Microsoft 365 Expiry Warnings

Stop the 2 a.m. outage nobody was watching for.

A client secret runs out, an Apple push certificate lapses, a DNS record is overwritten, and an integration, device enrollment or your mail stops in the middle of the night. GlacierPoint Remind lists everything in your Microsoft 365 tenant that can expire or break, names the owner of each item, and warns by mail a month, two weeks, a week and a day before it does.

You need a Windows computer and a Microsoft 365 administrator account. Details below.

Names and dates, never a secret’s value We hold no credential for your tenant Renewals stay yours: nothing is rotated for you
The first page after a run

One card says what is about to break.

How many items expire in the next 30 days, how many already expired, and the three nearest by name. Under it, one section per kind of item: where each one lives, its owner, its end date, the days left, what stops when it ends and what to do.

See a sample report

After a run

Example

4 items expire in the next 30 days, 1 already expired.

  • Payroll export, client secretApp registration · owner Dana RuizExpired 2 days ago
  • Apple MDM push certificateIntune · owner not assigned7 days left
  • Salesforce SAML signing certificateEnterprise application · owner IT Operations19 days left

Every row says what stops when it expires and what to do about it. contoso.com, an example tenant.

What you need

  • A Windows computerWindows 10 or Windows 11, 64-bit, for the app. It is a single program, with nothing else to install.Get the app
  • A Microsoft 365 administrator accountA run asks for read permissions only. An administrator who can consent for your organization grants them once.Every permission, by name
  • Exchange Online PowerShell, if you want DKIMFor the DKIM rotation state of your domains. Without it that one read is left out, and the report says so.The domain checks
  • A computer that is on, for scheduled runsWatch and MSP run every day as a Windows task on a computer of yours. A run missed while it was off starts at the next sign-in.Scheduled runs
What it tracks

Eight things that expire or break without a warning from Microsoft.

Each section of the report says, in one sentence, why it is checked, so that a record that never expires is never a surprise on an expiry report.

App registration secrets and certificates

A secret or certificate has an end date. When it passes, every integration that signs in with it stops, usually without a warning from Microsoft.

When it breaks: sign-ins and API calls through the application stop.

Enterprise application credentials

Single sign-on to a third-party application relies on a signing certificate with an end date. When it passes, staff can no longer sign in to that application.

When it breaks: SAML sign-in to the application stops.

Applications without an owner

Microsoft warns the owners of an application before its credentials expire. An application with no owner warns nobody.

When it breaks: nobody is warned before its credentials expire.

Unused applications

An application nobody has used in a long time still holds working credentials. If one leaks, nobody notices. Confirm it is still needed or remove it.

When it breaks: a credential nobody uses stays an open door.

Domains and mail records

DNS records do not expire, but they break. A domain move, a new mail service or a rebuilt website can delete or overwrite them, and nobody notices until mail bounces or lands in spam. Remind reads the MX, SPF, DKIM and DMARC records as the Internet sees them and compares them with what Microsoft 365 expects, so a change shows here before it shows as lost mail.

When it breaks: mail from the domain bounces or lands in spam.

Intune certificates and tokens

Apple and Google require a certificate or token that Microsoft cannot renew for you. When one expires, phones and laptops stop enrolling and can fall out of management.

When it breaks: device enrollment and management stop.

Entra Connect and cloud sync

Directory synchronization copies on-premises accounts and password changes to Microsoft 365. When it stalls, new staff cannot sign in and password changes do not take effect in the cloud.

When it breaks: password changes and new users stop reaching the cloud.

Conditional Access references

A sign-in policy that still names a deleted user, group or application no longer applies to what it was meant for. Microsoft does not flag this.

When it breaks: the policy no longer applies to what it was meant for.

How it works

Sign in, connect, run, report.

A Windows app does the reading with your own sign-in. The portal keeps the runs and shows them to your team.

  1. Sign in

    Create your workspace with your work email: a six-digit code, no password. The free Preview starts at once.

  2. Connect

    Download the Windows app from the portal and start it. It shows a code, and an owner or operator of your workspace approves it.

  3. Run

    Sign in to Microsoft with your administrator account. The app reads the eight sections, looks up your domains’ mail records, and sends the result to the portal sealed.

  4. Report

    What expires in the next 30 days and what already expired, the three nearest named, then every item with its owner, the days left and what to do. As a page, a PDF and a CSV.

The warning mail

A mail before every expiry, to the person who can renew it.

With Watch and MSP, the app runs every day on a computer of yours, and the portal mails 30, 14 and 7 days and 1 day before each end date and on the day.

  • To your team’s warning addresses, and to the owner you assign to an item, for that owner’s items
  • Mark an item handled, with the date the renewal should show, and its warnings pause until then
  • Ignore an item with the reason, and its warnings stop; the reason shows on the report for your auditor

Warning mail

Example
From
GlacierPoint Remind
Subject
Contoso: 2 items expire soon

These items of Contoso expire soon or expire today:

  • Apple MDM push certificateexpires on October 18, 2026in 7 days
  • Payroll export (Payroll API)expires on November 10, 2026in 30 days

Mark an item handled once it is renewed, or ignored with the reason, and its warnings stop.

Security

Names and dates of credentials. Never the credentials.

A list of every secret in your tenant would be a fine target, so Remind keeps no secret at all: only what each item is, where it lives, who owns it and when it ends.

How your data is protected

  • Read-only. Every check is a read. Microsoft never returns a secret’s value and the app never asks for one; it holds no private key and never renews, rotates or deletes anything.
  • No vendor access. We hold no password, token, secret or certificate for any tenant. The app on your computer does the work, signed in as you.
  • One write, named in advance. Scheduled runs need an app registration of your own in your directory, with read permissions only. You review every line before it is written, and you can remove it at any time. Nothing else is ever written to your tenant.
  • Encrypted before it leaves your computer, and at rest. Each run is sealed on your computer before upload and stored encrypted by the portal.
With the other GlacierPoint products

Assess, capture, change, verify. Then keep watching.

GlacierPoint Scan finds configuration weaknesses and sets priorities; GlacierPoint Snapshot preserves configuration history and recovers supported settings. Together: assess, capture the current configuration, make the approved changes, verify. GlacierPoint Remind keeps watch over what the tenant depends on and expires: secrets, certificates, tokens and records.

About GlacierPoint

GlacierPoint Technologies builds tools that keep Microsoft 365 and Windows environments known, safe and recoverable.

We started from a simple observation: most organizations don't know where their directory and tenant stand until something goes wrong, and the tools that could tell them are written for specialists. Our products put a clear answer in front of the people who have to act on it — a brief a leadership team can read, evidence an administrator can verify, and changes you approve one at a time.

Clarity

Plain-language reports and prices on the page. The same evidence sits behind every number.

Control

You authorize every collection and every change. Nothing runs in your environment without your sign-in, and every change our tools make records a way back.

Security first

Evidence is encrypted on your computer before it leaves. We never train AI on customer data, and support sees your data only when you grant it, for as long as you choose.

Pricing

Priced per tenant. Start free with the Preview.

Paid plans differ by how long they run, whether the app runs on a schedule and sends warnings, and how many tenants you look after. Never by what is checked.

One-time $49 per tenant for 30 days; Watch $9 per month, $108 a year billed in advance; MSP $79 a month plus $7 a month per tenant. See the plans

Every workspace starts as the free Preview. Compare the plans in full, with the MSP plan’s monthly totals worked out.

See what expires in your own tenant today.

The free Preview runs up to 3 times on one tenant: the headline, every section with its counts, and the three nearest items of each. Decide with your own dates in front of you.