No. EntraSight uses read-only Microsoft Graph API access. We never store secrets or certificates — only metadata like expiry dates and app names. Your credentials never leave Microsoft's infrastructure.
What permissions do you need?
We request Application.Read.All, Directory.Read.All, and AuditLog.Read.All — all read-only. We request the minimum permissions needed to monitor your tenant. No write access, ever.
Can I monitor multiple tenants?
Yes. Pro and above support multiple tenants. Each tenant admin completes a simple one-time admin consent — no credentials shared, no agents installed. Remote admins can be sent a link to complete consent without needing an EntraSight account.
Is the trial feature-limited?
No. Every plan includes a full 30-day trial with all features unlocked — ownership tracking, sign-in monitoring, rotation workflows, alerting, exports, everything. No credit card required to start. You only pay if you decide to continue after the trial ends.