Runs in your Azure subscription
The code runs in an Azure Functions app in your subscription, in the EU region you choose. Microsoft bills you for the Azure resources directly.
Areza builds Copilot readiness checks, document control, Teams bots and Microsoft Graph automations that run inside your company's own Microsoft 365 and Azure tenant, so your documents do not pass through our servers.
Your Microsoft 365 environment · illustrative example
Your Microsoft 365 tenant
Our components inside it
Documents stay in your tenant
01
Four offers you can start separately. Each one runs with permissions your administrator approves.
Before you switch on Microsoft 365 Copilot, find out who can see what in SharePoint and OneDrive. The check only reads, and shows links anyone can open, files shared with the whole organisation and access left behind by people who have left.
Required monthly documents for each client or case: what is missing, who to remind and which folder a newly received file belongs in. Scanned documents are read inside your own Azure subscription.
Reminders, requests and approvals in a Teams chat: a card with buttons, a file taken in, and a clear reply saying where it was filed.
Microsoft Graph apps that connect Outlook, SharePoint, Teams and your business systems with the narrowest permissions the job needs. When Power Automate is enough, we say so.
02
For a larger company, what an app does matters as much as where it runs and what it can reach. So we build everything to run in your tenant with as few rights as possible.
The code runs in an Azure Functions app in your subscription, in the EU region you choose. Microsoft bills you for the Azure resources directly.
The check and the Teams bot sign in with a managed identity, so there is no password, key or certificate to store or rotate.
The check needs read permissions only. Where writing is needed, it is limited to one SharePoint site, and the app can send email from one shared mailbox only.
The check changes nothing. Changes to files or permissions are a separate step, made only from a list you have approved.
03
Before offering this, we tested it in our own Microsoft 365 test environment with invented data. We planted the gaps and the risky access on purpose, so we knew what the app should find.
Measured on 2026-10-08 in our own Microsoft 365 test environment with invented data and read permissions only. It shows the check works on a real Microsoft 365 tenant; it does not show how it will work on your data. These are test results, not a client project.
04
Also in our own test environment with invented data, on 2026-10-08 and 2026-10-09:
05
01
We find out where your documents are kept, who administers Microsoft 365 and what you want to achieve. It helps to bring your IT administrator.
02
We send the scope, the list of permissions needed and a fixed price excluding VAT.
03
We start with a read-only check, or with a small pilot covering one team and one process.
04
We deploy in your tenant together with your IT team and, if you need it, support the solution after launch.
Something else on your mind?
No. Everything runs in your Microsoft 365 tenant and your Azure subscription, and we do not copy documents to our own servers. We deploy the Azure resources in the EU region you choose.
Microsoft's documentation says Copilot only shows organisational data that the user already has at least view permission for. That is why it is worth checking who can see what before you switch it on, which is exactly what our Copilot readiness check does.
We do not publish a price, because it depends on scope. After a 30-minute call we send a fixed price for the check or the pilot in writing, excluding VAT. Microsoft bills you directly for the Azure resources.
Approve the app permissions (this needs a Global Administrator or Privileged Role Administrator), create a resource group in an Azure subscription in an EU region and, if you want email reminders, a shared mailbox. We prepare the steps and the scripts.
No. Areza is an independent company and is not affiliated with Microsoft. We build apps that use Microsoft 365, Microsoft Graph and Azure inside your tenant.
Delete the Azure resource group the solution runs in: the app, its identities and its stored data go with it. The remaining steps, such as removing the Exchange permission and the Teams app, are listed in the handover document.