Skip to content
EP365 · App for Microsoft 365
Group, user and access management

EP365 Identity Manager Microsoft 365 accounts and groups, clear and under control

Group classification, a health score, access recertification, risks and guest management — all on top of the Microsoft 365 accounts and groups you already have. No costly extra tool, no scripts, no over-privileged account.

No more ownerless groups. For every group you see who is responsible for it and how sensitive it is — all in one place.
Access gets reviewed — you launch a review round and the app tracks deadlines and who confirmed or removed what.
Audit in one click. Who added a guest to a sensitive group? Evidence for NIS2 and ISO is a few minutes away in an export.
Data stays in your Microsoft 365 Deployed in days From CZK 3,000 per month
Directory status · 190 groups
Thursday 14 May
190groups in total
38without an owner
7to recertify
12access risks
Groups with a health score
Marketing-Teaminternal · sensitivehealth 92
HR-Payroll-Allsensitive · guesthealth 61
Project-Alfaunclassifiedno owner
All-Companypublic M365health 74

Sound familiar?

This is what companies with dozens to hundreds of groups tell us before they deploy Identity Manager. Not because IT is untidy — but because Microsoft 365 groups grow for years and nobody is responsible for keeping them in order.

“We have two hundred groups. Half of them, nobody knows what they're for.”

Names like HR-2019, Project-Alfa or Test-Mark with no rhyme or reason. No labels, no sensitivity. At audit time you're left guessing what is actually sensitive and what isn't.

“Who actually owns this group?”

After years of growth, half the groups have an empty owner field. When nobody is responsible for the content, membership swells and no one reviews it.

“Access reviews? We don't do them at all.”

Former employees, guests from long-finished projects, dead distribution lists. Least privilege falls apart and a NIS2 audit is knocking at the door.

What Identity Manager does about it

Five things that finally make the directory make sense. You'll find the complete feature list below in the details.

A group overview with a health score

One list of every group and user in your Microsoft 365. For each group you see a health score, classification, and the number of members, owners and guests. Filters, full-text search and a quick command palette take you to any group in a second.

A fragmented view across portals one view of the whole directory

Access risks · Top 3
HR-Payroll-All · guest not reviewed
Project-Alfa · group without an owner
All-Company · public M365 group
Directory health score · 72 %

Access risks in black and white

The app finds groups without an owner, guests in sensitive groups, and public groups that shouldn't be public. Every risk carries a severity score, and one click takes you straight to remediation.

Manually hunting for permission gaps a list of risks ranked by severity

Access recertification

You launch a review round and, for each group, the reviewer confirms or removes access. The app tracks deadlines and the history of decisions — and you don't need a pricier Microsoft licence for it.

Directory clean-up

It finds ownerless orphans, empty and long-unused groups, and duplicates with similar names. It offers them for merging or archiving — the decision is always yours.

Users and external guests

An overview of internal accounts and external guests in one place. For guests you see who invited them, their last sign-in and inactive accounts. A suspicious account is blocked in one click.

The fastest route: 30 minutes at a screen.

No company slideshow. We share a screen and click through the app on sample directory data — you'll see exactly what your administrator would see.

Pick a demo slot Free and without obligation · online in Teams
What we cover in 30 minutes
5 min Your current practice — how many groups you have and what hurts most about managing them
10 min The group overview with a health score, classification and access risks, live
10 min Access recertification, directory clean-up and external guest management
5 min What a rollout would look like for you + an indicative price

„For the first time in years we know what every group is for and who is responsible for it. This year the access audit was a matter of an export, not a three-day panic.“

Manufacturing company · 280 employees · 190 groups

Deployment took five days from the kick-off call — including group classification, owner assignment and the first recertification round. Without a single script, entirely through the user interface.

190 → 142 groups after directory clean-up
100 % of groups have an owner and classification
24 sensitive groups in the first recertification

For those who want to know more

Everything that matters in one place — features, a comparison with the alternatives, security, pricing and answers to common questions.

