AVD Manager par XOAP est là. Cliquez pour commencer  🚀

M365 Manager

M365 Manager

One console for Windows 365, Intune and Entra ID – and it tells you the truth

Cloud PCs, laptops, users, policies and reports side by side, live from Microsoft Graph. Start with the free 65-check tenant health check: read-only, no consent beyond Graph and it scores your tenant in one pass.

Aucune carte de crédit n'est requise
M365 Manager by XOAP
Fortifié par un écosystème robuste
Microsoft Azure AWS Google Cloud Platform GraphQL PowerShell GitHub Pâtissier Terraform VMware Citrix
The problem

Your estate is real. Your view of it isn't

Four records, one laptop

An Entra device object, an Intune enrollment, maybe a Cloud PC, maybe an Autopilot record. Four portals, four half-answers and the mismatches are exactly where the problems live.

Green dashboards that mean nothing

A tile shows 0 % non-compliant. Is the fleet clean, or did the read fail? Most consoles cannot tell you, because they never kept the difference.

Changes you cannot walk back

Someone edited a policy last Thursday. Which one, what did it say before and can you put it back?

One console

One console, drawn around your estate – not around Microsoft's APIs

Eleven tabs. A laptop is one row, not four lists. Licensing sits under Users, cloud apps under Apps, admin units under Groups – and every route stays a flat URL, so there is no hierarchy to learn.

Vue d'ensembleCloud PCsDispositifsUtilisateursGroupesAppsPolitiquesReports
DispositifUserSourcesState
LPT-0142j.weberEntraIntuneAutopilotConforme à la loi
CPC-ops-07m.kleinEntraIntuneCloud PCConforme à la loi
LPT-0388s.brandtEntraIntuneNot compliant
LPT-0415–EntraNot enrolled
One row per device · 5 sources merged
Tenant health checkRead-only
72%
Severity-weighted score64 of 65 checks assessed
HighLegacy authentication not blockedCEINIS2Fix with XOAP
MediumGuest invitations open to everyoneCEI
LowSelf-service password reset not configuredNIS2
Not assessedMissing permission · excluded from the score
Health check

Know how secure you are before anyone asks

65 curated read-only checks, scored severity-weighted, with CIS and NIS2 references and the evidence behind every finding. A check that could not be assessed says why and leaves the denominator alone.

CIS and NIS2 references are a mapping, not a verdict.

Safety net

Change anything. Revert everything

Every object XOAP touches is captured before the write. Change history on every list, a diff against the live object and a revert that records its own restore point first.

Config vault · Windows compliance policyCaptured before write
Edited Thursday, 14:32Diff against the live object
v14 → live
"osMinimumVersion": "10.0.22631",
−"passwordMinimumLength": 12,
+"passwordMinimumLength": 8,
−"bitLockerEnabled": true,
+"bitLockerEnabled": false,
"secureBootEnabled": true
Revert records its own restore point firstChange historyRevert
Customer tenants4 connected
Estate headline78%
▲ 3 vs previous run
Contoso84%▲ 2
Fabrikam71%▼ 1
Northwind79%▲ 5
TailspinPermission missing · rows degraded–
For MSPs

A score you can say out loud on the client call

A percentage per tenant, an estate headline across all of them and a change chip against the previous run. Standing access gets the same discipline: grant an Entra role for 1, 4, 8 or 24 hours with a reason, and revoke it early – requires Microsoft Entra ID P2.

Honest by design

A dash is not a bug. It's the point

When a read fails or a permission is missing, the console shows a dash and the reason – never a fake zero. Because "none found" and "never allowed to look" are not the same answer.

  • Every figure names its source
  • Every estimate is labelled an estimate
  • Every sensitive action lands in the audit log
Live data only

Commencez avec XOAP en quelques clics

Découvrez XOAP en action sans engagement. Compte gratuit, carte de crédit non requise.

Questions fréquemment posées

Questions, answered plainly

Does the health check change anything in my tenant?
No. The scan issues Microsoft Graph GET requests only – it is physically incapable of changing a tenant. Only Fix with XOAP writes, and each fix confirms its exact effect first.
What do you need access to?
One Entra app registration holding Graph application permissions, granted once by an administrator. The console shows all 47 permissions it can use, what each one unlocks and what breaks without it. A separate read-only principal reads Azure for image and network pickers.
Do you store our credentials?
No. Tokens are minted server-side per connection; the browser never performs a client-credentials exchange and never sees a client secret.
Does it work across customer tenants?
Yes – that is what it is built for. One aggregate view, a Tenant column on every list and one tenant's permission failure degrades only that tenant's rows.
Why does a number sometimes show as a dash?
Because it was not measured. Zero is a measurement; a dash is "we don't know". The console tells you which permission or licence would turn it into a number.
La plateforme

Une plateforme unique pour gérer l'ensemble de votre parc informatique hybride

XOAP regroupe la gestion des images, la configuration, les applications et Platform Management au sein d'une console unique, ce qui vous permet d'uniformiser les méthodes de travail, de démontrer votre conformité et de réduire les coûts liés à l'utilisation d'outils distincts.

M365 Manager · Free health check

See your tenant as it really is.

Run the free 65-check health check: read-only, live from Microsoft Graph. See every gap, why it matters and what fixes it.

Start for free No credit card required · Read-only scan
Retour en haut