FAQ

Frequently Asked Questions

Answers to the things people ask before they scan — and after they see the results.

Something not covered here? Get in touch →

General Questions

For everyone
What Microsoft 365 admin role do I need to connect my tenant?

You need to be a Global Administrator in your Microsoft 365 tenant to grant the consent Kyberbyte requests. This is a one-time step — you authenticate via Microsoft's standard sign-in and approve read-only API access.

If you're not a Global Admin, you'll need someone with that role to approve the consent screen. The scan itself can be initiated by whoever has your Kyberbyte login — the Microsoft admin only needs to be involved at the connection step.

Which Microsoft 365 plans and licence types are supported?

Kyberbyte's pricing catalogue covers over 600 commercial Microsoft 365 and Microsoft 365-adjacent SKUs — including the full Business family (Basic, Standard, Premium, Apps), the Enterprise family (E3, E5, F1, F3), and standalone add-ons such as Exchange Online, Microsoft Defender, Intune, Power BI, and Azure AD Premium.

If your tenant has a licence outside that catalogue, the report will say so explicitly rather than silently skipping it — so you always know exactly what was and wasn't priced.

What exactly does "read-only" access mean — what can Kyberbyte see?

Kyberbyte requests the following Microsoft Graph API permissions — all read-only, none write:

  • User.Read.All — full user profiles, including account status and sign-in activity
  • LicenseAssignment.Read.All — which licences are assigned to which users
  • Directory.Read.All — directory objects including users, groups, and service principals
  • RoleManagement.Read.Directory — directory role assignments (used to identify admin accounts for guardrail protection)
  • GroupMember.Read.All — group memberships (used to identify shared mailboxes and distribution groups)
  • MailboxSettings.Read — mailbox configuration settings such as auto-reply status (used to help identify shared and inactive mailboxes — not mailbox content)
  • Organization.Read.All — tenant-level subscription and organisation information
  • AuditLog.Read.All — sign-in and activity audit logs
  • Reports.Read.All — Microsoft 365 usage reports (application activity per user)
  • User.Read — the signed-in admin's own profile (delegated, used for authentication)

Kyberbyte cannot read email content, files, Teams messages, calendar entries, or any user-generated content. The consent screen Microsoft presents to your admin reflects exactly these permissions — nothing beyond what's listed above.

Are savings estimates based on list price or what we actually pay?

There are three levels of accuracy available, depending on how much detail you want to give us:

  • List price (default). Estimates use standard Microsoft UK list pricing — no setup required.
  • Pricing basis (semi-custom). You can tell us your commitment structure — annual paid monthly, annual paid upfront, or monthly — and we'll adjust the per-licence cost to reflect that structure using Microsoft's published pricing.
  • Custom pricing (fully tenant-specific). If you're on CSP, MSP, or negotiated rates, you can upload your Microsoft invoice and we'll extract your actual per-licence costs to use instead of list pricing.

The free preview always shows which pricing basis was used, so you can see at a glance whether the figures reflect list price or your own rates.

What are "guardrail-protected users" — why are some accounts flagged but not recommended for removal?

Guardrails are rules that prevent recommendations from being made against accounts where removal could cause serious operational harm — even if they look like waste on paper.

For example, an account with no recent sign-in activity might look inactive — but if it's a Global Administrator, a service account, or a shared mailbox with recent inbound activity, Kyberbyte will flag it for your awareness rather than recommend removal. You'll see these in the full report with the reason they were held back.

The guardrail system is designed to make the report safe to act on directly — you shouldn't need to second-guess whether a recommendation is risky.

Can I re-scan after acting on the recommendations?

Yes. Each scan is a separate, independent audit of your tenant at that point in time. If you action the recommendations from your first report and want to verify the changes, or if your organisation grows and you want a fresh view, you can run another scan.

Tenants with 10 or fewer licensed users get a recurring free scan, available again every 30 days. Larger tenants get one free scan; after that, running another requires a re-scan credit.

Buying a re-scan credit gets you more than just permission to scan sooner — when you use it, the full detailed report from that scan is included automatically, and you'll also receive 1 bonus credit to check back in on your changes later, at no extra cost. That bonus credit works the same way when you use it, but doesn't earn you a further one on top — so the free check-back is a one-time thing per credit purchased.

What data is stored, where, and for how long?

Scan data is processed and stored on Microsoft Azure infrastructure in the UK. We store the output of your scan (user-level licence and activity data) to generate and serve your report — not indefinitely.

