Areza
Microsoft 365 and Azure, in your tenant

Microsoft 365 automation that runs inside your own tenant

Areza builds Copilot readiness checks, document control, Teams bots and Microsoft Graph automations that run inside your company's own Microsoft 365 and Azure tenant, so your documents do not pass through our servers.

Your Microsoft 365 environment · illustrative example

Your Microsoft 365 tenant

  • SharePoint
  • OneDrive
  • Teams
  • Outlook

Our components inside it

  • Access checkread-only
  • Document checkmanaged identity
  • Remindersone mailbox

Documents stay in your tenant

01

What we build in your Microsoft 365

Four offers you can start separately. Each one runs with permissions your administrator approves.

02

Why your IT team can accept it

For a larger company, what an app does matters as much as where it runs and what it can reach. So we build everything to run in your tenant with as few rights as possible.

Runs in your Azure subscription

The code runs in an Azure Functions app in your subscription, in the EU region you choose. Microsoft bills you for the Azure resources directly.

No stored passwords

The check and the Teams bot sign in with a managed identity, so there is no password, key or certificate to store or rotate.

Only the permissions needed

The check needs read permissions only. Where writing is needed, it is limited to one SharePoint site, and the app can send email from one shared mailbox only.

Changes only after you approve

The check changes nothing. Changes to files or permissions are a separate step, made only from a list you have approved.

03

What we tested

Before offering this, we tested it in our own Microsoft 365 test environment with invented data. We planted the gaps and the risky access on purpose, so we knew what the app should find.

Measured on 2026-10-08 in our own Microsoft 365 test environment with invented data and read permissions only. It shows the check works on a real Microsoft 365 tenant; it does not show how it will work on your data. These are test results, not a client project.

18 of 18
planted document gaps found
12 of 12
planted risky access found
0
false findings in the same test
731
files in the folders of 18 invented clients

04

More test results

Also in our own test environment with invented data, on 2026-10-08 and 2026-10-09:

  • The document check, including text recognition, ran in an Azure Functions app in an EU region, with a managed identity holding read permissions only.
  • The reminder app could send email only from its own shared mailbox: Microsoft refused an attempt to send as another person (HTTP 403).
  • The Teams bot sent a reminder, took in a file sent back in the chat and filed it in the right folder under the standard name; when unsure, it asked with buttons.
  • The access check did not need Sites.FullControl.All: with read permissions the results were identical.

05

How we start

How we work and how we price
  1. 01

    A 30-minute call

    We find out where your documents are kept, who administers Microsoft 365 and what you want to achieve. It helps to bring your IT administrator.

  2. 02

    A price in writing

    We send the scope, the list of permissions needed and a fixed price excluding VAT.

  3. 03

    A check or a pilot

    We start with a read-only check, or with a small pilot covering one team and one process.

  4. 04

    Rollout and support

    We deploy in your tenant together with your IT team and, if you need it, support the solution after launch.

Common questions.

Something else on your mind?

Book a call
Do our documents leave our Microsoft 365?

No. Everything runs in your Microsoft 365 tenant and your Azure subscription, and we do not copy documents to our own servers. We deploy the Azure resources in the EU region you choose.

What can Microsoft 365 Copilot see?

Microsoft's documentation says Copilot only shows organisational data that the user already has at least view permission for. That is why it is worth checking who can see what before you switch it on, which is exactly what our Copilot readiness check does.

How much does it cost?

We do not publish a price, because it depends on scope. After a 30-minute call we send a fixed price for the check or the pilot in writing, excluding VAT. Microsoft bills you directly for the Azure resources.

What will our IT team need to do?

Approve the app permissions (this needs a Global Administrator or Privileged Role Administrator), create a resource group in an Azure subscription in an EU region and, if you want email reminders, a shared mailbox. We prepare the steps and the scripts.

Is Areza affiliated with Microsoft?

No. Areza is an independent company and is not affiliated with Microsoft. We build apps that use Microsoft 365, Microsoft Graph and Azure inside your tenant.

How do we remove your access if we stop?

Delete the Azure resource group the solution runs in: the app, its identities and its stored data go with it. The remaining steps, such as removing the Exchange permission and the Teams app, are listed in the handover document.

Let's agree where to start

In a 30-minute call we find out where your documents are kept, which permissions would be needed and whether to start with a read-only check or a pilot. You are welcome to bring your IT administrator.

Book a free call

30 min · free · price in writing, excluding VAT

A free 30-minute call

After the call we send a fixed price for the check or the pilot in writing, excluding VAT.

  • Where your documents are kept and which permissions would be needed
  • Where to start: a read-only check or a pilot
  • What your IT team would need to do

1 of 2 · How can we reach you?

It takes less than a minute.