Delegated IAM tools for scoped support teams
Use the tiles below to run approved Entra ID support actions. The portal only shows services available to your signed-in account.
Available Services
Start with the task you need.
Secure Secret Pickup
Sign in to retrieve your secure secret.
- Secret
Identity Verification
Sign in with your standard account to view the validation code.
- Validation code
No Services Available
Your account does not currently include a role for the available IAM services.
Secure Secret
Create a one-time secure link and email it to an internal or guest user.
PRV Verification
Create a verification link for the linked standard account and compare the validation code with the user.
Extension Attributes
Look up IAM user extension attributes from Microsoft Graph.
User Attributes
No user selected.
| Attribute | Value | Type |
|---|---|---|
| Lookup a user to view extension attributes. | ||
Entra App Changes
Submit a formal request to update an Entra Application field.
PIM Expiry
Review active and eligible PIM assignments from the daily expiry snapshot and renew them in bulk.
Expiring Assignments
Load the latest snapshot to view upcoming expiries.
| Type | Principal | Role or access | Target | Member | Expires | Days | |
|---|---|---|---|---|---|---|---|
| Load the latest snapshot to view upcoming expiries. | |||||||
Expired Assignments
Load the latest snapshot to view expired assignments not renewed in the last 30 days.
| Type | Principal | Role or access | Target | Member | Expired | Days overdue |
|---|---|---|---|---|---|---|
| Load the latest snapshot to view expired assignments. | ||||||
Application Credential Expiry
Valid app secrets, app certificates and SAML signing certificates approaching expiry.
| Application | Object | Credential | Expiry UTC | Days | Route |
|---|---|---|---|---|---|
| Load the current inventory. | |||||
Notification routing
Changes take effect on the next daily scan and are audited for 90 days.
Notification exclusions
Exclude an exact application ID from alerts and emails. Excluded credentials remain available in the inventory and audit trail.
| Application | Scope | Credential type | Reason | Review | |
|---|---|---|---|---|---|
| No exclusions loaded. | |||||
| Run a query to view sign-in logs. |
Find Token Look up a user to view and delete assigned OATH tokens.
AU Assigned Tokens List OATH tokens in your permitted scope.
| User | Display name | Serial number | Token ID | Status | Administrative Unit | Source |
|---|---|---|---|---|---|---|
| Load assigned tokens to view users in your scope. | ||||||
Batch Token Operations Upload a CSV to validate and run batch create, assign, activate, or delete operations.
CSV template guidance
UserPrincipalName, SerialNumber, SecretKey. Optional: Manufacturer, Model, TimeInterval, HashFunction.
UserPrincipalName and one of SerialNumber, TokenId, or MethodId.
Legacy Token Registry Import existing legacy token assignments for search, reporting, and duplicate checks.
CSV template guidance
upn or UserPrincipalName, and serialNumber. Optional: displayName, AdministrativeUnit, manufacturer, model. isEnabled and timeIntervalInSeconds are ignored. Blank AU is set to GERMANY for @mazars.de users.
Import Token Create, assign, and activate one OATH token in a V2 request.
OATH Result No token operation has run yet.
Token Details
No token selected.