Support
Admin Companion support — let's get you moving
Most questions we get are about connections and permissions — which makes sense, because that's the only part where Admin Companion depends on something outside itself. Start below.
Before you write in
The three things worth checking first
-
Re-run the connection test
In Settings → Connections, run the test probe. It records which Graph permissions were actually granted and which license features were detected. Controls, reports and actions are gated on that result, so a check that's missing from the list is usually a consent or licensing gap rather than a bug.
-
Check for an expiring credential
Connection certificates expire, and an expired certificate looks a lot like a broken integration. Expiry is tracked and surfaced on the dashboard — and Admin Companion can generate and rotate the certificate for you.
-
Look at the audit log
Settings → Audit log records membership changes, role grants, sign-on configuration edits and every remediation with before and after values, the actor, and a correlation id. If something changed and nobody remembers doing it, that's where the answer is.
FAQ
Questions we get a lot
Do I have to install anything in my tenant?
No. Admin Companion connects app-only using a certificate, and reads through the Microsoft admin APIs. There are no agents, no servers and nothing deployed inside your environment.
Which standards does it actually check against?
Recognized, published industry baselines — not a house ruleset. Two independent, versioned frameworks ship, with 283 automated controls between them, and your tenant picks the version it's assessed against. Every control keeps its published identifier, so findings trace straight back to the source document your auditor already knows. Happy to name names and walk the control lists on a call.
Will it change things in my tenant without asking?
Not unless you set it up that way. Assessments only read. Remediations and actions are things you start, and anything tenant-locking runs in approval-gated mode: it builds a preview of exactly what it would touch, then waits for a configurable quorum of tenant-admin approvals. A single rejection vetoes the run, and an undecided run expires at its deadline rather than firing late.
Scheduled runs are opt-in — every new schedule starts off.
A control shows as "manual". Is that a failure?
No. Some controls can be evidenced but not decided by a machine, so rather than guess, Admin Companion resolves them to a manual outcome. You record a dated attestation with a written rationale and an optional expiry, and the control then counts as satisfied in your secure score without re-running the assessment. A reminder sweep chases attestations that are about to lapse.
What if we're deliberately not fixing something?
Record an accepted-risk acknowledgment against it, with a rationale and an optional expiry. The row stays visible and is marked as accepted risk rather than vanishing from the list, it's keyed per tenant, framework and control so it applies to later assessments too, and the acknowledgment itself is written to the audit log.
Can I send a report to someone who doesn't have an account?
Yes. A finished report run can be emailed to any recipient list, including external addresses with no Admin Companion account. The download link is bounded twice: it expires after a time window and after a fixed number of downloads, so a forwarded email can't keep working forever.
How long is data kept?
Audit retention is configurable, with a platform default and per-tenant and per-user overrides, enforced by a purge job. The shipped defaults are roughly seven years for tenant and platform audit logs and two years for user account activity, with a permitted range of 30 days to ten years.
Where does our data live?
The platform is hosted in Europe, with European data residency for email delivery too. Your tenant's data is kept strictly separate from every other customer's — the isolation is structural, not a configuration setting.
Can we use our own identity provider?
Yes — each tenant can bring generic OIDC or Entra ID with claim mappings, and credential expiry is monitored and warned on. For accounts signing in directly, Admin Companion supports TOTP authenticator apps, passkeys (WebAuthn) and recovery codes.
We've hit a quota. What now?
Quotas cover assessments, reports, actions and remediations over a rolling 30-day window, plus a cap on concurrent jobs. There's a request form in the app — Settings → Quota — that sends your reasoning straight to us, and we'll come back to you.
Didn't find it?
Tell us what you're trying to do and we'll point you at the right screen — or fix the thing that made you ask.