How we work

Our access to your Microsoft 365 and Azure environment follows Microsoft's recommended least-privilege model. We never create local accounts in your tenant and we do not keep standing Global Administrator or other privileged roles switched on. Our technicians work from our own managing tenant with their own identities and elevate access only when a task needs it.

Core principles

Microsoft 365 — how we connect

What Microsoft 365 Lighthouse does not do

Microsoft 365 Lighthouse is an overview across tenants, not a replacement for the admin centers. Services configured in the Microsoft 365 admin center and the specialized admin centers (Exchange, SharePoint, Teams, Microsoft Purview and others) cannot be managed inside Lighthouse. For that work we access the relevant admin center directly through GDAP, still with delegated, least-privilege access and no local account.

Azure — how we connect

You stay in control

You keep ownership and full visibility of both environments. You can see every delegation, review exactly which roles are granted, and revoke our access at any time. Access is least-privilege, time-bound and revocable, with no hidden admin accounts and nothing privileged left switched on when it is not being used.

Ready to connect your tenant?