Safe changes · for MSPs

Nothing changes in a client’s tenant until you approve it.

Every change is dry-run against the live tenant, approved, logged and read back, with a way back where Microsoft allows one, and a dry run that says so where it does not.

30 days of everything in Automate on up to 3 tenants, from your first connected tenant. No card. Then choose the plan that fits.

Every permission it asks for Every kind of change

One change, start to finish

Contoso Group Ltd · demo tenant

  1. Found medium

    Resharing of content by external users (Collaboration & Sharing)

  2. Dry run against the live tenant

    Dry run· nothing has changed yet

    Stop guests resharing items they do not own

    SharePoint tenant settings

    Now
    Allowed
    After
    Not allowed

    What the client notices: Guests can still open what was shared with them, but cannot pass it on to others.

  3. Approved

    Approved by one or two people, your choice per client; some higher-risk changes always need two. With two, at least one is not the person who raised it.

  4. Logged and read back

    The change and who approved it go in the audit log. Each changed setting is then read back from Microsoft, and the check runs again: a fix counts only when it passes.

    /c/contoso › OverviewDemo tenant
    Changes since the last assessment for Contoso Group Ltd: fixes confirmed by the tenant passing the check, each with who marked it resolved and their note, and one marked done that is still failing.Changes since the last assessment for Contoso Group Ltd: fixes confirmed by the tenant passing the check, each with who marked it resolved and their note, and one marked done that is still failing.
  5. A way back

    Where Microsoft allows it, the change can be rolled back. Where it does not, the dry run says so before anyone approves.

The five steps, in detail

The same path for every change: a fix from a finding, a fix across clients, a leaver, a password reset or a seat count.

  1. Found, and drafted

    A check fails, or you ask for a change: a leaver, a password reset, a seat count. ConfigCheckup drafts the change. Drafting changes nothing.

  2. Dry run against the live tenant

    ConfigCheckup reads the live tenant and lists exactly what would change, what would be skipped and why. A change whose dry run fails cannot be approved. New Conditional Access policies are created in report-only mode, and switching one on is a separate change you approve.

  3. Approved

    Approved by one or two people, your choice per client; some higher-risk changes always need two. With two, at least one is not the person who raised it. 13 kinds of change always need two. An approval counts only for the dry run it was given to, and can come from the console, or from Teams or Slack where the change allows it.

  4. Logged and read back

    Just before it runs, ConfigCheckup checks again that automation is on, the permissions are still granted and the targets are within limits. Each target’s result is recorded with the request made, and the audit log names who asked and who approved. The changed part of the tenant is then read back and the check runs again: a fix counts only when it passes.

  5. A way back

    48 of the 55 kinds of change record the opposite change as they run, and can be rolled back from the change’s page, audited like the original. The 7 that cannot be undone, such as signing someone out everywhere or wiping a device, say so in the dry run before anyone approves.

/changes › Woodgrove FinancialDemo workspace
A change waiting for approval at Woodgrove Financial: the dry run shows the setting “Users can register applications” going from Yes now to No after, and the details say it is low risk and reversible, with a recorded rollback plan.A change waiting for approval at Woodgrove Financial: the dry run shows the setting “Users can register applications” going from Yes now to No after, and the details say it is low risk and reversible, with a recorded rollback plan.
  1. The dry run: what is set now, and after
  2. Reversible, with a recorded rollback plan
/changes › Woodgrove FinancialDemo workspace
The approvals panel of a change: one more approval required before it can run, a comment box noting that the decision is recorded in the audit log, and Approve and Reject buttons.The approvals panel of a change: one more approval required before it can run, a comment box noting that the decision is recorded in the audit log, and Approve and Reject buttons.
  1. Nothing runs until it is approved
  2. Every decision is recorded in the audit log
  3. Approve or reject

Fix one check at every client

Where the same check fails at several clients, prepare the fix at up to 100 of them from one screen, without loosening anything that holds for one client.

  • Each client gets its own change, dry-run against its own tenant, with its own approval rule, its own run and its own way back.
  • Each client is listed with whether the fix can be prepared there, and if not, why: no automation consent, automation off or paused, an input it needs, or a change already open.
  • Approve them together. Each approval is bound to the dry run you were shown; a client that needs two people waits for a second approver, and a dry run that failed or changed cannot be approved from there.

Automate and aboveFixing a check across clients, step by step

/findings/fix-across › NL-IDN-003Demo workspace
Fixing one check across clients: each client failing it, with where it stands (needs consent, or a connection to fix) and whether one or two people approve, beside the change each client would get, marked as able to be rolled back.Fixing one check across clients: each client failing it, with where it stands (needs consent, or a connection to fix) and whether one or two people approve, beside the change each client would get, marked as able to be rolled back.
  1. Each client, and why it can or cannot be prepared
  2. One or two approvers, per client
  3. The change, and that it can be rolled back

Automatic fixes, inside guardrails

Approve a policy in advance and covered fixes run on their own when an assessment or the drift check finds them failing. Only 35 of the 55 kinds of change can ever run this way; everything else waits for a person.

Automate and above

Start with Simulate: ConfigCheckup records what it would do, with each dry run, and changes nothing.

A fix runs on its own only when

  • It can be rolled back, is not high-risk and is not one of the changes that always need two people.
  • Its dry run against the live tenant succeeds, and it changes no more objects than the policy’s size limit.
  • Automation is on and not paused for the tenant, and the admin who approved the policy is still active. A tenant that needs two approvers needs a second admin to co-sign the policy.
  • Fewer than 20 automatic changes have run in the tenant, and fewer than 100 across the workspace, in the last 24 hours. A fix that has run 2 times in 7 days is not holding, so it waits for a person.

