🚀 COMING SOON — Join the waitlist for early access
Unify365
console services assistant compliance trust model security
Log in Join the waitlist
$ the ai operations layer for m365

Your Microsoft 365 tenant, managed in plain English.

Nine admin centers collapsed into one console. Ask questions about users, licenses, devices, mail, and security posture — get instant answers from live data, audit-ready reports, and safe one-touch automation. Every change previewed. Every action logged.

read-only scopes at install · nothing happens without a human saying yes
unify365 — assistant · contoso.onmicrosoft.com
you@contoso ›
which users still hold an E5 and haven't signed in for 60 days?
✓ queried Entra ID sign-in logs + license assignments · 847 users scanned · live data
userlast sign-inlicense
l.moreno94 daysE5
j.okafor71 daysE5
svc-legacy01312 daysE5
3 users · est. waste $1,373/yr — draft a reclaim plan? [y/N]
ENTRA ID·EXCHANGE ONLINE·SHAREPOINT·ONEDRIVE·TEAMS·INTUNE·DEFENDER·PURVIEW·LICENSING & BILLING
01 — THE UNIFIED DASHBOARD

One console for the whole estate.

A single admin consent connects the tenant. Live posture cards refresh through Microsoft Graph change notifications — the dashboard is never yesterday's data. Every number drills down to the underlying records: filterable, sortable, exportable.

Unify365
contoso.onmicrosoft.com ▾
Ask anything about your tenant…
LIVE MA
Overview
Users & Groups
Licenses
Devices
Mail Flow
Security
Compliance
Reports
Audit Log
SAVED QUERIES
Stale E5 holders
External fwd rules
Guests > 90d idle
USERS
847
98% MFA enabled
LICENSES
912
31 unassigned · $2,140/mo
DEVICES
1,204
12 non-compliant
SIGN-IN RISK (24H)
3
1 open · 2 dismissed
MAIL FLOW
OK
2 external fwd rules
STORAGE
71%
6.2 TB of 8.7 TB
DEFENDER ALERTS
5
1 high · 4 informational
SERVICE HEALTH
9/9
all services healthy
Drift from baseline — last 7 daysview all →
HIGHNew Global Admin — r.diaz@contoso.com2h
MEDExternal sharing enabled — /sites/finance1d
HIGHLegacy auth re-enabled — CA policy “Baseline”3d
Secure Score trend71% ▲4
JANJUL
ASSISTANT
clean up stale guest accounts
Found 14 guests with no sign-in for 90+ days across 6 Teams. Drafted a removal plan — review the diff before anything runs.
Review planDismiss
Sign-in for k.tanaka flagged: impossible travel (Osaka → Lagos, 40 min). Recommend session revocation. Explain why →
Ask or act…
Drill-down everywhere. Every number opens the records behind it. Role-based views. Helpdesk, security, finance — each sees only their slice. Custom dashboards. Any saved query becomes a card.
02 — FULL SERVICE COVERAGE

It speaks fluent Microsoft 365 — every service, in depth.

Not a wrapper around one API. Unify365 surfaces the details the admin centers hide behind tabs — forwarding rules, CA policy internals, compliance check-ins, sharing links, retention holds.

Entra ID
users · groups · roles · CA · sign-in logs
CA: Require MFA — all usersON
CA: Block legacy authREPORT-ONLY
Privileged roles4 GLOBAL ADMINS
Exchange Online
mailboxes · forwarding · mail flow
j.kim → gmail.comEXT FWD
sales@ → partner.ioEXT FWD
Shared mailboxes23
SharePoint & OneDrive
sites · storage · external sharing
/sites/finance88%
/sites/engineering54%
Anonymous links17 ACTIVE
Teams
teams · guests · policies
Active teams64
Guest accounts112 · 14 STALE
Ownerless teams3
Intune
devices · compliance · configuration
Compliant1,192 / 1,204
Missed 3+ check-ins12
Pending OS updates87
Defender
alerts · Secure Score
Phishing campaign detectedHIGH
Malware quarantined4 · 7 DAYS
Secure Score71% ▲4
Purview
audit · retention
Retention policies8 ACTIVE
Unified audit logENABLED
eDiscovery holds2
Licensing & Billing
SKUs · assignment · spend
E5 — 412 of 440 used94%
E3 — 397 of 400 used99%
Reclaimable spend$2,140/MO
03 — THE AI ASSISTANT

Multi-step operations, with a plan you approve first.

Tell it what you want done. It drafts the full plan — which objects, what criteria, what happens to each — and nothing runs until a human approves. Approved plans execute step-by-step with a live log.

