Skip to content

Troubleshooting

Common issues you may hit while using the portal, and what to do about them. These are all things you can resolve from the portal itself.

A tenant shows RE-AUTH NEEDED

New permissions were added since that tenant was connected. In Companies, click Re-authorize on that row and have the customer's Global Admin consent again. The badge clears on the next sync. See Connecting a Tenant › Re-authorizing later.

A write action fails with "insufficient permissions"

Two things to check:

  1. Is the tenant provisioned read/write? Read-only tenants block all changes by design. See Permission tiers.
  2. Is your role high enough? Actions need Engineer or above; system settings need SuperAdmin. See Roles & Access.

A change I made isn't showing up

  • Some data is cached. Use the Refresh from M365 button on the page to pull the latest.
  • Directory changes in Microsoft can take a minute or two to propagate. Wait, then refresh.
  • Confirm you were on the right tenant in the picker when you made the change.

A report page is empty

  • Check the freshness stamp near the top. A stale or missing cache usually just needs Refresh from M365.
  • For integration-backed sections (tickets, vulnerabilities, phishing), confirm the client is mapped to that integration under Admin › Settings › Integrations.
  • Some sections belong to a paid add-on. If the client doesn't have it, the section shows an upsell panel instead of data. That's expected, not an error.

MFA shows 0% or "no MFA" for a whole tenant

MFA registration is read per user even without premium licensing, so coverage figures work for every tenant. Detailed sign-in activity (last sign-in dates, sign-in logs) does need Microsoft Entra ID P1; tenants without it show those figures as unavailable rather than a true zero.

"Last login" looks wrong

Microsoft updates the sign-in timestamp on failed attempts too, so a blocked account can appear to have "logged in" recently. Use the Last Successful Login value in the user's Sign-in Activity, which is shown separately from the last attempt.

A tenant's data looks stale on the dashboard

Data is refreshed by a background sync that runs continuously. If one tenant looks behind while others are current, give it a sync cycle to catch up. If it persists, flag it to a SuperAdmin. See Sync Scheduling.

The tenant I want isn't in the picker

  • A newly connected tenant appears within a few minutes. Give it a moment and refresh the page.
  • If you have scoped client access, you only see your assigned clients. Ask a SuperAdmin if you need another client added.

A customer says they didn't get a scheduled report

Open Admin › Settings › Report Scheduling › Send history and check that report's last send outcome. It logs success and failure per report so you can confirm whether it went out.

Still stuck?

If none of the above resolves it, escalate to a SuperAdmin with the client name, the page, and what you expected to see versus what you saw.

Internal & partner documentation.