Each tenant keeps its currency in License Advisor
An analysis uses the currency the tenant had last time, so totals stay comparable run to run.
Every update to Implora, as it ships. A monthly summary goes out by email.
An analysis uses the currency the tenant had last time, so totals stay comparable run to run.
Windows Devices and Users move to v3.8. macOS and BYOD app protection are new.
The sidebar, the Baselines settings list, Lora Graph panels and the Chaos Score dialogs scroll with the browser's own smooth scrolling and a slim scrollbar without arrow buttons.
The What's new button at the bottom of the sidebar lists what we ship, newest first. It opens on what is new since you last looked; search by page or text for the rest. Home shows the latest three.
"2 new" and "N missing" open one list of the permissions, and "Allow configuration changes" replaces "Configuration Import".
Findings come first, one row per tenant. Pick the overview graph: savings over time, or where to act first.
Compare what your current SQL setup costs with other tiers, serverless included, on a What-If tab.
Results list each check once with its affected resources and the full scanner evidence in the detail sheet. Past Cloud Security scans can be deleted.
Upload Zero Trust 2.6.0 reports; SecOps and AI join the pillars findings are grouped by.
On, Report-only or Off as packaged. Override it per deploy - you are warned before a policy goes On for all users, and told up front when Security defaults would refuse it.
P1 (10 policies) and risk-based P2 (2 policies), built from Microsoft's June 2026 deployment plan.
Add directory roles and guest types to each Conditional Access policy before it is written.
When you deploy a package, Autopilot rows show whether the tenant already has the profile.
Sync sets each dynamic group's membership rule and records only what Entra ID shows back.
Bundle group templates into sets and deploy them to many tenants, see each tenant on its own page and which packages use a group. Verify all runs in the background.
Settings found across the admin portals, admin consent notifications and request expiry, and a tenant copy that shows its progress in the job monitor.
Intune tenant settings join Baselines, most "Not managed yet" rows are now settings, and number settings take any value in range.
Headline tiles, readiness by reason and over time, and an identities table of everyone behind every number, with each sign-in method they have.
"Create here" makes a missing group in the tenant, even when it has no group template.
A Targeting badge marks assignment-only changes, and a renamed policy can be pushed straight from its row.
Overview, template, tenant and scan pages rebuilt: one banner, progress while scanning, older scans read-only, and quick actions on scan rows.
Data tables in Config Drift, Groups and CA Analyzer sort by any column, and License Advisor lists followed.
A push translates a template's groups, locations and custom authentication strengths to the tenant by name.
CA Analyzer shows who a policy change would affect, with the names behind every number.
See who each Conditional Access policy covers, who satisfies it and who it would block, with Microsoft's What If verdict beside ours and observed sign-in numbers.
Every template update says what it changed, and a tenant can be unlinked from a template or stop being monitored.
Exchange and Teams access is one shared grant, Teams Administrator included, and consent links can be copied from the row menu.
Each tenant has an access page with what is left to hand off, a nightly access check and an access history. A consent counts the moment it lands.
Choose read-only or read-and-write access for Exchange, Teams and other workloads, with a manual setup path checked by a read-only verification.
Accept a deviation per tenant, fix one rule across tenants, and see how long a rule has failed.
One Baselines page for Entra, Exchange, Teams and Defender settings, checked in the background. A baseline can be captured from a tenant.
Manage passkey (FIDO2) settings in a full-page editor, and search for any setting in a baseline.
Device configuration profiles, custom profiles down to each payload key included, are compared and pushed like Settings Catalog policies.
When a scanner update drops a check, it shows as Not detected instead of vanishing. Cloud Security gains a workload column and a framework filter.
Certificate profiles and custom compliance scripts can use what the tenant already has or bring a copy; Confirm shows what a deploy would skip before it runs.
Pick your currency beside the plans, and billing pages are private to the account owner.
Package policies read as settings instead of raw JSON, and a policy is edited where it is kept.
Search, review and select all in the picker, see what a policy already belongs to, and find Conditional Access prerequisites nested under their policy.
A scheduled check flags packages whose source tenant changed, with an opt-in auto-update and a section in the weekly summary.
Create every group a deploy is missing in one step, linked and selected.
Packages remember the tenant they came from; update one from there, with its default assignments pre-filled.
Link a group that already exists in a tenant to a group template instead of creating a duplicate.
When a tenant has read-only access, the push button says so instead of failing when clicked.
A renamed policy is paired with its original and shown as renamed; accept a name once and it stays accepted.
Exclude single settings of a template policy for a tenant, and see the exemptions in the policy and rules views.
Link tenants, update from the source, scan all and read the history from the template page. Pushes are batched and verified with one scan.
See the whole story of a drifted policy: when it changed, what was accepted and why.
Each schedule names the state of every tenant, shows its runs and says which tenants it really covers.
An insight pack with cost per user, commitment coverage, year-over-year change and realized savings.
The overview is rebuilt around your workflow: templates in one table grouped by source, tenant search, and the source tenant follows its own standard.
A push shows which differences you keep and which you enforce, and every push is recorded.
Assignment changes on Settings Catalog policies show as drift, and a push aligns them.
Accept only the settings or elements that differ; the rest stay enforced, and pushes respect what you accepted.
Detected changes and a full policy tree in portal wording, with users, locations and roles shown by name.
A How it works sheet explains the status badges and how the reference compares with each tenant.
New permissions read as one rollout with a re-consent badge in the sidebar, instead of a warning on every tenant.
Lora Ops runs read-only checks, verifies what they found and plans from the checks that failed.
macOS scripts and custom attributes, remediations, named locations, assignment filters, terms and conditions, update policies, Endpoint Security, ADMX templates, app configuration and custom authentication strengths.
Named locations and authentication strengths a Conditional Access policy needs are linked on deploy, and the history shows each policy's result.
Run drift scans, Entra checks and assessment scanners on a schedule, with batched alerts and an optional weekly summary email.
Entra baselines manage the device quota, B2B direct connect and inbound trust settings.
Discovery resumes after a reload and reuses a recent export, marked in the tenant list.