Read-only • No data stored beyond assessment results

Know exactly which
E5 licenses to cut.

Connect your Microsoft 365 tenant and get per-user downgrade classifications in minutes — backed by live Graph API signals across PIM, Conditional Access, Defender, and eDiscovery.

Connect Your TenantAdmin consent required • Read-only permissions • No data modification
$252
saved per user / year
E5→E3
license delta target
< 5 min
time to full assessment

How it works

Three steps from consent to cost savings

01

Connect

Grant read-only admin consent. We request minimum permissions: User, Directory, Policy, and Role data.

02

Scan

Our engine checks each E5 user against PIM assignments, risk-based CA policies, Defender enrollment, and eDiscovery.

03

Act

Download a CSV with classifications, confidence scores, and remediation steps. Bring it to your licensing review.

Four-tier classification system

Every E5 user receives a deterministic safety classification with a confidence score

Safe to Downgrade

No E5-exclusive feature dependencies detected. Can move to E3 immediately.

Safe with Remediation

Minor dependencies exist. Remove them (e.g., risk-based CA policy) then downgrade.

Not Safe

Active PIM, eDiscovery, or Defender P2 dependencies. Downgrade would break functionality.

Requires Review

Signal data was unclear or incomplete. Manual review recommended.

Exactly what we request — nothing more.

We request the minimum Graph API permissions required to assess E5 dependencies. All are read-only. We never write to your tenant.

User.Read.All

Read user license assignments

Directory.Read.All

Read organizational data

Group.Read.All

Read group license assignments

Policy.Read.All

Read Conditional Access policies

RoleManagement.Read.Directory

Read PIM role assignments

eDiscovery.Read.All

Detect eDiscovery custodians