Tenaxis
/Docs
Sign in

Help

Frequently Asked Questions


General

Q: What is Tenaxis and what does it do?

Tenaxis is a governance platform for Microsoft 365 SharePoint sites and Teams. It connects to your Microsoft 365 tenant and gives IT admins:

  • A central dashboard showing all sites, who has access, and how risky they are
  • Tools to control who can create new sites (through a request/approval workflow)
  • Automated cleanup of stale sites (lifecycle management)
  • Periodic access reviews to confirm memberships are still correct
  • Automated removal of access for departed employees (offboarding)
  • Compliance reports and a full audit trail

In short: Tenaxis gives you the oversight and automation that Microsoft 365 alone doesn't provide.


Q: Does Tenaxis replace SharePoint or Microsoft 365 Admin Center?

No. Tenaxis sits on top of your existing Microsoft 365 environment - it doesn't replace it. Think of it as a governance layer:

  • Your users still access SharePoint sites directly through SharePoint
  • Your IT team can still use the Microsoft 365 Admin Center for M365-specific tasks
  • Tenaxis just makes it easier to manage the governance aspects: access control, security policies, lifecycle, compliance

Q: Does Tenaxis store my SharePoint files or content?

No. Tenaxis never stores file content. It only stores metadata about your sites (names, settings, membership lists, sync dates) and actions taken in Tenaxis (the audit log). Your files stay in Microsoft 365.


Q: Is Tenaxis secure? Does it have access to my data?

Tenaxis uses Microsoft OAuth (the same secure login used by Microsoft 365 itself) and communicates with your M365 tenant via the Microsoft Graph API using your organization's credentials. Tenaxis admins only have access to governance metadata - not file content.

All connections between Tenaxis and Microsoft Graph are secured with HTTPS. JWT session tokens are used for authentication within Tenaxis.


Q: Which Microsoft 365 licenses do I need?

Tenaxis works with standard Microsoft 365 Business and Enterprise licenses. No special SharePoint Premium or additional licenses are required for most features. File Search uses the Microsoft 365 Search API, which may require certain M365 licenses depending on your tenant configuration - check with your Microsoft partner if unsure.


Sites

Q: Why doesn't a SharePoint site appear in Tenaxis?

Sites only appear in Tenaxis if they have been:

  1. Provisioned through Tenaxis - created via the request/approval workflow or direct admin provisioning, OR
  2. Imported into Tenaxis - manually imported from your existing M365 groups via Sites → Import

Tenaxis doesn't automatically discover all sites in your tenant on connection. You need to explicitly import existing sites.


Q: A site shows as PROVISIONING but it's been 15 minutes. What's wrong?

SharePoint provisioning usually takes 1–5 minutes but can occasionally take longer in M365. Check:

  1. The Audit Log for the provisioning entry - did it show an error?
  2. The Microsoft 365 Admin Center - is there a service health issue affecting SharePoint?

If it's still in PROVISIONING status after 30 minutes and the audit log shows no error, contact your Tenaxis admin or support.


Q: I deleted a site in Tenaxis but it still exists in SharePoint. Is that normal?

Yes. Deleting (archiving) in Tenaxis is a soft-delete - it removes the site from Tenaxis's active management but does not delete the underlying SharePoint site in Microsoft 365.

To permanently delete the SharePoint site, you need to do so through the SharePoint Admin Center or Microsoft 365 Admin Center. This is intentional - it prevents accidental permanent data loss.


Q: Can I rename a site after it's created?

You can update the site's display name (the friendly title shown in Tenaxis) from the site detail view → Edit. However, the mail nickname (which forms the site URL) cannot be changed after creation - this is a Microsoft 365 limitation, not a Tenaxis limitation.


Q: What is a "risk score" and how is it calculated?

The risk score is a number from 0 to 100 that represents how much security concern a site warrants. Higher scores mean more attention is needed.

Risk factors that increase the score:

  • External/guest users are members of the site
  • The site allows anonymous or broad sharing (no sharing restrictions)
  • No security policy has been applied
  • Lifecycle management isn't tracking the site
  • Disabled (departed) users are still members

Reduce the risk score by: applying a security policy, removing external users who don't need access, removing disabled accounts, and ensuring lifecycle management is active.


Security Policies

Q: What happens when I apply a policy to a site?

Tenaxis uses the Microsoft Graph API to update the site's actual SharePoint settings. This means:

  • Sharing settings are changed in SharePoint itself
  • The changes take effect within seconds
  • Anyone who tries to share a file against the new policy will find they can't

The change is logged in the Tenaxis Audit Log.


