Knowledge Base
Help & how-to guides
Everything you need to set up and run CloudCapsule — from connecting your first tenant to reading reports and managing billing.
Getting Started
- Step 1: Running an AssessmentQuickly understand the security posture of any Microsoft 365 tenant and compare results to CIS, NIST CSF, Essential 8 and more — in under 60 seconds.
- Step 2: Share an Executive SummaryGenerate a shareable, business-level PDF summary of any tenant — Microsoft Secure Score, users, email, device health and CIS Controls adoption — in seconds.
- Trials and Free AssessmentsCloudCapsule offers a 14-day free trial with full assessment access for one internal tenant and one client tenant. What is included, what is not, and how to start.
- Understanding Assessment Control Statuses and AnnotationsThe five assessment control statuses (Not Set, Pass, Fail, Assumed Risk, N/A), when to override them, and how to use the comment field to document third-party solutions and accepted risks.
- Microsoft License Requirements for CloudCapsule AssessmentsWhat Microsoft 365 licenses CloudCapsule needs to return a full assessment, what is missing without them, and how to resolve the AADSTS650052 Defender service-principal error.
- RBAC — Managing Team Members and User Access in CloudCapsuleControl which team members can log into CloudCapsule, which tenants they can see, and what they can do. Covers login modes, manual users, groups, and permissions.
Connecting Tenants
- How to Connect a Customer Tenant and Troubleshoot Consent IssuesHow to send a consent link, what the Read Only vs Read & Write options mean, and how to resolve the most common consent errors including AADSTS650052.
- Microsoft App Registration & PermissionsCloudCapsule registers two Microsoft apps: CloudCapsule (read-only assessment) and CloudCapsule-Manage (adds remediation + policy management). Full Microsoft Graph permission list for each, with the purpose of every scope.
- Can I Rebrand the CloudCapsule App in Client Tenants?When CloudCapsule registers its enterprise application in a client tenant, the name, publisher, and branding are controlled by CloudCapsule and cannot be modified by MSP partners. Why, and how to communicate the tool to clients instead.
- Setting up your Microsoft Partner Center connectionLink your CSP relationship to CloudCapsule to import client tenants, then grant consent before assessing them.
- Understanding the Enterprise App consent flowWhat clients see when they grant CloudCapsule access, who can approve it, and what's left in their tenant afterward.
- Revoking tenant access and data deletionHow to remove a tenant from CloudCapsule, revoke its enterprise app in Entra ID, and what gets deleted.
- GDAP and delegated admin relationshipsHow CloudCapsule's tenant access differs from GDAP/DAP relationships, and what to check when you manage both for a client.
Billing
- How Manage Billing WorksHow the Manage add-on, the 250-user allowance, and the $1-per-user overage interact. Includes worked examples and what happens when you toggle Manage on/off for a tenant.
- Premium Features and Upgrading to Analyze + ManageWhat the Analyze + Manage tier unlocks (playbooks, remediation, policy cloning, cross-tenant Explorer), how to upgrade, and how to enable Manage on a per-tenant basis.
- Managing Billing, Invoices, and Your SubscriptionView your current plan and billable user count, download invoices, update payment method or billing contact, and cancel or turn off auto-renewal — all from Admin > Billing and Subscription.
Troubleshooting
- Why Are Some Users Showing as Missing MFA When MFA Is Enabled?CloudCapsule flags a user as MFA unprotected unless an active policy covers them AND a method is registered. Common causes, exclusions, and how to investigate.
- Troubleshooting Report Export and PDF IssuesPDF export issues — formatting errors, missing logos, incomplete data — are almost always an unsupported or outdated browser. CloudCapsule PDF export is built for Chrome.
- Troubleshooting Exchange Errors and Missing Mail Flow DataIf Exchange controls are failing or mail flow data is missing, Microsoft may have left the Exchange Administrator role unassigned during consent. How to verify and manually assign it.
- Email Authentication Checks: DKIM, DMARC, and SPFWhat CloudCapsule checks for DKIM, DMARC and SPF across every domain (including .onmicrosoft.com), why DMARC with p=none fails the check, and how to remediate each one.
- Why BitLocker Encryption Status Differs Between CloudCapsule and Your RMMBitLocker shows as encrypted in your RMM but non-compliant in CloudCapsule: protection suspension, key escrow, cipher mismatch, and CSP failures explain the gap.
- What CloudCapsule Can't See on Microsoft 365 Business StandardMicrosoft 365 Business Standard lacks Defender, Intune, Conditional Access, Entra ID P1, and full DLP — so several CloudCapsule checks fail or return no data. What works, what does not, and the recommended license tiers.