SectionOnboarding

Cindera · Onboarding

Onboarding

Two routes lead into Cindera: a company connecting its own Microsoft 365 tenant, and a managed service provider connecting tenants on behalf of clients. The accounts involved are different in each, which is where most of the confusion starts.

Which route applies to you

Direct
You are connecting your own company's Microsoft 365 tenant. You sign in, grant consent once, and you are done. Start at 'Signing in for the first time'.
MSP
You manage Microsoft 365 for other organisations and want them all in one console. Your own tenant becomes the account you sign in with; your clients' tenants are attached to it. Start at 'Setting up an MSP account'.

Signing in for the first time

Cindera has no passwords and no separate registration. You sign in with a Microsoft 365 work account from your own tenant, and the account is created on the spot.

  • You do not need to be an administrator to sign in. Signing in asks only for your name, email and profile. Administrator rights are needed later, at the consent step, and only once.
  • Personal accounts do not work. An outlook.com or hotmail.com account cannot be used. Cindera reads a company directory, so it needs the work account that belongs to it.
  • The first person to sign in becomes the administrator of the workspace. Everyone from the same tenant who signs in afterwards joins automatically as a viewer. If a specific person should hold the admin role, have them go first.

A 14-day trial starts here. It is measured per Microsoft tenant, so signing in with a second email address from the same company does not start a new one.

The four onboarding steps

After the first sign-in you land in a short guided flow instead of the dashboard. Cindera keeps returning you to the furthest step you have reached until it is finished.

1. Welcome

A one-screen summary of what Cindera is about to read and what it will never touch. Nothing is requested from Microsoft yet.

2. Connect

This is the only step that needs elevated rights. You are sent to Microsoft to grant admin consent for the Cindera scanner application, which must be done by a Global Administrator or a Privileged Role Administrator of the tenant being connected. Consent covers seven read-only Microsoft Graph permissions and is granted once for the whole tenant, not per user.

If you are not an administrator yourself

Ask your Global Administrator to sign in and complete this step. Once consent is granted, everything afterwards works with ordinary accounts. See what Cindera reads if they want the permission list before approving.

3. Scan

The first scan runs immediately and typically finishes in 15 to 30 seconds. You can watch it or close the tab; it keeps running either way.

4. Review

Your compliance score and the findings behind it. Finishing this step hands you the normal dashboard, and the guided flow does not come back.

Setting up an MSP account

An MSP account is an ordinary account with the fleet view switched on. The order matters, because the organisation does not exist until someone has signed in.

  1. Sign in once with your own company account.Use a work account from the MSP's own Microsoft 365 tenant, not a client's. This account is the one you will keep using, and the tenant behind it becomes your organisation's home tenant.
  2. Ask us to enable MSP mode. Email support@cindera.eu with the domain you signed in with. There is no self-service switch for this yet.
  3. Sign out and back in. Your account type is fixed at sign-in, so the fleet view and the tenant switcher only appear on a fresh session. If nothing looks different, this is almost always the reason.
  4. Connect your clients. Covered in the next section.

Billing works differently for MSPs

MSP plans are billed by agreement rather than through the self-service checkout, so the subscription screen offers a contact route instead of a card form.

Connecting a client tenant

From Connect clients in the fleet menu you paste your client list, one per line, each as a verified domain or a Microsoft tenant ID, with an optional client name on the same line. Nothing is sent to Microsoft at this point; you are only building the queue.

Then you work through the list one row at a time. Each row produces a Microsoft consent link that is valid for 15 minutes and can be used once. You can either complete it yourself if you hold administrator credentials in the client tenant, or send it to the client's own Global Administrator. The link is tied to that one tenant, so it cannot connect anything else even if it is forwarded.

Whoever completes it signs in at Microsoft, approves the same read-only permissions, and lands on a short confirmation page. The tenant then appears in your fleet with its own 14-day trial, ready to scan.

One consent per client, always

Microsoft has no mechanism for approving an application across many tenants at once. Every client tenant needs its own admin consent, granted by an administrator of that tenant. The queue exists to keep thirty of those organised, not to reduce them to one.

What your clients can and cannot do

Connecting a client tenant grants Cindera read-only access to that directory. It does not create accounts for anyone who works there.

  • Client staff cannot sign in to Cindera. Someone from a managed tenant who tries is told the tenant is looked after by their IT provider, and no account is created. Findings for that tenant are yours to interpret and share.
  • The administrator who grants consent gets no account either. Approving the connection and having a login are separate things.
  • Your own colleagues do get accounts.Anyone signing in from the MSP's own tenant joins your organisation and sees the whole fleet, as a viewer unless you raise their role.
  • Reports are how clients see their own data. Send a PDF, or schedule recurring delivery straight to them. With white-label branding enabled, those carry your name rather than ours.

Things that trip people up

The fleet view has not appeared
Sign out and back in. Account type is read at sign-in, so an existing session still behaves as it did before MSP mode was enabled.
Consent was granted, but for the wrong tenant
The person completing the link was signed in to another organisation at Microsoft. Nothing is connected in that case. Have them sign out of Microsoft first, then open the link again.
The consent link no longer works
Links last 15 minutes and are single-use. Generate a new one from the row; there is no limit on retries.
A client is already managed elsewhere
A Microsoft tenant can belong to one Cindera organisation at a time. If a client already connected Cindera themselves, they need to disconnect before you can attach them.
Sessions end sooner than expected
Cindera signs you out after 8 hours, and after 1 hour of inactivity. That is deliberate for a security console, and it applies to everyone.

Last updated · 2026-08-23