EP365 Identity Manager Microsoft 365 accounts and groups, clear and under control
Group classification, a health score, access recertification, risks and guest management — all on top of the Microsoft 365 accounts and groups you already have. No costly extra tool, no scripts, no over-privileged account.
Sound familiar?
This is what companies with dozens to hundreds of groups tell us before they deploy Identity Manager. Not because IT is untidy — but because Microsoft 365 groups grow for years and nobody is responsible for keeping them in order.
“We have two hundred groups. Half of them, nobody knows what they're for.”
Names like HR-2019, Project-Alfa or Test-Mark with no rhyme or reason. No labels, no sensitivity. At audit time you're left guessing what is actually sensitive and what isn't.
“Who actually owns this group?”
After years of growth, half the groups have an empty owner field. When nobody is responsible for the content, membership swells and no one reviews it.
“Access reviews? We don't do them at all.”
Former employees, guests from long-finished projects, dead distribution lists. Least privilege falls apart and a NIS2 audit is knocking at the door.
What Identity Manager does about it
Five things that finally make the directory make sense. You'll find the complete feature list below in the details.
A group overview with a health score
One list of every group and user in your Microsoft 365. For each group you see a health score, classification, and the number of members, owners and guests. Filters, full-text search and a quick command palette take you to any group in a second.
A fragmented view across portals one view of the whole directory
Access risks in black and white
The app finds groups without an owner, guests in sensitive groups, and public groups that shouldn't be public. Every risk carries a severity score, and one click takes you straight to remediation.
Manually hunting for permission gaps a list of risks ranked by severity
Access recertification
You launch a review round and, for each group, the reviewer confirms or removes access. The app tracks deadlines and the history of decisions — and you don't need a pricier Microsoft licence for it.
Directory clean-up
It finds ownerless orphans, empty and long-unused groups, and duplicates with similar names. It offers them for merging or archiving — the decision is always yours.
Users and external guests
An overview of internal accounts and external guests in one place. For guests you see who invited them, their last sign-in and inactive accounts. A suspicious account is blocked in one click.
The fastest route: 30 minutes at a screen.
No company slideshow. We share a screen and click through the app on sample directory data — you'll see exactly what your administrator would see.
„For the first time in years we know what every group is for and who is responsible for it. This year the access audit was a matter of an export, not a three-day panic.“
Manufacturing company · 280 employees · 190 groups
Deployment took five days from the kick-off call — including group classification, owner assignment and the first recertification round. Without a single script, entirely through the user interface.
For those who want to know more
Everything that matters in one place — features, a comparison with the alternatives, security, pricing and answers to common questions.
Group overview and search
One list of every group — internal and cloud — live from your Microsoft 365. For each group: a health score and the number of members, owners and guests. Filters by type, status and management, full-text search, saved views and a command palette to jump to any group or screen.
Classification and taxonomy
Custom classification schemes and trees — sensitivity, labels, categories. You finally know what each group is for and how sensitive it is. Bulk classification of several groups at once and a record of the responsible administrators for each group.
Members, owners and rules
Manage members and owners directly from the app, create new groups, and set dynamic membership rules based on user attributes — including ready-made templates. Batch add and remove members in one go.
Access recertification
A regular review as a simple process: an administrator launches a round and, for each group, the reviewer confirms or removes access. Deadlines, decision history and a “to review” queue for every reviewer — with no need for a pricier Microsoft licence.
Access risks
Detection of least-privilege breaches: groups without an owner, guests in sensitive groups, public groups, and sensitive yet exposed permissions. A severity score and a filter; a click opens the group detail straight at remediation.
Directory clean-up
It finds ownerless orphans, empty and long-unused groups, and duplicates — spotting similar names by comparing without diacritics and matching e-mail prefixes. It offers remediation and a merge suggestion right away; the decision is always yours.
Teams and lifecycle
Create a Microsoft Teams team on top of a company group in one click. A governed lifecycle: archiving as a flag (nothing is deleted) and controlled group deletion with confirmation — synchronised groups stay protected.
Change audit and reports
The history of each group merges the real Microsoft 365 audit with the app's derived events. Export membership and owners to CSV, a usage overview and the recertification decision trail — a direct basis for NIS2 and ISO 27001.
User and guest management
An overview of every account — internal members and external guests — in one place. For guests you see who invited them, their last sign-in and inactive accounts. Guest classification (supplier, partner, client), an internal sponsor and the reason for the invitation. A suspicious or unneeded account is blocked in one click, straight from the app.
Everything in your Microsoft 365
Groups, users and the audit stay in your environment. The app acts on your behalf — it does nothing that an administrator can't do in Microsoft 365 themselves. No third-party cloud, no over-privileged account, no copy of your data leaving.
Roles and clear administration
Two roles: an administrator with full governance and a regular user with an overview. Who may make changes is controlled by licensing. Group deletion is additionally protected by confirmation, and synchronised groups cannot be deleted.
Connection to EP365 Hub
Groups past their recertification deadline surface as alerts in the global My Operations overview. The administrator sees governance tasks alongside tasks from the other EP365 apps in one place.
Acts on your behalf
The app works with Microsoft 365 accounts and groups on your behalf — not through an over-privileged account. What you as an administrator can't do, the app won't do either. No service account, no unlimited permissions.
Data stays with you
Groups and users stay in your Microsoft 365, and so do classification, reviews and the audit. No server of ours holds your data; nothing leaves your environment.
Least privilege in practice
The app itself helps enforce least privilege — access risks, recertification and clean-up reveal where someone has access they no longer need.
Audit for NIS2 / ISO
The real Microsoft 365 audit plus a verifiable decision trail: who confirmed or removed access, and when. A direct basis for NIS2 and ISO 27001 in access management.
Roles and governed access
Administrator versus regular user. With an inactive licence the app runs read-only — no group changes. Deletion is additionally protected by confirmation, and synchronised groups cannot be deleted.
No extra new cloud
No unlimited-access permissions, no service account, no additional cloud. Governance runs on top of the Microsoft 365 you already have and pay for.
Price by company size
The price is based on the size of the organisation, i.e. the total number of users. An unlimited number of managed groups and administrators — you pay for the size of the environment, not the number of groups.
On-site implementation
We help you get started: deployment support, classification setup and training for application administrators.
The exact price depends on company size and the scope of the initial classification setup. We'll send a precise quote after a short call.
Support pricing
Consultations, classification setup, custom reports or preparing recertification rounds.
Support is billed per started 15 minutes of work. We always tell you the expected scope in advance.
Do we need a pricier Microsoft licence?
Does the app do anything I as an administrator can't do myself?
Does any of our data leave?
Isn't deleting groups dangerous?
Does it work with all group types?
Can it manage users and external guests too?
Does recertification replace Microsoft's built-in access reviews?
How do you spot duplicate groups?
Do we need any scripts or an IT specialist?
Is it ready for NIS2 and ISO 27001?
Can it handle hundreds of groups?
Does it integrate with the other EP365 apps?
Further reading on the blog
Need help putting your SharePoint in order first? Explore our audit, governance and care services
What exactly do you want to discuss?
Pick what's burning most right now. We'll get back to you, walk through your situation and propose next steps, including an indicative price.