Group overview and search

One list of every group — internal and cloud — live from your Microsoft 365. For each group: a health score and the number of members, owners and guests. Filters by type, status and management, full-text search, saved views and a command palette to jump to any group or screen.

Classification and taxonomy

Custom classification schemes and trees — sensitivity, labels, categories. You finally know what each group is for and how sensitive it is. Bulk classification of several groups at once and a record of the responsible administrators for each group.

Members, owners and rules

Manage members and owners directly from the app, create new groups, and set dynamic membership rules based on user attributes — including ready-made templates. Batch add and remove members in one go.

Access recertification

A regular review as a simple process: an administrator launches a round and, for each group, the reviewer confirms or removes access. Deadlines, decision history and a “to review” queue for every reviewer — with no need for a pricier Microsoft licence.

Access risks

Detection of least-privilege breaches: groups without an owner, guests in sensitive groups, public groups, and sensitive yet exposed permissions. A severity score and a filter; a click opens the group detail straight at remediation.

Directory clean-up

It finds ownerless orphans, empty and long-unused groups, and duplicates — spotting similar names by comparing without diacritics and matching e-mail prefixes. It offers remediation and a merge suggestion right away; the decision is always yours.

Teams and lifecycle

Create a Microsoft Teams team on top of a company group in one click. A governed lifecycle: archiving as a flag (nothing is deleted) and controlled group deletion with confirmation — synchronised groups stay protected.

Change audit and reports

The history of each group merges the real Microsoft 365 audit with the app's derived events. Export membership and owners to CSV, a usage overview and the recertification decision trail — a direct basis for NIS2 and ISO 27001.

User and guest management

An overview of every account — internal members and external guests — in one place. For guests you see who invited them, their last sign-in and inactive accounts. Guest classification (supplier, partner, client), an internal sponsor and the reason for the invitation. A suspicious or unneeded account is blocked in one click, straight from the app.

Everything in your Microsoft 365

Groups, users and the audit stay in your environment. The app acts on your behalf — it does nothing that an administrator can't do in Microsoft 365 themselves. No third-party cloud, no over-privileged account, no copy of your data leaving.

Roles and clear administration

Two roles: an administrator with full governance and a regular user with an overview. Who may make changes is controlled by licensing. Group deletion is additionally protected by confirmation, and synchronised groups cannot be deleted.

Connection to EP365 Hub

Groups past their recertification deadline surface as alerts in the global My Operations overview. The administrator sees governance tasks alongside tasks from the other EP365 apps in one place.

Area
EP365 Identity Manager
Microsoft 365 portal (manual)
Large IGA tool
Group overview + health
one view
fragmented
comprehensive
Classification and taxonomy
custom schemes
none
yes
Access recertification
a simple process
manual
yes
Access risks
least privilege
manual
yes
User and guest management
blocking + classification
fragmented
yes
Clean-up of duplicates and empties
automatic detection
manual
partially
Audit for NIS2 / ISO
audit + decision trail
system log only
yes
Acts on your behalf
yes, no over-privilege
yes
over-privileged account
Price
from CZK 3,000 / month
included in M365
costly licence + tool
Deployment
in days
manual effort
weeks to months

Acts on your behalf

The app works with Microsoft 365 accounts and groups on your behalf — not through an over-privileged account. What you as an administrator can't do, the app won't do either. No service account, no unlimited permissions.

Data stays with you

Groups and users stay in your Microsoft 365, and so do classification, reviews and the audit. No server of ours holds your data; nothing leaves your environment.

Least privilege in practice

The app itself helps enforce least privilege — access risks, recertification and clean-up reveal where someone has access they no longer need.

Audit for NIS2 / ISO

The real Microsoft 365 audit plus a verifiable decision trail: who confirmed or removed access, and when. A direct basis for NIS2 and ISO 27001 in access management.

