TenantFabric is the multi-tenant command centre for MSPs - identity, Intune, security, help-desk tooling and automation, across every customer, without logging into a dozen admin centres. In two editions: Business and Education.
Entra, Intune, Exchange, Teams, Purview - multiplied by every school you manage. Context-switching all day, every day.
Which devices are non-compliant? Who's missing MFA? Which tenant's connection is degraded? The answer lives in ten different portals.
Passwords pasted into chats, callers verified on a hunch, and - in schools - staff and students needing different rules entirely. The safe way is the slow way, so it gets skipped.
TenantFabric connects to each customer's Microsoft 365 through the Graph API and gives your engineers one consistent interface for the work that used to mean a dozen logins.
A live MSP dashboard and cross-tenant fleet overview: connection health, users, licences, devices, MFA coverage, Secure Score and open alerts - per customer, at a glance.
Device reporting that tells you which machines need an engineer - compliance, Autopilot health, Windows Hello, update and security-policy coverage, app deployment, all honestly computed.
Secure Score and Defender posture, Conditional Access, risky users, and phishing response built in - with critical events pushed to Teams and raised as SupportPal tickets automatically.
Scheduled automations, bulk jobs, configuration-drift detection against your house baseline, tenant comparison, and a full audit trail of who changed what, where.
The day-to-day of a service desk is where tenants quietly get less secure. TenantFabric builds the secure habit straight into the one-click action - so your engineers never have to choose between doing it right and doing it now.
Reset a password and hand it over as a Password Pusher one-time link instead of plain text. It self-destructs after one view or on a timer, and the password is never written to chat, email or the audit log.
Run a structured identity-verification flow for help-desk callers and issue a Microsoft Entra Temporary Access Pass - a time-boxed, MFA-strength credential - so a caller proves who they are before you touch their account. No more "verifying" on a hunch.
When a user travels outside your UK geolock, grant a time-boxed Conditional Access bypass from their profile in one click - it expires on its own, so the geofence snaps back without anyone remembering to undo it.
Critical events - a new Global Admin, a phishing hit, a degraded tenant - are pushed to Microsoft Teams and opened as SupportPal tickets automatically, so nothing important waits for someone to notice it.
Every one of these is confirmed and audited. Outward-facing and destructive actions ask before they run, record who did what, and are scoped to the customers an engineer is allowed to touch.

The fleet overview ranks every customer by what needs attention - devices, compliance, stale endpoints, Autopilot issues, Windows end-of-life - and drills straight into the tenant that needs you. One PDF is a board-ready estate report.
Same platform, same engine, same honest-by-design reporting. Education simply adds the school-specific layer on top - so a commercial MSP isn't paying for cohorts and MIS it will never use.
The full multi-tenant command centre for MSPs, consultancies and in-house IT running Microsoft 365 for commercial customers.
Everything in Business, plus the layer that understands how a school actually runs.
Everything in Business, plus:
The Education edition adds everything a school needs on top of the core platform: it classifies users into cohorts from your group names, syncs your MIS, and applies the right policy to the right people - automatically.

Connect Arbor, Bromcom or ScholarPack (and SIMS via an aggregator), and TenantFabric pulls staff, students and classes - then shows a dry-run plan of the security groups, email groups and class Teams it would create, before anything is written.
Direct REST sync of staff, students and teaching groups.
Native adapters for the MIS your schools already run.
Reached cleanly through a data aggregator - no fragile workarounds.
Onboard a customer and consent least-privilege Graph access - app-only or GDAP. TenantFabric verifies exactly what was granted.
A background sync caches each tenant's users, devices, licences, policies and groups, so every page loads instantly.
Report across the estate, fix what needs fixing, and run changes with a confirmation - every action audited.
Schedule checks, push critical alerts to Teams and SupportPal, and keep tenants aligned to your baseline.
Reporting reads from a cached snapshot and tells you when data was last refreshed. Where Microsoft Graph can't answer a question, TenantFabric says so - it never invents data to fill a gap. Every change is confirmed, scoped to the customers you're allowed to touch, and written to the audit log.
Book a walkthrough and we'll show you your own estate in TenantFabric - multi-tenant reporting, Intune, security and MIS, in one place.
Get started at tenantfabric.com · hello@tenantfabric.com