Read permissions only
A run asks Microsoft for read permissions and nothing else. The consent card in the app shows which were granted, and a missing optional one leaves its section out, said so on the report.
GlacierPoint Remind knows what each item is, where it lives, who owns it and when it ends. It never holds a secret’s value or a private key, it holds no access to your tenant, and the work is done by an app on your computer, signed in as you.
Only people in your organization, with their own sign-in, and, for scheduled runs, an app registration your organization owns.
A run asks Microsoft for read permissions and nothing else. The consent card in the app shows which were granted, and a missing optional one leaves its section out, said so on the report.
We hold no password, token, client secret or certificate for any tenant, and there is no support account or back door. Nobody at GlacierPoint can read or change your tenant.
You sign in to Microsoft in your browser. The sign-in is used by the app on your computer and never sent to the portal; a scheduled run asks for a fresh token every time and keeps none.
Scheduled runs need an app registration of your own, “GlacierPoint Remind scheduled run”. The setup shows you every object before it is created, writes only to your directory, removes its own write permissions when it is done, and keeps a journal on your computer. Remove takes it all away.
A Windows task on a computer you choose, with a certificate made there whose private key Windows keeps and will not export. The schedule never lives at the portal, so the portal never holds a key to your tenant.
What the app reads is fixed in the app. The portal receives runs; it cannot make the app read something else or run anything.
What a run carries: names, dates, owners and states. What the portal does with it: the report and the warnings.
Asked at sign-in, as delegated permissions; a scheduled run has the same seven as application permissions, and nothing that writes.
| Permission | What it reads |
|---|---|
Application.Read.All | The secrets and certificates of app registrations and enterprise applications, by name and end date, and their owners |
Directory.Read.All | Owners’ names and the state of directory synchronization |
Domain.Read.All | Your domains, their verification and federation state |
AuditLog.Read.All | The last sign-in of each application, for the unused applications (optional) |
DeviceManagementConfiguration.Read.All | The Apple push certificate and the Apple tokens of Intune (optional) |
DeviceManagementServiceConfig.Read.All | Managed Google Play and the certificate connectors of Intune (optional) |
Policy.Read.All | Conditional Access policies and the objects they name (optional) |
| Exchange Online, read | The DKIM signing configuration of your domains, in runs a person starts (optional) |
The setup of scheduled runs signs in once with Application.ReadWrite.All, AppRoleAssignment.ReadWrite.All and DelegatedPermissionGrant.ReadWrite.All to create your app registration and grant its read permissions, then takes these three back out of the consent at the end of every setup, renewal and removal.
If we do not hold it, it cannot leak from us.
No trackers, no analytics, no advertising, no third-party scripts or fonts.
Every page, this one included, may run only scripts and styles served by the portal itself, and cannot be framed by another site.
A sign-in to the portal lasts twelve hours at most, with a code sent to your address and no password. Roles decide who may connect apps, change settings and invite people: owner, operator or viewer.
Found a security problem? Write to security@glacierpointtech.com; how to report a vulnerability says what to send and what to expect.