Free and open source ยท Built for MSPs

Microsoft 365 reports for every client, without the busywork

Office Sentry reads each client's Microsoft 365 tenant every night, keeps the history and turns it into the reports you actually send: a branded monthly review, an insurance evidence pack, about 30 detail reports, a view across every client and what changed since last month.

No sign-up. The demo has three fictional clients and resets every night.

A client's overview: key figures, what needs attention and what changed since last month

Read-only by design

It asks Microsoft for read permissions only, so it can't change anything in a client's tenant.

Keeps the history

Every night's results are kept, so you can see what changed, when, and whether it got better.

Every client side by side

Compare any report across all your clients, worst first, and open the rows behind any figure.

Your brand, plain English

Reports carry your logo and colours and explain findings in words a client understands.

What you get

The reports an MSP sends, ready when you need them

Office Sentry does the gathering every night for every client. You review the report and send it, or let it email itself.

A monthly review your clients will read

The Monthly Security & Licensing Review opens with a verdict and a plain-English summary, then the figures that matter.

  • Key figures with their four-week change
  • What to fix first, and what changed
  • Secure Score, and licence waste in money
  • A web page, a branded PDF and a spreadsheet
Open the example PDF
The monthly review in the portal
The monthly review on a phone

About 30 detail reports you can filter, save and export

Identity, email, files, devices and licences: MFA coverage, mail forwarding, mailbox permissions, sign-ins, Conditional Access, licence right-sizing and more.

  • Filter by any value or date, sort and hide columns
  • Save a view and reuse it on any client
  • PDF, XLSX and CSV downloads contain exactly the rows shown
  • Every headline figure opens the rows behind it
See every report
MFA coverage: who has set up MFA, who is required to, and where the two differ

Every client at once, and what changed

All tenants compares any report across every client, one row each. What changed lists the month's changes, most important first: new and fixed findings, admins, accounts, Conditional Access, forwarding, apps and devices.

  • Every figure is clickable
  • A row-by-row comparison of every detail report
Open the What changed PDF
All tenants: the monthly review's figures for every client

SharePoint storage: why it's full and what to clean up

See how full a tenant is and when it will run out at the current rate, where the space goes, and the biggest folders, files, version histories and recycle bin items, each with what to do about it.

Open the 19-page example
SharePoint storage: 88% used, full in about 3 months, and where the space goes

Insurance evidence, answered from the data

The evidence pack answers the controls cyber-insurance questionnaires ask about, such as MFA, admin accounts, legacy sign-in, email authentication, forwarding, leavers and devices, with the gaps listed.

Open the example pack
Insurance evidence: each control with the evidence and the gaps
An account page: needs attention, MFA, admin roles, licences and devices

One page per person

Sign-in, MFA, admin roles, licences, mailbox forwarding, devices and sharing for one account, with how it changed. Handy for offboarding and "was this account compromised?"

Recommended projects for every client, worst first

Projects to recommend

Findings become the projects an account manager can propose, with a branded proposal PDF. A project drops off once the tenant is fixed.

Schedules, alerts, contacts and the delivery history

Emailed reports and alerts

Any mix of reports weekly, monthly or quarterly in the client's timezone, plus alert emails and Teams, Slack or webhook alerts.

What a client sees when they sign in

A view for your clients

Client users sign in and see only their own organisation's reports and downloads, never another client or how collection works.

See it for yourself

Open the demo and click around three fictional clients with five weeks of history. Nothing can be changed, and it starts fresh every night.

Open the live demo

Example reports

See what your clients would get

Real exports from Office Sentry, made from fictional demo data.

Security

It holds read access to many clients, so it does as little as possible with it

Read the security model
  • Read-only by construction. One app asks only for read permissions. The code has no way to write to Microsoft Graph, and only runs Exchange commands that start with Get-.
  • Certificate sign-in, no stored passwords. The app signs in with a certificate whose private key is encrypted in the database. Secrets and private keys can never be downloaded.
  • Every client kept apart. People see only the tenants they're given, and clients see only their own reports.
  • Runs on your own server. Your clients' data stays with you. There's no telemetry: nothing is sent to us.

Get started

Up and running on your own server

Office Sentry runs as two Docker containers with everything in one volume. No database server, no Redis.

  1. 1

    Start it

    Download the compose file, set your domain and timezone, and run docker compose up.

  2. 2

    Create the read-only app

    One command creates the app in your own Microsoft tenant, with its certificate.

  3. 3

    Add your clients

    Each client approves read access once. The first reports are ready after the first collection.

Questions

What does it cost?

Nothing. Office Sentry is free, open-source software under the AGPL-3.0. You run it on your own server; a small cloud server is enough for most MSPs.

Can it change anything in a client's tenant?

No. It only asks Microsoft for read permissions, and its code can't write to Microsoft Graph or run Exchange commands other than ones that read.

Does it read anyone's email?

No. It reads settings, mailbox details such as size, forwarding and permissions, and inbox rules, never message contents. What Office Sentry reads lists every permission, written for your clients.

Where is the data kept?

On your own server, in one database you can back up and restore. Office Sentry has no telemetry, so nothing is sent to us.

How is it different from Microsoft's own admin centres?

Microsoft shows one tenant at a time, in its own words, with little history. Office Sentry keeps every night's results for every client, compares them month by month and across clients, and turns them into branded reports.