Roles and governed access

Administrator versus regular user. With an inactive licence the app runs read-only — no group changes. Deletion is additionally protected by confirmation, and synchronised groups cannot be deleted.

No extra new cloud

No unlimited-access permissions, no service account, no additional cloud. Governance runs on top of the Microsoft 365 you already have and pay for.

Licence

Price by company size

Up to 25 users
CZK 4,000 / month
26–70 users
CZK 6,000 / month
71–150 users
CZK 8,000 / month
More than 150 users
Individual

The price is based on the size of the organisation, i.e. the total number of users. An unlimited number of managed groups and administrators — you pay for the size of the environment, not the number of groups.

Deployment

On-site implementation

CZK 8,800–17,600 one-off

We help you get started: deployment support, classification setup and training for application administrators.

What affects the price

The exact price depends on company size and the scope of the initial classification setup. We'll send a precise quote after a short call.

Extended support

Support pricing

CZK 2,200 / hour

Consultations, classification setup, custom reports or preparing recertification rounds.

How support is billed

Support is billed per started 15 minutes of work. We always tell you the expected scope in advance.

Prices exclude VAT
Do we need a pricier Microsoft licence?
For most features a standard Microsoft 365 is enough. Dynamic membership rules require a higher plan — that's a Microsoft licensing condition, not ours. You can do recertification, access risks and clean-up even without the most expensive plan, so access reviews don't force you to pay more.
Does the app do anything I as an administrator can't do myself?
No. Identity Manager acts on your behalf — it works with Microsoft 365 accounts and groups just as you would yourself. If there's a change you're not allowed to make, the app won't make it either. No over-privileged permissions, no service account.
Does any of our data leave?
No. Groups and users stay in your Microsoft 365, and so do classification, reviews and the audit. No server of ours holds your data. Everything runs inside your environment.
Isn't deleting groups dangerous?
Deletion is protected: only an administrator may do it, it's confirmed with a checkbox, and synchronised groups cannot be deleted. If you just want to take a group out of service, use archiving — it's merely a flag and deletes nothing in Microsoft 365.
Does it work with all group types?
Yes. The overview, classification, risks and recertification cover both security groups and Microsoft 365 and Teams groups. Creating a team in Microsoft Teams applies only to cloud Microsoft 365 groups.
Can it manage users and external guests too?
Yes. The Users section gives you an overview of internal members and external guests — with guest classification, an internal sponsor, last sign-in and identification of inactive accounts. A suspicious or unneeded account can be blocked, or unblocked, straight from the app. External guests are the biggest access risk, so you keep them under control alongside groups.
Does recertification replace Microsoft's built-in access reviews?
It's a lighter alternative. Instead of the most expensive plan and its access reviews, you get a simple review-round process right inside your Microsoft 365 — the reviewer confirms or removes access, all with deadlines and history. For companies that don't have, or don't want, the pricier plan.
How do you spot duplicate groups?
By comparing names without diacritics, word similarity and matching e-mail prefixes — from data we already have loaded. We offer suspicious pairs for merging; the decision is always yours.
Do we need any scripts or an IT specialist?
No. Everything happens through a clear interface — overview, classification, reviews and clean-up. No scripts, no command lines, no service accounts.
Is it ready for NIS2 and ISO 27001?
The access audit — the real Microsoft 365 audit merged with the recertification decision trail — is a direct basis for access management under both NIS2 and ISO 27001. Exporting to CSV for an auditor is a matter of a click.
Can it handle hundreds of groups?
Yes. Lists are paginated, and there's full-text search, filters and a quick command palette to jump to any group. The health score and risks tell you where to start, even with hundreds of groups.
Does it integrate with the other EP365 apps?
Yes. Groups past their recertification deadline surface as alerts in EP365 Hub — in the global My Operations overview. The administrator thus sees governance tasks alongside tasks from the other EP365 apps.