FAQ
Frequently asked questions
Conditional Access operations, Microsoft Entra licensing, workspace baselines, and Policytab billing.
Product
Is Policytab for me if we only use Microsoft 365 email?
Probably not. Policytab is for teams that operate Microsoft Entra Conditional Access - MSPs and internal IT with Entra ID P1 or P2. If you only need email, Teams, and files with default Microsoft 365 security, stay in the Microsoft 365 admin center.
What is Policytab?
Policytab is a Conditional Access operations platform for Microsoft Entra. MSPs and internal IT teams use it for drift detection against a baseline, sign-in impact analysis, MFA posture, time-bound exclusions, and governed CA policy changes with preview and rollback.
Does Policytab replace the Microsoft Entra admin center?
No. Policytab sits beside the Entra admin center for CA operations at scale - drift, impact, fleet rollup, and change workflow. You still manage identities, licenses, and non-CA settings in Entra.
What Microsoft licenses do I need?
Conditional Access requires Entra ID P1 or P2 (or equivalent Microsoft 365 licensing that includes Entra ID P1). Identity Protection risk actions require Entra ID P2. Policytab detects tenant capabilities and gates features accordingly.
How does drift detection work?
Policytab snapshots CA policies, groups, and named locations on resync and nightly backup, then compares them to each tenant's effective comparison baseline (imported CA snapshot by default, or a workspace baseline you assign per tenant). Portal edits surface on the next snapshot - not via live Graph change notifications.
Can I import a CA baseline from GitHub?
Yes. Import an open Conditional Access template from GitHub (for example Teuftis/ConditionalAccessBaseline-Hardened) into Baseline library, edit in your workspace, and assign per tenant. Policytab does not bundle a global catalog - new tenants default to an imported CA snapshot baseline until you assign a workspace baseline.
Can Policytab write to Conditional Access policies?
Yes, on Pro and Enterprise. CA policy writes always run preview validation, optional second-admin approval, pre/post snapshots, and rollback when supported. Some operations (group membership, exclusions, emergency pause) use separate audited paths outside the policy change workflow.
How long does onboarding a tenant take?
Connect a tenant with Microsoft admin consent - Policytab registers a single-tenant Entra app in that directory, with no platform-wide multitenant consent. Plan for roughly 15 minutes of one-time guided setup per tenant; the first policy snapshot and drift report against your baseline follow once that setup completes.
How does Policytab keep a CA change from locking admins out?
Before any policy write you get a preview diff, a sign-in impact estimate for who would be newly blocked, and optional second-admin approval. Every write is wrapped in pre/post snapshots, so you can roll back to the previous policy state through the same governed workflow when the change kind supports it.
Can I model the impact of a policy before enforcing it?
Yes. Impact analysis replays recent sign-ins (up to 30 days on Pro, 90 days on Enterprise) to estimate who would be newly blocked if you move a policy from report-only to enforced - so you can size the affected scope before you flip it.
What are time-bound exclusions?
Brokered, temporary exclusions from a CA policy with a required expiry (up to 90 days). Policytab adds the user to the exclusion group immediately and schedules removal from Entra at expiry. Use Sync expired if a removal has not synced yet.
How does change approval work?
Approval is an optional four-eyes gate: when enabled, a second admin must approve a pending CA change before it can be applied, and the requester cannot approve their own change. Critical changes always require a different approver. Previews, approvals, and applies are all written to the audit log.
Does Policytab monitor break-glass accounts?
A daily validator checks that your emergency-access (break-glass) accounts stay excluded from blocking policies and remain healthy, and alerts you if that posture drifts.
Is every change audited, and can I export it?
Every mutating action writes one row to the audit log. Pro includes 30-day in-console history. Enterprise adds CSV/JSON export and unlimited audit retention.
Where is data stored?
Policytab runs on encrypted cloud infrastructure (AWS, ca-central-1 by default). Each connected Entra tenant is scoped to your workspace. Graph app credentials are encrypted at rest.
Is Policytab affiliated with Microsoft?
No. Policytab is an independent product built for Microsoft Entra Conditional Access. Microsoft, Entra, Azure, and Microsoft 365 are trademarks of Microsoft Corporation.
Pricing & licensing
What counts as a connected tenant?
One Microsoft Entra ID directory (tenant) you add to your Policytab workspace under Tenants. For internal IT that is usually your production Entra tenant; for MSPs it is each customer Entra tenant you onboard. Each distinct Entra tenant ID counts once in your workspace. Entra users, groups, Azure subscriptions, and Microsoft 365 licenses inside a directory do not add billing line items. If you connect separate dev, test, and prod Entra tenants, each one counts separately. Adding an organization starts the count (including while connect or admin consent is still in progress). Disconnecting or pausing does not remove it from billing until an owner permanently deletes the tenant (Settings → delete, after disconnect when required). The same Entra tenant cannot be onboarded twice in one workspace. Your first connected tenant is included in the Pro or Enterprise base fee; each additional tenant is $10/mo on Pro or $4.99/mo on Enterprise, synced to Stripe when you have an active subscription.
Is there a Free plan?
No. Every new workspace starts with a 14-day Pro trial (no credit card). When the trial ends, choose Pro or Enterprise to continue. There is no read-only tier after trial.
What happens after the 14-day Pro trial?
Your trial ends and the console locks until you subscribe to Pro ($9.99/mo + $10/tenant) or Enterprise ($29.99/mo + $4.99/tenant). Pick a plan at Settings → Billing after you sign in.
Do I need a credit card to start the trial?
No. Create a workspace and run the 14-day Pro trial without entering payment details. Subscribe at Settings → Billing before or when the trial ends to keep using Policytab.
Can I move between plans?
Yes. Subscribe or change plans from Settings → Billing (Stripe checkout or Customer Portal). Upgrades apply once Stripe confirms the subscription. Plan-change timing for downgrades follows your Stripe subscription settings. When you add or remove tenants in Policytab, we sync the per-tenant add-on quantity on your subscription automatically.
What does Enterprise include in the product?
Enterprise unlocks a dedicated database (provisioned after upgrade), outbound Slack, Teams, email, and signed webhook alerts, scheduled compliance digests, CSV exports, unlimited audit retention, and sign-in analysis windows up to 90 days (Microsoft Graph limit). Configure notification channels at Settings → Notifications after upgrading. First tenant is included in the base fee; each additional tenant is $4.99/mo (Pro add-ons are $10/mo).
Can I get Entra SSO for the Policytab console?
Not currently. Policytab operator sign-in uses email and password. Microsoft Entra admin consent connects customer tenants to Policytab and is separate from console sign-in. Contact us if console SSO is a procurement requirement so we can discuss the roadmap.
Where do you store our data?
Hosted on AWS (ca-central-1 by default). Each connected Entra tenant is scoped to your workspace. Customer Entra credentials are encrypted at rest. Contact us if you need a specific region or DPA.
Topic guides
See the documentation for setup and security.