Answers from live data — never canned responses. Every answer cites what it queried.
Explanations, not just data — why a sign-in was risky, what a policy actually does, in plain English.
Tenant memory — it knows your naming conventions, baselines, and documented exceptions.
Reports on demand — “license waste report for the CFO” becomes a branded document in seconds.
Assistant every step logged to the audit trail
Offboard Dana Whitfield — she left on Friday.
Found dana.whitfield@contoso.com (Marketing, E3, 2 devices, 14 group memberships). Here's the offboarding runbook — nothing runs until you approve:
1Disable account + revoke all sessions and tokens
2Convert mailbox to shared → manager: t.osei
3Set out-of-office auto-reply (template: departure)
4Transfer OneDrive ownership → t.osei (90-day window)
5Reclaim E3 license → return to pool
6Remove from 14 groups · retire 2 Intune devices
DRY-RUN PREVIEW — THE EXACT DIFF
− accountEnabled: true → false
− licenses: [E3] → []
− mailboxType: user → shared
…14 group removals, 2 device retirements
Type the user's name to arm this action:
dana.whitfield
Send for approval
maker/checker: requires sign-off from an approver role
✓ APPROVED BY M.ALVAREZ · EXECUTING
account disabled · 41 sessions revoked
mailbox converted to shared
transferring OneDrive ownership… (3 of 6)
audit #8412 · rollback available for 30 days
04 — ONE-TOUCH COMPLIANCE

Governing-body compliance checks — and the fixes — in one click.

Assess the tenant against built-in baseline packs. Findings arrive in plain English, ranked by risk and effort — written so both the auditor and the CEO understand them. Every finding carries a prepared remediation that flows through the approval gate.

74%
POSTURE
Compliance posture
Tracked as a trend, not a snapshot. Updates in real time as remediations land.
Microsoft Secure Score71% ▲4
CIS M365 Foundations Benchmark81 / 104 controls
NIST CSF-aligned baseline68%
HIPAA pack3 gaps
SOC 2 pack92%
CMMC-aligned controlsL1 met · L2 74%
Run assessment — all packs
last run 22 min ago · scheduled weekly
Findings — ranked by risk × effort 23 open · 81 passing
Legacy authentication is not blocked HIGH RISKLOW EFFORT
Why it matters: legacy protocols (IMAP, POP, SMTP AUTH) skip MFA entirely — most password-spray attacks come in this door. CIS 1.1.9 · NIST PR.AC-7 · Secure Score +8.
// prepared remediation — dry-run
+ CA policy “Block legacy auth” → enabled
affects 7 sign-ins/wk · 2 service accounts need app passwords first
Review fix → approve Document exception flows through the five-stage gate ↓
4 Global Admins — baseline allows 3 MEDreview fix →
17 anonymous sharing links older than 90 days MEDreview fix →
Mailbox auditing disabled on 3 shared mailboxes LOWreview fix →
drift watch armed — alerts the moment reality diverges from baseline ↓ export auditor evidence pack (time-stamped, control-mapped)
05 — AUTOMATION WITH A HUMAN IN THE MIDDLE

Unify365 never changes your tenant silently.

Every write action — from a license swap to a device wipe — passes through the same five-stage gate, each gated proportionally to its blast radius.

STAGE 1
Dry-run preview

The exact diff: which objects change, from what, to what.

STAGE 2
Typed confirmation

Type the target's name to arm the action. No accidental clicks.

STAGE 3
Maker / checker

Helpdesk proposes; an admin approves. Configurable per action type and role.

STAGE 4
Immutable audit

Who, what, when, before/after values — tamper-evident, exportable.

STAGE 5
Rollback

Where the platform allows it, one click restores the previous state.

action catalog: licenses · groups & roles · password resets · enable/disable · session revocation · mailbox conversion · device sync/retire/wipe · conditional access
06 — ALWAYS WATCHING

Alerts with an explanation, not just a red dot.

AI-contextualized alerting

Pushed to Teams, email, or webhook with a plain-English explanation and a recommended response.

⚠ IMPOSSIBLE TRAVEL — K.TANAKA
Sign-in from Osaka, then Lagos 40 minutes later. MFA passed both times — token theft is likely. Recommended: revoke sessions, require re-registration.
Anomaly baselines

Unify365 learns the tenant's normal — sign-in geography, license churn, sharing volume — and flags deviations. Fewer static thresholds, fewer false alarms.

sharing volume — baseline 40/day
today: 312 shares — 7.8σ above baseline
What-if simulation

Test a Conditional Access policy against the last 30 days of real sign-ins before enabling it. No more Friday-night lockouts.

simulate: “block non-compliant devices”
11,204 sign-ins unaffected
would have blocked 3 execs traveling in Mexico
→ suggest: add trusted-location exception
07 — SECURITY & ARCHITECTURE

Built for the security review, not around it.

Trust through restraint: the product's most important feature is what it refuses to do without you.

// consent model
granted: read-only Graph scopes
not granted: write scopes — separate, explicit consent event, only if you enable automation
Least-privilege by default

Read-only scopes at install. Write scopes are a separate consent you grant only when you enable automation.

Human-approved writes

No autonomous changes, ever. The five-stage gate applies to every write, including the ones the AI proposes.

Hard tenant isolation

Tenant identity derives from the authenticated session, never from a request. Cross-tenant leak tests run on every build.

Encryption everywhere

TLS in transit, encryption at rest, secrets in managed vaults — no static credentials in application code.

Complete auditability

Every read and write attributable to a person, a time, and a reason. Exportable. Streamable to Sentinel or Splunk.

Open surface

Everything in the UI exists in the API. Webhooks for events, PowerShell-friendly endpoints for the diehards.

Ask. Approve. Done.

Connect your tenant with a single admin consent — read-only until you decide otherwise.

Join the waitlist
© 2026 Unify365 — the AI operations layer for Microsoft 365 Terms of ServicePrivacy PolicyContact