Who can access what in your Microsoft 365?
just IDM knows. Transparently.
The management layer on top of your Entra ID: users, roles, teams, mailboxes and licenses — modeled as roles, provisioned automatically, traceable at any time. In your own Azure environment.
just IDM
Übersicht
Benutzer
Rollen
Zugriffe
Teams
Lizenzen
Audit
Rollen & Zugriffe
+ BeauftragenAudit-Log
Rolle zugewiesen
Vertrieb Innendienst → M. Beispiel
Team freigegeben
TEAM-VTR-Angebote
Lizenz-Abweichung begründet
E5 statt E3 · Ticket #4711
Managing permissions by hand means managing them badly.
Offboarding gaps
Leavers keep groups, mailbox rights and licenses. You find out during the audit — or during the incident.
License blind flight
Nobody can say who has which license and why. At renewal, you pay for ghosts.
Teams sprawl
Everyone creates, nobody cleans up. Naming conventions live in a wiki nobody reads.
No evidence
“Who approved this access, and when?” — without a central log, that's archaeology.
A management layer on top of your Entra ID.
just IDM doesn't replace your directory — it adds the business layer Microsoft doesn't give you: roles. Describe once what a role means — access, teams, mailboxes, license. From then on: a person gets a role, and everything else follows automatically.
- Change one role instead of touching a hundred groups — memberships are computed
- Department moves in seconds instead of tickets: assign roles in bulk
- Your directory stays in charge — just IDM makes it manageable
just IDM — management layer
Entra ID · on-prem AD · Exchange
your directory — still the source of truth
Everything in one place — from users to audit.
One role model instead of a thousand individual permissions. No more portal hopping.
Role-based access
Change one role instead of touching a hundred groups. Memberships are computed, not maintained.
Learn moreClean offboarding
Leavers automatically lose every group membership. The history stays intact.
Learn moreLicense governance
Target/actual comparison per person, costs in the catalog, deviations only with a documented reason.
Learn moreTeams without sprawl
Teams and channels are created by request: validated, categorized, with owner structure and release step.
Learn moreShared mailboxes, handled
Full-access and send-as as groups, continuously reconciled — cloud and hybrid.
Learn moreEverything documented
Every change with actor, timestamp and before/after — automatically, without anyone having to remember.
Learn moreHybrid AD sync
Entra ID and on-prem AD in parallel, married via correlation IDs — including a migration path to the cloud.
Safe operations
Managed identity instead of password accounts, test run before every write, environment self-test.
Every license has a reason. Or it stands out.
Your role catalog knows the recommended license for every role — including its cost. just IDM shows target and actual side by side for every person; deviations require a documented reason. Add-ons are computed from roles instead of handed out one by one, and retention policies follow the license all the way to the mailbox.
- Target/actual comparison per person — deviations need a documented reason
- License costs and a sortable priority ranking right in the catalog
- At your next Microsoft renewal, you'll argue with numbers, not gut feeling
License: target vs. actual
Demo dataDeviation documented: “E5 for Power BI reporting — management approval, ticket #4711”
Audit log (demo data)
tamper-proofThe auditor asks. You click three times.
just IDM logs every change automatically, the moment it happens: who, what, when, before, after. Nobody can alter the log after the fact. And whoever leaves the company automatically loses all access — the history remains.
- History right on every object, filterable by everything an auditor asks
- ISO 27001, NIS2, cyber insurance: from now on it's a filter, not a project
Cloud-only, hybrid, or somewhere in between — the engine handles all three.
The sync engine provisions groups in Entra ID and on-prem AD in parallel and marries both worlds via correlation IDs. Four operating modes per group, an automated migration path from cloud-only to hybrid, per-directory membership reconciliation.
- Test run first, then for real — every run reports its numbers to a job register
- Errors become tasks — not line 4,712 in a log file
- Requesting and executing are separated — exactly what an auditor expects
Cloud
Entra ID
On-prem
Active Directory
Sync engine
4 operating modes · dry-run · job register
You request. The engine delivers. The log keeps the record.
Model
Map your organization as roles: person → role → access. Roles carry recommendations for licenses, add-ons and security classifications.
Request
New team, new access group, new shared mailbox? One request in just IDM — validated names, categories, and an explicit release step.
Provision automatically
The sync engine puts everything in place across Entra ID, on-prem AD and Exchange — as a test run first, then for real, with full feedback. Every change is logged automatically.
just IDM
Desired state + request
Sync engine
checks first, writes second
Entra ID · AD · Exchange
Actual state
Your instance. Your tenant. Your data.
Your own instance, not a SaaS black box
Runs as your own instance in your Azure environment (West Europe) — no multi-tenant SaaS.
Managed identity throughout
No password service accounts, no secrets in code — everything in Azure Key Vault.
Least privilege as a process
Permissions declared as code. Admin consent stays with your IT — we deliver the ready-made request.
API-first — no black box
Everything the UI can do, the REST API can do too: every single function. Documented as OpenAPI — the Swagger specification is available on request.
Infrastructure as code
Reproducible via Terraform, CI/CD with automated tests and tested migrations, destructive database changes technically blocked.
Runs as a Teams tab, too
Manage permissions without leaving Teams — in the browser or directly as a Microsoft Teams tab.
From grown to governed in three steps.
Roll out your instance
Terraform provisions the environment; the permission catalog ships as a ready-made IT request. A self-test verifies every connection afterwards.
Import your data
The repeatable importer reads your legacy source read-only, runs as a dry run first, and delivers a deviation report instead of surprises.
Automate block by block
Connectors go live one at a time — each in observation mode first. You decide when the engine actually writes.
Target-system connectors roll out step by step — person sync and group provisioning first, each with a dry-run phase.
Six perspectives, one system.
Head of IT
Provable control over every permission — at the push of a button.
Admins
One interface instead of five portals. And a full night's sleep.
Executives
Less risk, visible license costs, auditor-proof answers.
Department leads
Manage your team's roles yourself — delegated instead of ticketed.
Digitalization teams
Joiner, mover, leaver as guided workflows — permissions follow the process, not a hallway request to IT.
IT service providers
Roll it out reproducibly for every client — own instance, own branding.
The most common questions — answered concretely.
No — it makes Entra ID governable. Your directory stays the source of truth for users; just IDM adds the business role model on top and provisions it automatically.
No. just IDM handles cloud-only, hybrid with on-prem AD/Exchange — and the path in between, including an automated migration mode.
In your own Azure environment (West Europe): your instance, your database, your Key Vault. No shared SaaS.
Through a repeatable import: dry-run by default, deviation report included. It reads your source read-only with minimal permissions — and never deletes.
Their account changes lifecycle status, all group memberships are revoked on the next reconciliation — and every one of those changes is in the audit log.
Yes — that's the intended path: role model and import first, then one connector at a time, each starting in dry-run.
Yes — just IDM is built API-first: everything the UI can do, the documented REST API can do too. Every single function. The OpenAPI (Swagger) specification is available on request.
As a managed instance: infrastructure as code, CI/CD, a self-test after every rollout, job monitoring and error escalation as tasks. You or your IT run it — just experts is at your side at any time and enables your team. On explicit request, we also operate just IDM as SaaS for you.
Depends on your environment and rollout stage — let's talk for 30 minutes.
Turn “we should clean that up someday” into “done and documented.”
Two ways in, one goal: talk for 30 minutes — or try it yourself in a test instance with sample data.
30-minute call · test instance with sample data · no obligation