Help

Turn on automation

Automation lets ConfigCheckup make approved fixes in a client tenant: disabling dormant accounts, reclaiming licences, removing stale devices and more. It is off by default and every change is previewed, approved and recorded with a way back.

What you need

  • The Growth or Scale plan. Starter and the trial assess and report, but do not make changes.
  • The write permissions for the fixes you want, granted in the client tenant.
  • Two people in your workspace with the Admin or Owner role, since most changes need two approvals.

1. Grant write permissions

Each action lists the Microsoft Graph permission it needs in the table below. When the ConfigCheckup application includes them, the client's Global Administrator sees them on Microsoft's consent screen alongside the read permissions. For a tenant that is already connected:

  1. Open the tenant and select Grant consent again, or send the consent link to the client's administrator.
  2. After they accept, run an assessment. The tenant page lists every permission granted under Access granted.

Holding a write permission changes nothing by itself. Tenants without any can be assessed indefinitely. Full permission details are in connecting a tenant.

2. Switch it on per tenant

On the tenant's page, find the Automation card and select Enable automation. This needs the Admin role, is recorded in the audit log, and can be switched off again at any time. It is refused if the tenant has not granted any write permission.

3. Propose a fix

Fixes start as proposals. Anyone with the Consultant role can propose one:

  • From a finding: open it in Findings and select Propose automated fix, where the finding has one.
  • From Licence savings: Reclaim these licences drafts removal of licences from disabled and dormant accounts.
  • From Device lifecycle: remove inactive end-of-life devices, disabling them first and deleting later.

Every proposal is dry-run straight away: ConfigCheckup reads the tenant and lists exactly what would change, and what would be skipped and why. A proposal whose dry run fails cannot be approved.

4. Approve and run

  1. Submit the proposal. It appears under Approvals, and approvers are notified.
  2. An Admin or Owner reviews the dry run and approves or rejects it with a comment. By default two approvals are needed, and at least one must come from someone other than the person who proposed it. High-risk actions always need two.
  3. Once approved, the change runs. Just before it does, ConfigCheckup checks again that automation is on, the permissions are still granted and the targets are within limits. Each target's result is recorded, with the request that was made.

Rolling back

Reversible actions record the opposite change as they run. To undo one, open it under Approvals and select Roll back (Admin role). The rollback is audited like the original. Actions that cannot be reversed, such as revoking sign-in sessions or deleting devices, say so before you approve them.

What can be automated

ActionReversible
Disable accounts
Sets accountEnabled to false on the listed accounts. Sign-in stops immediately; mailbox and file content are untouched and the change is reversible by re-enabling the account.
Needs User.ReadWrite.All
Yes
Revoke sign-in sessions
Invalidates refresh tokens for the listed accounts, forcing re-authentication everywhere. Used after a suspected compromise. It cannot be undone, but the only effect is that users sign in again.
Needs User.ReadWrite.All
No
Remove licences from accounts
Removes assigned licences so the seats return to the pool. Mailboxes over 50 GB and OneDrive content enter their normal retention window — convert mailboxes that colleagues still need to shared mailboxes first.
Needs User.ReadWrite.All
Yes
Remove a directory role assignment
Removes the named principals from a directory role. Use it to clear administrative access from dormant or disabled accounts. The assignment can be restored, but any just-in-time configuration attached to it is not.
Needs RoleManagement.ReadWrite.Directory
Yes
Create a Conditional Access policy (report-only)
Creates a Conditional Access policy from a known-good template. The policy is always created in report-only mode so it logs what it would have done without blocking anybody; promoting it to enforcing is a separate, deliberate change.
Needs Policy.ReadWrite.ConditionalAccess
Yes
Set an expiry on SharePoint "Anyone" links
Applies a tenant-wide expiry to anonymous sharing links. Existing links that are already older than the new limit stop working, so tell the business before running it.
Needs SharePointTenantSettings.ReadWrite.All
Yes
Remove inactive end-of-life devices
Disables, or deletes, end-of-life devices that have not signed in or checked in for the chosen number of days. Disabling stops the device signing in to Entra ID and can be undone. Deleting removes the device from Entra ID and Intune and cannot be undone: BitLocker recovery keys stored on the Entra device are deleted with it, so disable first and delete later.
Needs Device.ReadWrite.All
Yes

Questions about what automation can touch? See data protection or the FAQ.