Microsoft 365 + Azure reporting

Your whole tenant. One report.

Azure Reporter inventories every workload across Microsoft 365 and Azure — users, mailboxes, sites, teams, Conditional Access policies, role assignments and spend — into one self-hosted reporting platform. Snapshot-based history. PDF-ready executive reports. Your data never leaves your tenant.

Why Azure Reporter

One platform for everything your tenant runs

Stop bouncing between the Entra portal, Exchange admin center, SharePoint admin, Teams admin, the Azure portal and Cost Management. Sync once, report on everything.

Every workload, unified

Directory, Exchange, SharePoint, Teams, Azure, Billing and Conditional Access in one inventory.

Point-in-time history

Every sync writes a snapshot. Compare any two to see exactly what changed and when.

Executive-ready PDFs

21 polished report templates, server-rendered, scheduled or on-demand. Email them, save them, share them.

Self-hosted, read-only

Runs on your SQL Server with read-only Graph and ARM access. Your tenant data stays on your network.

Modules

A module for every part of Microsoft 365 and Azure

Turn on what you need. Each module syncs independently, writes to its own tables and feeds the same dashboards, reports and exports.

Microsoft Entra ID

Every user, group, license SKU and on-prem sync flag. Sign-in activity on P1+ tenants. The canonical source that every other module enriches.

Exchange Online

Mailbox composition, quotas, storage usage bands, automatic replies, archive coverage, time-zone mix and top mailboxes by size.

SharePoint & OneDrive

Every site collection plus personal OneDrives. Storage allocated vs used, top sites by size, owners by site count, activity recency bands.

Teams & Calling

Team activity, channel composition, guest exposure, Phone System adoption, PSTN spend, Direct Routing call success rate.

Azure resources

Every resource across every subscription, grouped by type / region / RG. Optional detailed mode extracts ARM properties and dependency edges.

Azure cost management

Current vs last month spend, top subscriptions and resources, spend by service and region, budget tracking, marketplace charges.

Conditional Access

Every policy, named location, grant control and target. Plus last-30-day usage from sign-in logs — who’s hitting what, when, and how often.

RBAC & privileged access

Every Azure role definition and assignment, with scope tree. Highlight Owner / Contributor / User Access Administrator grants for review.

Snapshot history

Every sync writes a new snapshot with a record count. Pick any past point to view as the active dataset — perfect for monthly compliance evidence.

Conditional Access

Find out which CA policies actually fire

Sync your Conditional Access policies, named locations, grant controls and target matrix — then layer 30 days of sign-in log data on top so you can see which policies are working, which aren’t, and which are quietly doing nothing.

  • Every policy at a glance. State, grant operator, built-in controls, authentication strength and target counts in one summary view.
  • Estimated user coverage. Direct users, included groups (with member counts), All-users / Guests sentinels — so you know who a policy actually touches.
  • Last-30-day usage from sign-in logs. Evaluations, successful applies, failures, last-applied timestamp, top apps and top users — per policy.
  • Spot policies doing nothing. Enabled-but-unused report lists policies that haven’t fired once in the last 30 days — candidates for review or retirement.
  • Per-user coverage. Open any user’s profile to see exactly which CA policies are configured to affect them and how.
Executive reports

PDFs that look like the executive summary — automatically

21 built-in report templates spanning summary, detailed and change-tracking formats for every module. Server-rendered via QuestPDF — no headless browser to maintain, no Chromium download, no rendering surprises.

  • Summary reports. Single-page exec briefings — Tenant Overview, Azure Cost, Security Posture, CA Summary, Teams, Exchange, SharePoint.
  • Detailed reports. Operational depth — full breakdowns per module with KPI tiles, composition breakdowns and per-entity tables.
  • Change reports. Diff the latest two snapshots — what was added, removed or modified since the previous sync.
  • Schedule + email. Pick a frequency, pick recipients. Reports generate on the server and arrive as PDF attachments at the scheduled time.
  • Data Extract builder. Pick a data source, choose columns, save it as a custom report template. Export to PDF, Excel or CSV.
Example: Tenant Overview PDF — rendered by QuestPDF, no Chromium required.

Snapshot history

What changed last week? Last month? Last quarter?

Every sync writes a new snapshot for every module. View the tenant as it was on any past date. Diff any two snapshots for a clean list of what was added, removed or modified — perfect for compliance evidence, change audits, and “what did we do last quarter” board prep.

Snapshot retention is configurable per module — keep as many as you want.
6
Change reports — one per module — diffing the latest two snapshots automatically.
1
Click to swap snapshot on any page — every chart, table and report refreshes.

Security & deployment

Self-hosted. Read-only. Your data, your network.

Azure Reporter runs on your own SQL Server with a service principal that only has read-only Microsoft Graph and Azure ARM access. Tenant data is synced into your database and stays there.

Read-only access only

Graph application permissions are all .Read.All. Azure access is via the Reader RBAC role (plus Cost Management Reader for billing). No write permissions ever.

Your SQL Server

Deploys to your own infrastructure — bare metal, VM, container, App Service or Kubernetes. The database lives wherever you tell it to. Nothing phones home.

Granular role permissions

Built-in Admin and Reporter roles, or define your own. Per-module permissions, per-action audit log, sync throttling, and configurable retention windows.

Full audit trail

Every sign-in, sync trigger, settings change, schedule edit and report download is recorded in the audit log with category, actor and target.

Background sync queue

Manual syncs run on a background worker so the request finishes immediately. Schedule any module on a cron-style frequency for hands-off operation.

Signed license model

Locked to your Entra tenant via a cryptographically signed XML license. Per-module entitlement and per-seat caps are enforced at load time.