Solutions
Conditional Access solutions for Microsoft Entra
Policytab serves MSPs managing customer fleets and internal IT teams running a production Entra tenant. Same console - different scale.
Create your account, set up a workspace, and get 14 days of Pro - connect tenants, detect drift, and run impact analysis. No credit card required.
Two ways teams run Policytab
The same drift, impact, and change workflow - whether you operate one tenant or a hundred.
Conditional Access across your customer fleet
One workspace for every customer Entra tenant - drift vs baseline, sign-in impact, MFA posture, time-bound exclusions, and change management with preview before apply.
- Fleet rollup. Connect customer Entra tenants once. Roll up drift, MFA posture, open alerts, and pending exclusions without switching portals per customer.
- Safe CA changes at scale. Every policy write runs preview, optional second-admin approval, and snapshot rollback when supported. Bulk change sets when the same fix applies everywhere.
- Tenant isolation. Each customer tenant is isolated in Policytab. Your workspace only sees tenants you connected.
Conditional Access for your production Entra tenant
Years of portal edits, merger tenants, and exception groups add up. Policytab gives internal IT one place to see drift, model impact, and apply CA changes with preview and rollback.
- Drift you can explain. Snapshot policies on resync and compare to the imported snapshot or workspace baseline you assign per tenant. Show auditors and leadership what changed - not just what is enabled today.
- Impact before enforcement. Model who would likely be blocked from recent sign-ins before you move a policy from report-only to enforced.
- Exceptions that expire. Time-bound exclusion groups with reason, approver, and scheduled Entra sync - so travel and vendor access does not become permanent risk.
Everything in one console
Built specifically for Microsoft Entra Conditional Access operations - not a generic policy manager.
Drift detection
Snapshot Entra CA policies on resync and nightly backup. Compare to the tenant comparison baseline you assign at onboarding.
Learn moreImpact analysis
Model who would likely be blocked before you enforce a CA policy - from recent Microsoft Graph sign-ins.
Learn moreChange management
Preview, optional approval, apply, and rollback for CA policy writes. Five change kinds, all audit-logged.
Learn moreExclusion workflow
Time-bound CA exclusion group membership with reason, approver, and scheduled Entra sync at expiry.
Learn moreMFA posture
Per-user fresh, amber, and stale buckets with confidence labels - stale admins surfaced on the dashboard.
Learn moreBreak-glass monitoring
Emergency-access sign-ins and missing break-glass exclusions - monitored on schedule.
Learn moreHow it works
Connecting a tenant is a guided, one-time setup of roughly 15 minutes per tenant - then the first snapshot and drift report land automatically.
Connect
Onboard each Entra tenant once with admin consent. Policytab registers a single-tenant app in that directory - no platform-wide multitenant consent.
Compare
Snapshot policies, groups, and named locations on resync and nightly, then diff against the comparison baseline you assign per tenant.
Govern
Every CA write runs preview validation, optional second-admin approval, and pre/post snapshots with snapshot-backed rollback when supported.
See it on your tenants
Connect an Entra tenant with admin consent and compare Conditional Access against your baseline.
Not sure which path fits? Contact us or read the FAQ.