Security & trust

Touch every client tenant.
Without becoming their biggest risk.

A tool that connects to all your clients' Microsoft 365 tenants is only worth adopting if it can't become your single point of failure. Here's exactly how Octopane is built so it never is.

It's the first question every MSP owner asks, and the right one: “if you can reach all my clients' tenants, doesn't a breach on your side become a breach on mine?”

Our answer is architectural, not a promise. Octopane runs on least-privilege, app-only Microsoft Graph access that your client grants and can revoke, no global admin, no stored credentials, no access to their mail or files. The blast radius is deliberately small.

Access model

How access actually works

No global admin, ever

Octopane is a single multi-tenant Entra application. A client's Global Admin approves one consent link; from then on access is app-only Microsoft Graph, scoped to exactly the permissions they approved. We never ask for, or hold, a global admin account.

No GDAP, no shared passwords

No CSP enrollment, no GDAP relationships, no stored credentials, no break-glass logins sitting in a vault. Authentication stays with Microsoft. There's no password for us to leak.

Revocable in one click, by the client

The client owns the consent. They can revoke Octopane's access at any time from their own Entra portal, without asking you or us. Disconnecting a tenant deletes its synced data.

We never read mail or files

Octopane reads directory metadata, users, licenses, MFA state, Conditional Access summaries, Secure Score. We never request, read, or store mailbox, OneDrive or SharePoint content.

Every write is a tracked job

Bulk actions (MFA enforce, password resets, enable/disable) run as tracked jobs attributed to a named technician in an immutable audit log. You can always answer "who changed what, where, and when."

Console secured by Clerk + MFA

Your workspace is protected by Clerk with enforced MFA for technicians and role-based access. Tenant calls use short-lived, app-only tokens, not long-lived secrets.

Your data

What we store, and what we don't

What we store

Synced directory metadata only: user profiles, license assignments, MFA registration state, Conditional Access policy summaries, and Secure Score history, the data that powers your dashboards.

What we never store

Passwords or credentials (authentication stays with Microsoft), and mailbox / OneDrive / SharePoint content. Disconnect a tenant and its synced data is removed.

Where it lives

Hosted on AWS (eu-west-1), encrypted in transit and at rest. Data is logically isolated per workspace. A per-tenant privacy toggle lets you honor report anonymization where a client requires it.

Compliance

Where we are on certifications

We'd rather be honest than tick a box we haven't earned.

Octopane is built on the same security primitives the largest M365 tools rely on: Microsoft Graph app-only auth, encryption in transit and at rest, and least-privilege scoping. SOC 2 Type II is on our roadmap; until it's complete we won't claim it.

Need a security questionnaire answered or a one-pager for your own compliance file? support@octopane.io , a human replies.

FAQ

Security questions, answered

How does access to my clients' tenants work?

Octopane is a single multi-tenant Entra ID application. You send your client one admin-consent link; a Global Admin clicks approve once, and the tenant starts syncing within minutes. Access is app-only Microsoft Graph, no stored credentials, no shared admin accounts, and the client can revoke it at any time from their own Entra portal.

Do I need GDAP or Microsoft partner status?

No. That's the point. Microsoft Lighthouse requires CSP enrollment and GDAP relationships per customer; CIPP needs GDAP plus SAM app setup. Octopane only needs that one consent link. It works for any client tenant, whether or not you resell their licenses.

What data do you store?

Synced directory metadata only: user profiles, license assignments, MFA registration state, Conditional Access policy summaries and Secure Score history. We never see or store passwords, authentication stays with Microsoft, and we never read mailbox or file content.

How is access to the console secured?

Your workspace is secured by Clerk with enforced MFA for technicians. Tenant access uses short-lived, app-only Graph tokens scoped to the permissions your clients consented to. Every write action runs as a tracked job, attributed to a technician in the audit log.

Give every tenant eight arms.

Connect your first client in minutes, no GDAP, no PowerShell, no partner paperwork. 14 days free, all features unlocked.

Octopane · Every Microsoft 365 tenant. One pane of glass.