Answers to the things people ask before they scan — and after they see the results.
Something not covered here? Get in touch →
You need to be a Global Administrator in your Microsoft 365 tenant to grant the consent Kyberbyte requests. This is a one-time step — you authenticate via Microsoft's standard sign-in and approve read-only API access.
If you're not a Global Admin, you'll need someone with that role to approve the consent screen. The scan itself can be initiated by whoever has your Kyberbyte login — the Microsoft admin only needs to be involved at the connection step.
Kyberbyte's pricing catalogue covers over 600 commercial Microsoft 365 and Microsoft 365-adjacent SKUs — including the full Business family (Basic, Standard, Premium, Apps), the Enterprise family (E3, E5, F1, F3), and standalone add-ons such as Exchange Online, Microsoft Defender, Intune, Power BI, and Azure AD Premium.
If your tenant has a licence outside that catalogue, the report will say so explicitly rather than silently skipping it — so you always know exactly what was and wasn't priced.
Kyberbyte requests the following Microsoft Graph API permissions — all read-only, none write:
User.Read.All — full user profiles, including account status and sign-in activityLicenseAssignment.Read.All — which licences are assigned to which usersDirectory.Read.All — directory objects including users, groups, and service principalsRoleManagement.Read.Directory — directory role assignments (used to identify admin accounts for guardrail protection)GroupMember.Read.All — group memberships (used to identify shared mailboxes and distribution groups)MailboxSettings.Read — mailbox configuration settings such as auto-reply status (used to help identify shared and inactive mailboxes — not mailbox content)Organization.Read.All — tenant-level subscription and organisation informationAuditLog.Read.All — sign-in and activity audit logsReports.Read.All — Microsoft 365 usage reports (application activity per user)User.Read — the signed-in admin's own profile (delegated, used for authentication)Kyberbyte cannot read email content, files, Teams messages, calendar entries, or any user-generated content. The consent screen Microsoft presents to your admin reflects exactly these permissions — nothing beyond what's listed above.
There are three levels of accuracy available, depending on how much detail you want to give us:
The free preview always shows which pricing basis was used, so you can see at a glance whether the figures reflect list price or your own rates.
Guardrails are rules that prevent recommendations from being made against accounts where removal could cause serious operational harm — even if they look like waste on paper.
For example, an account with no recent sign-in activity might look inactive — but if it's a Global Administrator, a service account, or a shared mailbox with recent inbound activity, Kyberbyte will flag it for your awareness rather than recommend removal. You'll see these in the full report with the reason they were held back.
The guardrail system is designed to make the report safe to act on directly — you shouldn't need to second-guess whether a recommendation is risky.
Yes. Each scan is a separate, independent audit of your tenant at that point in time. If you action the recommendations from your first report and want to verify the changes, or if your organisation grows and you want a fresh view, you can run another scan.
Tenants with 10 or fewer licensed users get a recurring free scan, available again every 30 days. Larger tenants get one free scan; after that, running another requires a re-scan credit.
Buying a re-scan credit gets you more than just permission to scan sooner — when you use it, the full detailed report from that scan is included automatically, and you'll also receive 1 bonus credit to check back in on your changes later, at no extra cost. That bonus credit works the same way when you use it, but doesn't earn you a further one on top — so the free check-back is a one-time thing per credit purchased.
Scan data is processed and stored on Microsoft Azure infrastructure in the UK. We store the output of your scan (user-level licence and activity data) to generate and serve your report — not indefinitely.
Specifically: scan results are retained for up to 90 days after your scan date, after which they are deleted from our systems. Your report download is yours to keep indefinitely — we just don't hold the underlying data longer than needed.
We do not sell, share, or transfer your tenant data to any third party. See our Privacy Policy for full detail.
No. Your tenant data — user names, licence assignments, activity signals — is used solely to generate your report. It is not aggregated, benchmarked against other tenants, used to train models, or analysed for any purpose beyond producing your specific output.
The statistics on our website (e.g. "30% of licences go unused") come from published third-party research, not from data collected through Kyberbyte scans.
Yes — the easiest method is to open the downloaded HTML file in your browser and use File → Print → Save as PDF. In Chrome and Edge this produces a clean, well-formatted output. The report is styled to print cleanly, with the full detail intact.
A native PDF export option is on the roadmap. For now, the browser print route works well for attaching to emails or sharing with Finance.
Not yet. Right now, the report is designed to give you everything you need to action the recommendations yourself — named users, specific licences, and the saving for each change.
A managed implementation option, where we make the changes for you, is something we're considering for the future but haven't built or scoped yet. If that's something you'd find valuable, let us know — it helps us prioritise.
The product works for any Microsoft 365 commercial tenant, regardless of geography — the scan itself doesn't care where you're based. Pricing estimates default to UK list pricing in GBP, using whichever pricing basis you select for the commitment structure.
If you're outside the UK, or your actual costs differ from UK list price, you can upload your Microsoft invoice and we'll extract your real per-licence costs to use instead — see the question above on list price vs custom pricing for how that works.
Our company is UK-registered and our primary market is the UK and Ireland, so the experience is most polished there today. Support for additional regional pricing defaults is something we'd consider with enough demand.
Yes. Each client tenant is a separate Microsoft environment, so each one requires its own admin consent to grant Kyberbyte read-only access to their data. This is a standard Microsoft requirement — cross-tenant access isn't possible without explicit per-tenant consent.
In practice, this means a client's Global Admin needs to approve the consent screen once per tenant. It takes under two minutes and only needs to happen once — subsequent scans of the same tenant don't require re-consent unless the permissions change.
We provide a short, plain-English explanation you can send to clients ahead of the consent step if they want to understand what they're approving.
Currently, the MSP workspace is MSP-access only — your clients don't have their own portal login. Reports are delivered to you, and how you share them with clients is your choice (most MSPs download the HTML and include it in a quarterly business review pack, or send it directly).
Client-facing access is something we're evaluating for a future release — if that's important to your workflow, let us know and we'll factor it into roadmap prioritisation.
Not at this time. Reports carry Kyberbyte branding and there are no current plans to change that in the near term. This is something we may revisit further down the line, but we'd rather be straightforward than put it on a roadmap we can't commit to.
In practice, most MSPs add a short cover memo or summary in their own template when presenting to clients — the report itself handles the detailed content, so the Kyberbyte branding tends not to be a friction point. If it's a hard requirement for your business, let us know so we can have an honest conversation about fit.
The MSP is billed through the workspace — not your clients. How you charge your clients for the audit and any remediation work is entirely up to you; most MSPs include it within a remediation quote or as a line item on a managed service invoice.
Kyberbyte is currently free during the early access pilot for tenants up to 250 users. A pricing model for general availability is still being finalised — we'll confirm details before any billing begins.
Tenant management is fully self-serve. From your MSP workspace you can create a workspace, add new client tenants, and remove them at any time — no involvement from us required.
Adding a tenant triggers the standard Microsoft Graph consent flow for that client. Once their admin approves, the tenant appears in your workspace and is ready to scan.
We'll get back to you within one business day.
Free scan. Results in minutes. No commitment until you've seen the numbers.