FAQ

Questions, answered plainly.

Not here? Write to support@glacierpointtech.com.

The product

What exactly is read?

The subscriptions of your tenant with their purchased and assigned units, every user with the licenses and service plans assigned to it and how they were assigned, the account state, the sign-in activity, the guests, and the shared, room and equipment mailboxes with their licenses. That is all: no mail, no files, no chats.

How is the waste priced?

At your own price per SKU if you typed one in for the tenant, else at Microsoft's commercial list price in US dollars per user per month at annual commitment, from a signed table with a version and an as-of date shown on the report. A SKU the table does not know is listed with "price not known" and counts as zero until you type a price.

Which checks run?

Eleven: unassigned licenses, overlapping licenses, disabled users still licensed, stale users, never-activated users, guests, shared and resource mailboxes with licenses, license assignment errors, add-ons without a base, service plans disabled inside a SKU, and subscriptions ending. The first nine are priced; the last two are listed without a price.

What does the stale-users check need?

Sign-in dates, which Microsoft provides through sign-in activity to tenants with Entra ID P1 or P2. Without them the check says "needs Entra ID P1" and falls back to the creation date and "never signed in". The number of days is 90 by default; 30, 60, 90 or 180 per tenant.

How often does it run?

Whenever you press Run in the Windows app. With Watch and MSP, also on a schedule: weekly by default, daily at most, as a Windows task on a computer you choose, with an app registration you own and a certificate whose private key stays on that computer.

Security and data

Does it change anything in the tenant?

No. Every check is a read. The app asks for read permissions only, and there is no write permission in the product. Releasing a license, removing a user from a group or converting a mailbox is yours to do in the admin center; the report tells you which.

What permissions does the app ask for?

Organization.Read.All, Directory.Read.All, User.Read.All, AuditLog.Read.All for sign-in activity and, optionally, Reports.Read.All for usage, asked on Microsoft's own sign-in page with a consent card that names each one, plus the Exchange Online administrator read for the mailbox check. The security page lists them.

Can you access our tenant?

No. We hold no password, token, secret or certificate for any tenant. The app signs in as you, and scheduled runs use an app registration your organization owns with a certificate that stays on your computer.

Where are the findings kept?

In the portal, encrypted. A run is sealed on your computer before upload and stored encrypted at rest; the portal opens it to price the findings and to show the report to the members of your workspace. Logs and the activity record hold counts and codes, never a user's name.

Buying

Is there a free trial?

The Preview is free: one tenant, up to 3 runs, the savings card with every headline figure, and every check with its count and its cost, with the first 5 rows of each list. A plan unlocks every row, the CSV and PDF exports and your own prices.

How do we pay?

By invoice for now; card payments are coming. Prices and billing questions.

What happens when a plan ends?

A plan runs until its end date; it does not renew by itself, and renewing is a new invoice. When a plan ends the tenant returns to the Preview: no scheduled runs, no alerts, and the lists show their first 5 rows again. The runs of the plan stay readable for 30 days.

We are a managed service provider. Is there a plan for us?

Yes: the MSP plan keeps all your customers' tenants in one workspace, with a tenant table of each customer's waste figure and last run, at a platform fee plus a price per tenant. Talk to us about the numbers.