puretenant
PT.AUDIT · 2026

Microsoft 365 licenses. Clear.

PureTenant analyzes your Microsoft 365 tenant in less than an hour and delivers a report dashboard that classifies every user as optimal, over- or under-licensed. An app that turns 20 fragmented admin centers, cryptic PowerShell outputs, and Excel tables into a single, identity-based report. Use it to manage security, compliance, and cost transparently.

Read-onlyCert-AuthGDPREU-Hosted
PT.AUDIT.cockpit contoso.onmicrosoft.com
00:38:24 LIVE
GRAPHusers.list — 412 entries fetched +38m24s
User classification 412 / 412
Anna Becker E5 E3 over
Marc Hoffmann E3 optimal
Sara Lopez F3 E3 under
Tim Walter E5 E3 over
Lisa Maier E3 optimal
Jan Roth E5 E3 over
Petra Schmidt E3 optimal
Oliver Krüger E5 E3 over
Total
412
100 % captured
Optimal
287
69.7 %
Savings / year
€18,420
net, after audit
Compliance
NIS2PASS
TISAX 5.1.1PASS
ISO 27001PASS
BSI Grundschutz3 OPEN
License distribution · current412 licenses
E5
E3
F3
96 over (E5) 287 optimal (E3) 29 under (F3)
STATUS ● COMPLETE
HMAC-BOUND READ-ONLY SHA256:8f2a…b1c4
38Min.
Audit-Dauer · ⌀
23%
Einsparung · ⌀ pro Tenant
100%
Read-only · keine Schreibrechte
3 285+
Tenants auditiert · seit 2024
Trusted by mid-market & enterprise
PT.02 · The Product

Microsoft 365 is complex. PureTenant makes it simple.

An app that turns 20 fragmented admin centers, cryptic PowerShell outputs and Excel sheets into a single, identity-centric report. What can otherwise only be surfaced manually — laborious and error-prone — becomes visible on one screen, exportable, archivable.

§ 02 — Value · p. 3 / 24
PT.02.01

20 admin centers → 1 report

Identity, Security, Compliance, Intune, Defender, Purview, Exchange, SharePoint, Teams. PureTenant consolidates every relevant data source — no fragmented tabs, no conflicting numbers.

Identity · Compliance · Security
PT.02.02

Identity-centric view

Every identity linked with licenses, roles, MFA status, sign-in activity, app access. Filter by department, location, risk. No data silo.

User · Group · Service principal
PT.02.03

What only PowerShell shows

Hidden admin roles, OAuth consents, orphaned service principals, conditional-access gaps. Visible — without anyone writing a single line of script.

GUI instead of Get-MgUser
PT.02.04

MFA gaps — one click

Identities without MFA, with legacy auth protocols, without CA coverage. Visually presented, ranked by risk class, an action list in seconds.

Conditional Access · Risk-based
PT.02.05

App-consent governance

Every third-party access to your tenant — with best-practice scoring. Which app reads mail? Which writes calendars? What was consented to, when?

OAuth · Enterprise apps
PT.02.06

Cost — by site, department, person

License costs broken down by cost center and service usage. Renewal negotiations with real numbers instead of gut feel. Excel export included.

FinOps · CSV / XLSX
PureTenant takes complexity out. Brings value in — for Security Compliance Regulation Cost
What we audit

Eight Microsoft 365 services. One single analysis run.

PureTenant scans your entire tenant — from identity through mail to compliance — in one choreographed run. No separate tools, no double approvals, no data exports.

PT.03·Status quo·2026

Licenses grow quietly.
Compliance asks loudly.

Three truths almost every Microsoft 365 tenant ignores — until the audit notice arrives or the renewal date is on the calendar.

§ 03 — Pain · p. 4 / 24
PT.03.1 — License drift
23%

On average, 23 % of all M365 licenses are over- or underlicensed.

Employees change roles but keep their old license. E5 for someone who only uses Outlook. F3 for someone who needs Power BI. The drift grows daily — no one sees it.

Source: PT audits 2024–2026
PT.03.2 — Regulation
2,026· NIS2

NIS2, TISAX 5.1.1 and ISO 27001 require documented license and access control.

“I think it’s fine” isn’t enough at audit time. You need an auditable point-in-time report — not just in emergencies, but as regular evidence in your ISMS.

NIS2 implementation · BSI Grundschutz
PT.03.3 — Consultant bill
25 k€ avg

External audit days cost €25k and up — per run, every year, anew.

PureTenant is not a consulting engagement, it’s software. Buy once, scan as often as you like. The report is yours, not the consultant’s.

Mid-market DACH · 5 audit days
PT.04·Process

Four steps. One hour.
Full clarity.

PureTenant connects to your tenant, reads read-only, cross-references the official license matrix, and returns the finished HTML report.

§ 04 — Process · p. 7 / 24
PT.04.1~ 5 min.
01

Setup

An app in your own tenant, upload the certificate, grant permissions — fully guided and highly automated by the setup assistant.

PT.04.2~ 38 min.
02

Scan

PureTenant reads read-only all data via Microsoft APIs.

PT.04.3~ 2 min.
03

Analysis

Cross-reference the license matrix, classify every user, mark security and compliance gaps, calculate savings in euros.

