How it works

Sign in, connect, run, report. Then a warning before every end date.

The Windows app reads your tenant with your own sign-in, and the portal turns each run into a report your team can act on. Here is every step, and what runs where.

The four steps

From sign-up to the first report.

The first run takes a few minutes. Every later run is the same, by hand or on a schedule.

  1. Sign in

    Create your workspace on the sign-up page with your work email and the name of your organization. We email a six-digit code; there is no password to keep.

  2. Connect

    Download the app from the portal and start it on a Windows computer. It shows a one-time code; an owner or operator approves it in the portal, and the app is connected to your workspace.

  3. Run

    Sign in to Microsoft in your browser. The consent card shows which read permissions were granted. The app reads, then seals the result on your computer and uploads it.

  4. Report

    The report opens in the portal: the headline card, then one section per kind of item. Owners, handling and notes are added there, and the PDF and CSV export carry them.

The eight sections

What is read, why, and what to do.

The same sentences appear under each section of the report, in the PDF and in the CSV.

App registration secrets and certificates

A secret or certificate has an end date. When it passes, every integration that signs in with it stops, usually without a warning from Microsoft.

What to do: Add a new secret or certificate in the app registration (Microsoft Entra admin center, App registrations, Certificates & secrets), update the integration that uses it, then remove the old one. Remind shows the new date on the next run.

When it breaks: sign-ins and API calls through the application stop.

Enterprise application credentials

Single sign-on to a third-party application relies on a signing certificate with an end date. When it passes, staff can no longer sign in to that application.

What to do: Renew the certificate in the enterprise application’s single sign-on settings (Microsoft Entra admin center, Enterprise applications) and upload the new one on the application’s side before the old one ends.

When it breaks: SAML sign-in to the application stops.

Applications without an owner

Microsoft warns the owners of an application before its credentials expire. An application with no owner warns nobody.

What to do: Assign an owner in the Microsoft Entra admin center (the application’s Owners page), or assign one here so that Remind knows whom to warn.

When it breaks: nobody is warned before its credentials expire.

Unused applications

An application nobody has used in a long time still holds working credentials. If one leaks, nobody notices. Confirm it is still needed or remove it.

What to do: Confirm with the application’s owner that it is no longer used, then remove its credentials or the application itself. A credential nobody uses is an exposure, not only an outage risk.

When it breaks: a credential nobody uses stays an open door.

Domains and mail records

DNS records do not expire, but they break. A domain move, a new mail service or a rebuilt website can delete or overwrite them, and nobody notices until mail bounces or lands in spam. Remind reads the MX, SPF, DKIM and DMARC records as the Internet sees them and compares them with what Microsoft 365 expects, so a change shows here before it shows as lost mail.

What to do: Update the record at the registrar or DNS host to what Microsoft publishes (Microsoft 365 admin center, Settings, Domains), and rotate DKIM in the Microsoft Defender portal under Email authentication settings. Changes show after DNS has propagated.

When it breaks: mail from the domain bounces or lands in spam.

Intune certificates and tokens

Apple and Google require a certificate or token that Microsoft cannot renew for you. When one expires, phones and laptops stop enrolling and can fall out of management.

What to do: Renew in the Microsoft Intune admin center under Tenant administration, Connectors and tokens, with the same Apple ID or Google account that created the token. A renewal with a different account unenrolls devices.

When it breaks: device enrollment and management stop.

Entra Connect and cloud sync

Directory synchronization copies on-premises accounts and password changes to Microsoft 365. When it stalls, new staff cannot sign in and password changes do not take effect in the cloud.

What to do: Check the Entra Connect or cloud sync server: the service is running, the connector account can sign in, and the last synchronization completed. The Entra admin center, Entra Connect, Connect Sync, shows the errors.

When it breaks: password changes and new users stop reaching the cloud.

Conditional Access references

A sign-in policy that still names a deleted user, group or application no longer applies to what it was meant for. Microsoft does not flag this.

What to do: Edit the policy in the Microsoft Entra admin center (Protection, Conditional Access) and remove or replace the deleted user, group, application or location it still names.

When it breaks: the policy no longer applies to what it was meant for.

The domain checks: DNS from your computer

Mail records live outside your tenant, so the app looks them up as the Internet sees them: for every verified domain that sends mail, the MX records, the SPF record, the DMARC record and the two DKIM selectors. It asks public resolvers (Cloudflare, then Google, then Quad9) and falls back to your computer’s own resolver when none answers; a setting of the app prefers your internal resolver instead. The report names the resolver that answered.

The portal receives the records as text, never the DNS traffic itself. The DKIM rotation state comes from Exchange Online in a run a person starts.

Scheduled runs and warning mails (Watch and MSP)

The point is the warning, so a paid tenant runs every day without anyone at the keyboard. The schedule lives on a computer of yours, never at the portal:

  • The setup in the app signs in as a Global Administrator, reads what exists, shows you the plan and writes nothing until you confirm it.
  • It creates an app registration of your own, “GlacierPoint Remind scheduled run”, with the seven read permissions of a run, and adds the public part of a certificate made on that computer. The private key stays in Windows on that computer and cannot be exported. This is the one write the product ever makes, to your directory; nothing in your tenant’s data is written.
  • A Windows task runs the app daily at 06:00 by default, or at the hour or on the weekday you choose, while the account that set it up is signed in. A run missed while the computer was off starts at the next sign-in.
  • The certificate is valid for one year. The portal watches its end date like any other item, and mails before it ends.
  • Remove takes away the permissions, the app registration, the certificate and the task again.

After each run the portal mails 30, 14 and 7 days and 1 day before each end date and on the day: to the tenant’s warning addresses (the workspace’s owners when none are set) and to the owner you assign to an item. Each step is sent once per item; a new end date starts again.

Without an always-on computer you keep the runs you start by hand, and the portal reminds you when the newest run is 14 days old.

What runs where

Your computer reads. The portal reports.

On your computer: the app

Signs in to Microsoft as you, reads, looks up the DNS records, seals the result and uploads it. For scheduled runs it holds the certificate and the Windows task. It never asks the portal what to read.

In the portal

Opens the sealed run, works out the days left, the state and the impact of every item, keeps the history your plan includes, and sends the warning mails. It holds no credential for your tenant.

See what expires in your own tenant today.

The free Preview runs up to 3 times on one tenant: the headline, every section with its counts, and the three nearest items of each. Decide with your own dates in front of you.