Book a demo call
Pick a free slot. In 30 minutes we show you just IDM live — guided by your questions, not by a slide deck.
Scheduling via Microsoft Bookings
The management layer on top of your Entra ID: users, roles, teams, mailboxes and licenses — modeled as roles, provisioned automatically, traceable at any time. In your own Azure environment.
just IDM
Übersicht
Benutzer
Rollen
Zugriffe
Teams
Lizenzen
Audit
Rollen & Zugriffe
+ BeauftragenAudit-Log
Rolle zugewiesen
Vertrieb Innendienst → M. Beispiel
Team freigegeben
TEAM-VTR-Angebote
Lizenz-Abweichung begründet
E5 statt E3 · Ticket #4711
Leavers keep groups, mailbox rights and licenses. You find out during the audit — or during the incident.
Nobody can say who has which license and why. At renewal, you pay for ghosts.
Everyone creates, nobody cleans up. Naming conventions live in a wiki nobody reads.
“Who approved this access, and when?” — without a central log, that's archaeology.
just IDM doesn't replace your directory — it adds the business layer Microsoft doesn't give you: roles. Describe once what a role means — access, teams, mailboxes, license. From then on: a person gets a role, and everything else follows automatically.
just IDM — management layer
Entra ID · on-prem AD · Exchange
your directory — still the source of truth
One role model instead of a thousand individual permissions. No more portal hopping.
Change one role instead of touching a hundred groups. Memberships are computed, not maintained.
Learn moreLeavers automatically lose every group membership. The history stays intact.
Learn moreTarget/actual comparison per person, costs in the catalog, deviations only with a documented reason.
Learn moreTeams and channels are created by request: validated, categorized, with owner structure and release step.
Learn moreFull-access and send-as as groups, continuously reconciled — cloud and hybrid.
Learn moreEvery change with actor, timestamp and before/after — automatically, without anyone having to remember.
Learn moreEntra ID and on-prem AD in parallel, married via correlation IDs — including a migration path to the cloud.
Managed identity instead of password accounts, test run before every write, environment self-test.
Your role catalog knows the recommended license for every role — including its cost. just IDM shows target and actual side by side for every person; deviations require a documented reason. Add-ons are computed from roles instead of handed out one by one, and retention policies follow the license all the way to the mailbox.
License: target vs. actual
Demo dataDeviation documented: “E5 for Power BI reporting — management approval, ticket #4711”
Audit log (demo data)
tamper-proofjust IDM logs every change automatically, the moment it happens: who, what, when, before, after. Nobody can alter the log after the fact. And whoever leaves the company automatically loses all access — the history remains.
The sync engine provisions groups in Entra ID and on-prem AD in parallel and marries both worlds via correlation IDs. Four operating modes per group, an automated migration path from cloud-only to hybrid, per-directory membership reconciliation.
Cloud
Entra ID
On-prem
Active Directory
Sync engine
4 operating modes · dry-run · job register
Map your organization as roles: person → role → access. Roles carry recommendations for licenses, add-ons and security classifications.
New team, new access group, new shared mailbox? One request in just IDM — validated names, categories, and an explicit release step.
The sync engine puts everything in place across Entra ID, on-prem AD and Exchange — as a test run first, then for real, with full feedback. Every change is logged automatically.
just IDM
Desired state + request
Sync engine
checks first, writes second
Entra ID · AD · Exchange
Actual state
Runs as your own instance in your Azure environment (West Europe) — no multi-tenant SaaS.
No password service accounts, no secrets in code — everything in Azure Key Vault.
Permissions declared as code. Admin consent stays with your IT — we deliver the ready-made request.
Everything the UI can do, the REST API can do too: every single function. Documented as OpenAPI — the Swagger specification is available on request.
Reproducible via Terraform, CI/CD with automated tests and tested migrations, destructive database changes technically blocked.
Manage permissions without leaving Teams — in the browser or directly as a Microsoft Teams tab.
Terraform provisions the environment; the permission catalog ships as a ready-made IT request. A self-test verifies every connection afterwards.
The repeatable importer reads your legacy source read-only, runs as a dry run first, and delivers a deviation report instead of surprises.
Connectors go live one at a time — each in observation mode first. You decide when the engine actually writes.
Target-system connectors roll out step by step — person sync and group provisioning first, each with a dry-run phase.
Provable control over every permission — at the push of a button.
One interface instead of five portals. And a full night's sleep.
Less risk, visible license costs, auditor-proof answers.
Manage your team's roles yourself — delegated instead of ticketed.
Joiner, mover, leaver as guided workflows — permissions follow the process, not a hallway request to IT.
Roll it out reproducibly for every client — own instance, own branding.
No — it makes Entra ID governable. Your directory stays the source of truth for users; just IDM adds the business role model on top and provisions it automatically.
No. just IDM handles cloud-only, hybrid with on-prem AD/Exchange — and the path in between, including an automated migration mode.
In your own Azure environment (West Europe): your instance, your database, your Key Vault. No shared SaaS.
Through a repeatable import: dry-run by default, deviation report included. It reads your source read-only with minimal permissions — and never deletes.
Their account changes lifecycle status, all group memberships are revoked on the next reconciliation — and every one of those changes is in the audit log.
Yes — that's the intended path: role model and import first, then one connector at a time, each starting in dry-run.
Yes — just IDM is built API-first: everything the UI can do, the documented REST API can do too. Every single function. The OpenAPI (Swagger) specification is available on request.
As a managed instance: infrastructure as code, CI/CD, a self-test after every rollout, job monitoring and error escalation as tasks. You or your IT run it — just experts is at your side at any time and enables your team. On explicit request, we also operate just IDM as SaaS for you.
Depends on your environment and rollout stage — let's talk for 30 minutes.
Built by people who haven't just advised on identity management in mid-sized companies — they've owned it themselves.
Product Owner
Owns product, roadmap and prioritization of just IDM.
IT Architect
Architecture and technology — from the Azure platform to the sync engine.
Co-Product Owner
Former head of IT and one of the very first IDM customers — brings the practitioner's view into the product.
Consultant Identity & Access Management
Microsoft 365 governance and collaboration — supports rollout and operations on the customer side.
just experts
Behind just IDM stands just experts — consulting and delivery for IT, processes, data and AI from one team.
Meet the just experts teamTwo ways in, one goal: talk to us for 30 minutes — or try it yourself right away.
Pick a free slot. In 30 minutes we show you just IDM live — guided by your questions, not by a slide deck.
Scheduling via Microsoft Bookings
just IDM runs with sample data at demo.justidm.app. Simply sign up and explore — no installation, no obligation.
Prefer to write to us? idm@justexperts.de
30-minute call · demo environment with sample data · no obligation