PT.04.4Instant.
04

Report

An HTML dashboard, runs locally, can be re-analyzed any number of times within the contract term.

PT.05·Report

One dashboard. All answers.

The result is a single, self-contained HTML file. No SaaS login, no external dependency. Open it in your browser, archive it in your ISMS, hand it to your auditor.

§ 05 — Output · p. 11 / 24
contoso-audit-2026-05-09.html
Optimal
287
69.7 % · 412 total
Savings / year
€18,420
net, after audit
License distribution · current
E5 · 96E3 · 287F3 · 29
Compliance · current
✓ NIS2 ✓ TISAX 5.1.1 ✓ ISO 27001 ⚠ BSI Grundschutz · 3 open
PT.05.1

Single-file HTML

A ~2 MB file. Open locally, archive locally — no server, no login, no cloud.

PT.05.2

Three languages

German, English, French — every UI string fully localised. Language switcher inside the report.

PT.05.3

Audit-proof

SHA-256 hash and HMAC tenant binding. Tampering with the report is detectable.

PT.05.4

Diff workspace

New report? Just load it against the previous one — changes are highlighted page-wide.

PT.06·Security

Read-only. App-only.
Certificate-based.

PureTenant cannot modify your tenant — technically excluded. Authentication runs via app-only certificate auth, no user credentials. No write permission is requested.

§ 06 — Trust · p. 14 / 24

Read-only by design

No write, delete, or mail-send rights are ever requested. Microsoft itself cannot use this app for write operations.

Certificate authentication

No client secret, no password. Authentication via X.509 certificate in the keystore of your audit host.

GDPR · EU hosting

License server, Mailgun, Stripe registered office — all in the EU. No data processing outside the EEA.

Compliance mapping

NIS2, TISAX 5.1.1, ISO 27001, BSI Grundschutz — all controls automatically checked, referenced in the report.

Minimum permissions Microsoft Graph · Application · all read-only
User.Read.AllUser
Directory.Read.AllOrg
Reports.Read.AllUsage
Organization.Read.AllSKU
RoleManagement.Read.DirectoryRBAC
Policy.Read.AllCA
SecurityEvents.Read.AllDefender
AuditLog.Read.AllLogs
DeviceManagementConfiguration.Read.AllIntune
DeviceManagementManagedDevices.Read.AllIntune
Sites.Read.AllSharePoint
Files.Read.AllOneDrive
PT.07·Pricing

One tier per tenant.
Per year.

You choose the tier yourself — the license is bound to your tenant ID, not exactly to user count. Auto-renewal, cancellable up to 4 weeks before expiry.

§ 07 — Tariff · p. 18 / 24
Included in every tier
XS
up to 100 users
2,000
net, plus VAT. · per year
S
up to 250 users
3,500
net, plus VAT. · per year
M
up to 1,000 users
5,000
net, plus VAT. · per year
L
up to 2,500 users
7,500
net, plus VAT. · per year
XL
up to 5,000 users
10,000
net, plus VAT. · per year
XXL
from 5,001 users
15,000
net, plus VAT. · per year

All prices net in EUR, plus statutory VAT. Reverse-charge procedure for EU business customers with valid VAT ID. Switzerland and United Kingdom on request. One license binds to exactly one Microsoft 365 tenant ID.

PT.08·Answers

Frequently asked.

Eight answers we have heard before every purchase — from IT admins, CISOs, executives.

§ 08 — FAQ · p. 22 / 24
FAQ.01 How fast is an audit completed?

On average 38 minutes for medium tenants (up to 1,000 users). For very large tenants (5,000+) up to 90 minutes. You don’t need to be present during the run — the analysis runs from the command line on an audit host of your choice.

FAQ.02 Which permissions does PureTenant need in our tenant?

Exclusively read permissions on Microsoft Graph — no write, delete, or mail-send rights. The list is shown above under “Security”. Your compliance officer can review it any time in the Entra portal.

The app registration is performed in your tenant — we have no access to it, unless you actively share the report with your IT partner.

FAQ.03 Where is the audit data stored?

With you. The report is processed in LocalStorage in the browser, locally with you. No tenant details are transferred. PureTenant is a SaaS product.

FAQ.04 How does this fit our NIS2/TISAX obligations?

The report contains its own section mapping to NIS2 (all 14 main controls), TISAX 5.1.1 (all 8 related controls), and ISO 27001 Annex A. You can file it as evidence in your ISMS — audit-proof, signed with SHA-256 and HMAC tenant binding.

FAQ.05 How many audits are included in the license?

Unlimited. A tier (XS to XXL) is bound to exactly one tenant ID. Within the license year you can analyze as often as you wish — e.g. monthly for ongoing compliance evidence.

FAQ.06 What happens if our user count exceeds the tier?

Nothing. The next tier only changes with the new contract term. You switch the tier pro-rata.

FAQ.07 Can we test before purchase?

Yes. You can view demo data via a sample access and get an impression of what will be displayed to you.

FAQ.08 Who is behind PureTenant?

Michael Bauer — 33 years of IT experience. Of which 10 years at Bechtle and 15 years self-employed. PureTenant is an independent product based in Germany, white-label, no external investor structure.

PT.09 · Get started

Ready for clarity?

Choose a license, enter the tenant ID, start the audit. First insights in less than an hour — even if you have never run an M365 audit yourself before.