Identity & access management for Microsoft 365

Who can access what in your Microsoft 365?
just IDM knows. Transparently.

The management layer on top of your Entra ID: users, roles, teams, mailboxes and licenses — modeled as roles, provisioned automatically, traceable at any time. In your own Azure environment.

Runs in your Azure tenant Roles instead of one-off permissions Cloud-only & hybrid AD Built for 50–2,000 users
app.justidm.app

Rollen & Zugriffe

+ Beauftragen
PersonRolleStatus
M. Beispiel Vertrieb Innendienst provisioniert
E. Mustermann IT-Administration provisioniert
A. Demo Buchhaltung Engine läuft…
K. Muster Ausgeschieden Zugriffe entzogen
Stylized product view with demo data
The problem

Managing permissions by hand means managing them badly.

Offboarding gaps

Leavers keep groups, mailbox rights and licenses. You find out during the audit — or during the incident.

License blind flight

Nobody can say who has which license and why. At renewal, you pay for ghosts.

Teams sprawl

Everyone creates, nobody cleans up. Naming conventions live in a wiki nobody reads.

No evidence

“Who approved this access, and when?” — without a central log, that's archaeology.

The solution

A management layer on top of your Entra ID.

just IDM doesn't replace your directory — it adds the business layer Microsoft doesn't give you: roles. Describe once what a role means — access, teams, mailboxes, license. From then on: a person gets a role, and everything else follows automatically.

  • Change one role instead of touching a hundred groups — memberships are computed
  • Department moves in seconds instead of tickets: assign roles in bulk
  • Your directory stays in charge — just IDM makes it manageable

just IDM — management layer

Person Role AccessTeamsMailboxesLicense
provisioned automatically into

Entra ID · on-prem AD · Exchange

your directory — still the source of truth

Features

Everything in one place — from users to audit.

One role model instead of a thousand individual permissions. No more portal hopping.

Role-based access

Change one role instead of touching a hundred groups. Memberships are computed, not maintained.

Learn more

Clean offboarding

Leavers automatically lose every group membership. The history stays intact.

Learn more

License governance

Target/actual comparison per person, costs in the catalog, deviations only with a documented reason.

Learn more

Teams without sprawl

Teams and channels are created by request: validated, categorized, with owner structure and release step.

Learn more

Shared mailboxes, handled

Full-access and send-as as groups, continuously reconciled — cloud and hybrid.

Learn more

Everything documented

Every change with actor, timestamp and before/after — automatically, without anyone having to remember.

Learn more

Hybrid AD sync

Entra ID and on-prem AD in parallel, married via correlation IDs — including a migration path to the cloud.

Safe operations

Managed identity instead of password accounts, test run before every write, environment self-test.

License governance

Every license has a reason. Or it stands out.

Your role catalog knows the recommended license for every role — including its cost. just IDM shows target and actual side by side for every person; deviations require a documented reason. Add-ons are computed from roles instead of handed out one by one, and retention policies follow the license all the way to the mailbox.

  • Target/actual comparison per person — deviations need a documented reason
  • License costs and a sortable priority ranking right in the catalog
  • At your next Microsoft renewal, you'll argue with numbers, not gut feeling

License: target vs. actual

Demo data
RolleSollIst
Vertrieb Innendienst E3 E3
IT-Administration E5 E5
Buchhaltung E3 E5 Grund?

Deviation documented: “E5 for Power BI reporting — management approval, ticket #4711”

Audit log (demo data)

tamper-proof
09:41 a.demo Rolle entzogen · Ausgeschieden → alle Zugriffe
09:12 engine Gruppe provisioniert · SG-VTR-CRM · Entra ID + AD
08:57 e.muster Team freigegeben · TEAM-PRJ-Rollout
08:30 engine Lizenz abgeglichen · Soll E3 / Ist E3 ✓
Offboarding & audit

The auditor asks. You click three times.

just IDM logs every change automatically, the moment it happens: who, what, when, before, after. Nobody can alter the log after the fact. And whoever leaves the company automatically loses all access — the history remains.

  • History right on every object, filterable by everything an auditor asks
  • ISO 27001, NIS2, cyber insurance: from now on it's a filter, not a project
Hybrid & automation

Cloud-only, hybrid, or somewhere in between — the engine handles all three.

