a payment method. If no card is added by day 30, access ends on its own — nothing can be charged. You can subscribe anytime from your settings.
How does billing work?
Three plans based on how many tenants you manage, monthly or yearly (2 months free). No commitment: cancel anytime from your settings.
What happens if a client withdraws consent?
Access to that tenant is cut off immediately. Revocation is possible from both sides, at any time.
Take back control of your clients’ tenants
Set up EasyTenant in minutes and handle your day-to-day requests from a single interface.
The full app, on sample data. No account, no card.