Q: Can someone override a policy by changing settings directly in SharePoint?

Yes - if someone with SharePoint Admin rights changes the settings directly in the SharePoint Admin Center, it will override what Tenaxis set. Tenaxis doesn't prevent this.

However, the next time a Tenaxis admin applies the policy (or syncs the site), Tenaxis will restore the correct settings. You can also detect drift by checking the "Last Verified" date on a site - if it doesn't match the expected policy, a re-apply is needed.


Q: Can I apply different policies to different sites?

Yes. Each site has its own security policy assignment. You can have some sites on "Strict - HR/Legal" and others on "Project Team" - whatever fits each site's purpose.


Access Reviews

Q: A site owner says they didn't receive the access review email. What should I do?

  1. Check the owner's email address in Tenaxis - is it correct?
  2. Ask them to check their Spam/Junk folder
  3. Trigger a new review manually from the Access Reviews page to resend the email

Q: Can the admin complete an access review on behalf of a site owner?

Currently, only the site owner can submit the review through the unique review link. If an owner is unavailable (on leave, departed), you can:

  1. Cancel the current review
  2. Assign a new owner to the site
  3. Trigger a new review - the new owner will receive the link

Q: What happens if a site has multiple owners? Who gets the review email?

All site owners receive the access review email. Any one of them can complete the review. The first owner to submit their decisions completes the review for everyone.


Q: Can I see what decisions an owner made during a review?

Yes. The full review record - including each KEEP/REMOVE decision and the timestamp - is stored in the Access Reviews detail view and in the Audit Log.


Offboarding

Q: Why won't Tenaxis remove a disabled user automatically?

The most common reason is that the user is the sole owner of one or more sites. Tenaxis won't auto-remove the only owner of a site because that would leave the site with no one responsible for it (an "orphaned" site). You need to assign a new owner first, then remove the disabled user.


Q: Does Tenaxis disable Microsoft accounts? Or just remove site access?

Tenaxis only removes site memberships - it does not disable Microsoft 365 accounts. Account management (disabling, deleting) is done in Microsoft Entra ID (Azure Active Directory), not in Tenaxis.


Q: How quickly does Tenaxis detect a disabled account?

Tenaxis runs a nightly sync that checks account status. If someone's account is disabled today, it will typically appear in the Offboarding page within 24 hours. You can also use the Re-check button on a specific user to get an immediate status update.


Lifecycle Management

Q: The site owner is on vacation and didn't click the renewal link in time. What do I do?

The site will escalate to ESCALATED status. You (as admin) can either:

  1. Wait for them to return and manually reset the site status
  2. Click the renewal link they received (if you have access to their email - use caution)
  3. Manually reset the lifecycle status in Tenaxis

Q: Can I exempt certain sites from lifecycle management?

Currently, lifecycle management applies globally to all sites. There's no per-site exemption. Sites with regular activity (e.g., a company intranet) will automatically reset their lifecycle status based on activity, so they'll never be escalated.


Requests

Q: Can I edit a request after submitting it?

No - once a request is submitted, it can't be edited by the requester. If you submitted incorrect information, ask your IT admin to reject the request, and then submit a new one with the correct details.


Q: How long does it take for a site request to be approved?

This depends entirely on your organization's IT team and their processes. Tenaxis sends a notification to admins when a request is submitted, but there's no automatic approval. Contact your IT team if a request has been pending for more than your expected response time.


Webhooks

Q: Are webhooks included on all plans?

Yes - webhooks are available on all paid plans (Starter, Pro, Enterprise).


Q: My webhook deliveries are failing. Where do I start troubleshooting?

  1. Check the Delivery Log in Settings → Webhooks → [Webhook name] → Delivery Log
  2. Look at the status code - 200 means success; 4xx or 5xx means something's wrong
  3. 403 / 401 - Your endpoint is rejecting the request (authentication issue)
  4. 500 - Your endpoint has an internal error; check logs on the receiving system
  5. No deliveries at all - Check the webhook is marked Active and the events are selected

Billing

Q: Do I need a credit card to start a trial?

No. The 14-day trial starts without any payment information required.


Q: What happens when my trial ends?

You won't be charged automatically. The trial simply ends, and you'll see a prompt to subscribe. Until you subscribe, you can view your existing data but cannot provision new sites or use governance features.


Q: Can I downgrade from Pro to Starter?

Yes - contact support or manage your subscription through the Stripe billing portal. Downgrades take effect at the end of your current billing period.


Q: My organization needs invoicing instead of credit card payments. Is that possible?

Invoice billing is available on the Enterprise plan. Contact the Tenaxis sales team for details.