Anything else is drafted for approval, with the reason. Each automatic fix is recorded in the approver’s name, checked again, reported to admins by email and in Teams or Slack, and can be rolled back. Pause a tenant, or stop every automatic change at once, at any time.

Containing a taken-over account

From a takeover alert, contain the account in one approved change: sign-in blocked, every session revoked, and inbox rules that send mail outside turned off. Where you turn it on for a tenant, a high-confidence takeover is contained straight away, under the same guardrails; emergency and service accounts can be left out.

Account takeover alerts

Everyday admin, with the same safety

Leavers, starters, password resets and devices go through the same dry run, approval and audit log as every fix.

  • A reset password is made in the run and shown once to the approver, in the console. It is never stored, emailed or logged.
  • An account with any directory role always needs two approvers to reset.
  • A full wipe always needs two approvers, each typing the device’s name, and is never approved from Teams or Slack; at most 5 run in a workspace in an hour.
  • A Technician can ask for resets, retires and wipes and approve device actions, with no access to billing or settings.
  • A one-time access pass is only for an account an approved change created, within 7 days, shown once and never stored.

Automate and aboveLeavers and helpdesk tasks

/c/woodgrove-financial › People and leaversDemo workspace
People in a client tenant, each with the actions Set up like…, Reset password and Offboard.People in a client tenant, each with the actions Set up like…, Reset password and Offboard.
  1. Offboard a leaver as one approved change
  2. Reset a password, shown once to the approver
  3. Set up a new starter like a colleague

Every kind of change

All 55 kinds of change ConfigCheckup can make, from the product’s own registry. 48 can be undone; 13 always need two people to approve, whatever the client’s setting.

Every kind of change, whether it can be undone and whether it always needs two people to approve
ChangeCan be undoneAlways two people
Add the offices as a trusted named locationYesOne or two, your choice
Apply the Intune device baselineYesOne or two, your choice
Apply the standard Conditional Access setup (report-only)YesOne or two, your choice
Ask non-compliant devices to check in nowNo, the dry run says soOne or two, your choice
Back up local administrator passwords with Windows LAPSYesOne or two, your choice
Block apps from signing inYesYes
Change an Exchange Online or Defender settingYesOne or two, your choice
Change the seats on a CSP subscriptionYesYes
Contain a compromised accountYesOne or two, your choice
Create a Conditional Access policy (report-only)YesOne or two, your choice
Create emergency access accountsYesYes
Create groupsYesOne or two, your choice
Create user accountsYesOne or two, your choice
Delete stale groups and TeamsYesYes
Disable accountsYesYes
Give groups an ownerYesOne or two, your choice
Label Microsoft 365 groups, teams and sitesYesOne or two, your choice
Limit SharePoint and OneDrive sharing to approved domainsYesOne or two, your choice
Make a custom domain the defaultYesOne or two, your choice
Make groups and Teams privateYesOne or two, your choice
Make standing admin roles eligible in PIMYesYes
Move admin roles to cloud-only accountsYesYes
Move Windows devices to a supported releaseYesOne or two, your choice
Offboard a leaverYesOne or two, your choice
Prompt everyone to set up Microsoft AuthenticatorYesOne or two, your choice
Protect privileged apps with Conditional AccessYesOne or two, your choice
Publish MTA-STSYesOne or two, your choice
Publish SPF and DMARC recordsYesOne or two, your choice
Remove a directory role assignmentYesYes
Remove expired app secretsNo, the dry run says soOne or two, your choice
Remove inactive end-of-life devicesYesYes
Remove licences from accountsYesYes
Reset passwordNo, the dry run says soOne or two, your choice
Resolve Microsoft Defender alertsYesOne or two, your choice
Restore Conditional Access from a backupYesYes
Restore SharePoint sharing settings from a backupYesOne or two, your choice
Retire deviceNo, the dry run says soOne or two, your choice
Revoke delegated consentYesOne or two, your choice
Revoke sign-in sessionsNo, the dry run says soOne or two, your choice
Set an expiry on SharePoint "Anyone" linksYesOne or two, your choice
Set security notification contactsYesOne or two, your choice
Set up a new starter like an existing personYesOne or two, your choice
Set up Microsoft Purview protectionYesOne or two, your choice
Set usage locationYesOne or two, your choice
Sign outgoing mail with DKIMYesOne or two, your choice
Stop passwords expiringYesOne or two, your choice
Switch a Conditional Access policy on (or back to report-only)YesOne or two, your choice
Switch off directory synchronisationNo, the dry run says soYes
Tighten a SharePoint sharing settingYesOne or two, your choice
Tighten a tenant user settingYesOne or two, your choice
Tighten the default cross-tenant access settingsYesOne or two, your choice
Tighten the sign-in methods people can useYesOne or two, your choice
Turn off external forwarding rulesYesOne or two, your choice
Turn on the admin consent workflowYesOne or two, your choice
Wipe deviceNo, the dry run says soYes

Approved changes come with Automate: see the plans Turning on automation, step by step

See a change made safely, on your own tenant.

Connect one client read-only, then switch automation on for it when you are ready.

30 days of everything in Automate on up to 3 tenants, from your first connected tenant. No card. Then choose the plan that fits.