The sync engine provisions groups in Entra ID and on-prem AD in parallel and marries both worlds via correlation IDs. Four operating modes per group, an automated migration path from cloud-only to hybrid, per-directory membership reconciliation.

  • Test run first, then for real — every run reports its numbers to a job register
  • Errors become tasks — not line 4,712 in a log file
  • Requesting and executing are separated — exactly what an auditor expects

Cloud

Entra ID

On-prem

Active Directory

Correlation ID

Sync engine

4 operating modes · dry-run · job register

Cloud-only ✓ Hybrid ✓
How it works

You request. The engine delivers. The log keeps the record.

Model

Map your organization as roles: person → role → access. Roles carry recommendations for licenses, add-ons and security classifications.

Request

New team, new access group, new shared mailbox? One request in just IDM — validated names, categories, and an explicit release step.

Provision automatically

The sync engine puts everything in place across Entra ID, on-prem AD and Exchange — as a test run first, then for real, with full feedback. Every change is logged automatically.

just IDM

Desired state + request

Sync engine

checks first, writes second

Entra ID · AD · Exchange

Actual state

Audit log
Technology & security

Your instance. Your tenant. Your data.

Your own instance, not a SaaS black box

Runs as your own instance in your Azure environment (West Europe) — no multi-tenant SaaS.

Managed identity throughout

No password service accounts, no secrets in code — everything in Azure Key Vault.

Least privilege as a process

Permissions declared as code. Admin consent stays with your IT — we deliver the ready-made request.

API-first — no black box

Everything the UI can do, the REST API can do too: every single function. Documented as OpenAPI — the Swagger specification is available on request.

Infrastructure as code

Reproducible via Terraform, CI/CD with automated tests and tested migrations, destructive database changes technically blocked.

Runs as a Teams tab, too

Manage permissions without leaving Teams — in the browser or directly as a Microsoft Teams tab.

100% Azure-native Static Web AppAPI ManagementAzure FunctionsPostgreSQLKey VaultAzure AutomationApplication InsightsTerraform
Onboarding

From grown to governed in three steps.

1

Roll out your instance

Terraform provisions the environment; the permission catalog ships as a ready-made IT request. A self-test verifies every connection afterwards.

2

Import your data

The repeatable importer reads your legacy source read-only, runs as a dry run first, and delivers a deviation report instead of surprises.

3

Automate block by block

Connectors go live one at a time — each in observation mode first. You decide when the engine actually writes.

Target-system connectors roll out step by step — person sync and group provisioning first, each with a dry-run phase.

Who is it for?

Six perspectives, one system.

Head of IT

Provable control over every permission — at the push of a button.

Admins

One interface instead of five portals. And a full night's sleep.

Executives

Less risk, visible license costs, auditor-proof answers.

Department leads

Manage your team's roles yourself — delegated instead of ticketed.

Digitalization teams

Joiner, mover, leaver as guided workflows — permissions follow the process, not a hallway request to IT.

IT service providers

Roll it out reproducibly for every client — own instance, own branding.

FAQ

The most common questions — answered concretely.

No — it makes Entra ID governable. Your directory stays the source of truth for users; just IDM adds the business role model on top and provisions it automatically.

No. just IDM handles cloud-only, hybrid with on-prem AD/Exchange — and the path in between, including an automated migration mode.

In your own Azure environment (West Europe): your instance, your database, your Key Vault. No shared SaaS.

Through a repeatable import: dry-run by default, deviation report included. It reads your source read-only with minimal permissions — and never deletes.

Their account changes lifecycle status, all group memberships are revoked on the next reconciliation — and every one of those changes is in the audit log.

Yes — that's the intended path: role model and import first, then one connector at a time, each starting in dry-run.

Yes — just IDM is built API-first: everything the UI can do, the documented REST API can do too. Every single function. The OpenAPI (Swagger) specification is available on request.

As a managed instance: infrastructure as code, CI/CD, a self-test after every rollout, job monitoring and error escalation as tasks. You or your IT run it — just experts is at your side at any time and enables your team. On explicit request, we also operate just IDM as SaaS for you.

Depends on your environment and rollout stage — let's talk for 30 minutes.

Turn “we should clean that up someday” into “done and documented.”

Two ways in, one goal: talk for 30 minutes — or try it yourself in a test instance with sample data.

30-minute call · test instance with sample data · no obligation