SectionFAQ

Cindera · FAQ

Frequently Asked Questions

The questions IT managers, MSPs, and DPOs ask most often. If your question isn't here, email us — we add common ones back to this page.

How often does Cindera scan?

By default Cindera scans nightly at 03:00 UTC. You can also trigger an on-demand scan from the dashboard at any time, and configure recurring report deliveries on a weekly or monthly cadence from Settings. The nightly scan keeps your posture current; on-demand scans are useful when you want to verify a remediation immediately.

Why does Cindera need admin consent?

The scanner uses application-level Microsoft Graph permissions — not per-user delegated permissions. Application permissions always require tenant-wide admin consent in Microsoft 365; that is how Microsoft separates "a user agreeing for themselves" from "an admin agreeing on behalf of the tenant".

The benefit is that no user is ever interrupted by a Cindera consent prompt during a scan, and the permissions are explicitly reviewable in the Entra admin centre. The trade-off is that initial setup requires a Global Administrator to click through the consent flow once.

Can Cindera make changes to my tenant?

No.The scanner application is configured with read-only Microsoft Graph permissions. There is no remediation permission, no write permission, no role assignment permission. Even if Cindera's servers were compromised, an attacker could not modify your tenant through Cindera's identity.

Cindera tells you what to fix and links you straight to the Microsoft 365 admin centre page where you (or your admin) make the change. You stay in control.

What happens if I disconnect Cindera?

The EntraConnection is marked as consent_revoked, and all scheduled and on-demand scans stop immediately. Your historical scan data, findings, and reports are retained inside Cindera so you can still consult them; they're purged 30 days after disconnect unless you request earlier deletion.

For full revocation, an admin should also remove the Cindera scanner application from Enterprise applications in the Entra admin centre — see the disconnect guide for the exact steps.

How long does a scan take?

Typically 15 to 30 seconds. Larger tenants — 5,000+ accounts or dozens of conditional access policies — can take up to a minute. Cindera uses Microsoft Graph batching and $select projections to keep each call as small as possible.

Why do I see findings about service principals I don't recognise?

Microsoft 365 tenants accumulate identities from three sources:

  • App registrations you created yourself, e.g. for an internal automation.
  • Enterprise applications consented by users — this is where third-party SaaS apps register themselves the first time someone signs in with Microsoft.
  • First-party Microsoft service principals installed by various Microsoft products. Many of these are hidden by default in the admin centre but still appear in Graph.

Cindera shows them all because attackers can hide in any of the three categories. If a service principal looks unfamiliar, its finding includes the app ID and publisher — paste the app ID into Microsoft's first-party app list to identify it.

Can multiple people from my team use Cindera?

Yes. Every user that signs in with a Microsoft 365 work account from your tenant automatically joins your Cindera workspace. All users see the same scan results, findings, tasks, and reports — tenant data is strictly isolated from other organisations.

Role-based access control (admin, analyst, viewer) is on the roadmap and will allow you to restrict what team members can see and do. For now, all workspace members have the same level of access.

What's the difference between Cindera and Microsoft Secure Score?

Microsoft Secure Scoretells you what you could improve in general: enable this feature, configure that policy. It's a strong baseline and we recommend tracking it.

Cindera tells you which specific users, admins, and applications are an active problem today, with named resources and step-by-step remediation. We also map every finding to NIS2 and GDPR controls, which Secure Score does not do, and surface audit-ready PDFs for renewal or audit cycles.

In practice: Secure Score is your generic to-do list; Cindera is the targeted shortlist of the things that matter in your tenant this week.

Does Cindera support other identity providers besides Entra ID?

Today, Cindera is Microsoft 365 / Entra ID only. Google Workspace and Okta support are on the roadmap; the rule engine is designed to be IdP-agnostic but each provider needs its own collector and rule mappings. Email support@cindera.eu if you want to be notified when these go live.

Can my MSP use Cindera for multiple clients?

Today, the model is one Cindera workspace per Entra ID tenant. MSPs that manage multiple tenants currently sign in to each client's Cindera workspace separately. A multi-tenant MSP console — list view across clients, bulk report generation, cross-tenant trend dashboards — is on the roadmap. If you're an MSP and would like to influence that design, get in touch.

How do I export evidence for an auditor?

Download the latest PDF report from the dashboard or from the Reports page. The PDF lists every finding with its mapped NIS2 / GDPR control, severity, status, and the methodology page describing which Microsoft Graph permissions were used. It includes a generation date and a checksum so the document can be referenced unambiguously.

For richer evidence, also download the audit log from Settings— it's a CSV of every action taken inside Cindera during the audit window. The two documents together cover the "measures are tested regularly" requirement of GDPR Article 32 and the NIS2 accountability obligations.

Last updated · 2026-06-05