Specifically: scan results are retained for up to 90 days after your scan date, after which they are deleted from our systems. Your report download is yours to keep indefinitely — we just don't hold the underlying data longer than needed.

We do not sell, share, or transfer your tenant data to any third party. See our Privacy Policy for full detail.

Is my tenant data ever used for benchmarking, analytics, or training?

No. Your tenant data — user names, licence assignments, activity signals — is used solely to generate your report. It is not aggregated, benchmarked against other tenants, used to train models, or analysed for any purpose beyond producing your specific output.

The statistics on our website (e.g. "30% of licences go unused") come from published third-party research, not from data collected through Kyberbyte scans.

The full report is HTML — can I convert it to PDF?

Yes — the easiest method is to open the downloaded HTML file in your browser and use File → Print → Save as PDF. In Chrome and Edge this produces a clean, well-formatted output. The report is styled to print cleanly, with the full detail intact.

A native PDF export option is on the roadmap. For now, the browser print route works well for attaching to emails or sharing with Finance.

Can Kyberbyte action the report's recommendations for me?

Not yet. Right now, the report is designed to give you everything you need to action the recommendations yourself — named users, specific licences, and the saving for each change.

A managed implementation option, where we make the changes for you, is something we're considering for the future but haven't built or scoped yet. If that's something you'd find valuable, let us know — it helps us prioritise.

Does Kyberbyte work for organisations outside the UK?

The product works for any Microsoft 365 commercial tenant, regardless of geography — the scan itself doesn't care where you're based. Pricing estimates default to UK list pricing in GBP, using whichever pricing basis you select for the commitment structure.

If you're outside the UK, or your actual costs differ from UK list price, you can upload your Microsoft invoice and we'll extract your real per-licence costs to use instead — see the question above on list price vs custom pricing for how that works.

Our company is UK-registered and our primary market is the UK and Ireland, so the experience is most polished there today. Support for additional regional pricing defaults is something we'd consider with enough demand.

For MSPs & IT Consultancies

Self-serve
Does each client tenant need to grant fresh Microsoft Graph consent?

Yes. Each client tenant is a separate Microsoft environment, so each one requires its own admin consent to grant Kyberbyte read-only access to their data. This is a standard Microsoft requirement — cross-tenant access isn't possible without explicit per-tenant consent.

In practice, this means a client's Global Admin needs to approve the consent screen once per tenant. It takes under two minutes and only needs to happen once — subsequent scans of the same tenant don't require re-consent unless the permissions change.

We provide a short, plain-English explanation you can send to clients ahead of the consent step if they want to understand what they're approving.

Can my clients access the portal and view their own reports?

Currently, the MSP workspace is MSP-access only — your clients don't have their own portal login. Reports are delivered to you, and how you share them with clients is your choice (most MSPs download the HTML and include it in a quarterly business review pack, or send it directly).

Client-facing access is something we're evaluating for a future release — if that's important to your workflow, let us know and we'll factor it into roadmap prioritisation.

Are the reports white-labelled — can I brand them with my MSP's name?

Not at this time. Reports carry Kyberbyte branding and there are no current plans to change that in the near term. This is something we may revisit further down the line, but we'd rather be straightforward than put it on a roadmap we can't commit to.

In practice, most MSPs add a short cover memo or summary in their own template when presenting to clients — the report itself handles the detailed content, so the Kyberbyte branding tends not to be a friction point. If it's a hard requirement for your business, let us know so we can have an honest conversation about fit.

How does billing work — does the MSP pay and re-bill, or can clients pay directly?

The MSP is billed through the workspace — not your clients. How you charge your clients for the audit and any remediation work is entirely up to you; most MSPs include it within a remediation quote or as a line item on a managed service invoice.

Kyberbyte is currently free during the early access pilot for tenants up to 250 users. A pricing model for general availability is still being finalised — we'll confirm details before any billing begins.

How do I add or remove client tenants from my workspace?

Tenant management is fully self-serve. From your MSP workspace you can create a workspace, add new client tenants, and remove them at any time — no involvement from us required.

Adding a tenant triggers the standard Microsoft Graph consent flow for that client. Once their admin approves, the tenant appears in your workspace and is ready to scan.

Still have a question?

We'll get back to you within one business day.

Ready to find out what's being wasted?

Free scan. Results in minutes. No commitment until you've seen the numbers.