Documentation

Everything CloudSergeant does, what each feature needs to work, and what it deliberately does not do.

What CloudSergeant is

A single Windows desktop application that signs you in with your own Microsoft 365 work or school account and administers Microsoft 365 through delegated Microsoft Graph, Exchange Online and SharePoint. It covers the directory objects you edit day to day — users, groups, devices, mail contacts, licence subscriptions and admin roles — plus mailbox and OneDrive configuration, with tools for restricted-sender remediation, quarantine management, cleanup, copy/move, and export/import of mail and OneDrive files.

It acts as you. There is no service account, no application permission and no background process with standing access. If your account cannot do something, neither can CloudSergeant.

Requirements

Windows, 64-bit
The app is Windows-only. There is no macOS or Linux build, and none is planned.
No .NET installation
The download is self-contained — the runtime is inside the executable.
A Microsoft 365 work or school account
Personal Microsoft accounts are not supported. What you can do once signed in depends on your Entra and Exchange roles — see the capability matrix.
An app registration with admin consent
One multitenant app registration serves all users, but its delegated permissions must be admin-consented in your tenant before anything will load. See Sign-in & permissions.

Install and first run

  1. Download CloudSergeantSetup.exe from the Download page.
  2. Run it. By default it installs for you alone, under %LocalAppData%\Programs\CloudSergeant, and asks for no administrator rights. You get a Start menu entry, a desktop shortcut and an entry in Apps and Features. Clear the desktop shortcut tick if you would rather not have one — updates will not put it back. On a shared machine you can choose an install for all users instead, which does need administrator rights and puts the app in Program Files.
  3. Click Sign in and complete the normal Microsoft sign-in, including MFA.
  4. The first sign-in asks for consent to the permissions the app needs. A Global Administrator can grant it for the whole organisation.

Updates

CloudSergeant asks the licence service whether a newer version has been published — that check sends only the version you are running. When one has been, a band appears at the top of the window. Choosing Update now downloads the installer, checks it against the SHA-256 the service published and against the signature of the copy you are already running, then closes CloudSergeant, installs the new version and reopens it. Nothing is downloaded or installed until you accept, and a download that fails either check is deleted without being run.

Your sign-in, licence and activity log are untouched by an update: they live in %LocalAppData%\CloudSergeant, separately from the application itself, so you are not asked to sign in again. Occasionally an update is marked as required, and then CloudSergeant will not continue until it is installed. If you are running a copy that was not put there by the installer, the band links to the Download page instead.

Beta builds are unsigned

During the controlled Beta, the download is a build that is clearly identified as unsigned. Windows will show an unknown publisher warning, and SmartScreen may ask you to confirm. This is expected for the Beta; production builds are signed. Only accept that warning for a build you obtained from cloudsergeant.com.

It never updates without being asked

CloudSergeant can install a new version for you, but only after you choose Update now — nothing is downloaded or installed in the background, and no update is ever applied silently. If a version is marked as required, the app stops working until it is installed; that is the one case where the notice cannot be dismissed.

How the app is laid out

A navigation pane on the left, grouped by the Microsoft 365 workload each page works on. Each group holds that workload's object lists first and its tools after them. Every object list is searchable, and its rows open an editable card.

  • Entra: the directory. Users, Groups, Devices and Contacts, then two tools that work across the whole directory. Search finds any object in the tenant. Compare shows two users or two groups side by side and highlights what differs.
  • Exchange: the Mailboxes list, then searchable Restricted senders and Quarantine lists with single and bulk actions, plus Cleanup, Copy / Move and Export / Import wizards whose runs detach into their own window. See Mailbox tools.
  • OneDrive: the OneDrives list, then Cleanup, Copy / Move and Export / Import for files and folders, with ZIP archives and an optional separate sign-in for another tenant. Runs use the same detached job-window model. See OneDrive tools.
  • Tenant: the tenant as a whole rather than one object in it. The Organization profile, verified Domains, the Licenses the tenant holds and who holds them, the Roles catalogue, and Your access, the admin roles you personally hold here.
  • Partner — visible with a Partner licence: a searchable version of the tenant switcher (Tenants (GDAP)) and the full lifecycle of your GDAP relationships (Relationships (GDAP)) — see Delegated administration.
  • Settings, at the foot of the pane below the groups above — a few preferences (theme, and how it behaves), your CloudSergeant subscription, the activity log folder, and version information.

At the very bottom sit the tenant picker (with a Partner licence — see Delegated administration) and the account menu, which holds Switch account, Grant permissions again, Clear cached tokens and Sign out.

Every list works the same way

Each list has one search box plus a few dropdown filters, and its status line reports the count — 4 of 1,284 user(s). when a filter narrows it. Lists load the whole tenant, not a first page, and are read once per tenant with an explicit Refresh button. Searching matches more than the visible columns: a user is findable by their username as well as their mail address, a group by its alias, and any mailbox or contact by every secondary SMTP address it carries.

The activity log

One plain-text file per day under %LocalAppData%\CloudSergeant\logs, holding sign-ins, every change made to the tenant, every tool run, and the full technical detail of every error. Files older than 90 days are deleted. Open the folder from Settings ▸ Activity log.

What it deliberately does not contain is mail content. A change is recorded by the names of the fields that changed, not their values, and a tool run is recorded as a start line and an end line with counts — never a line per message, because a message line would carry its subject. The exceptions are narrow and chosen: the identity of a mailbox being changed and of a principal being granted access are recorded, since otherwise "who was given access to whose mailbox" would be unanswerable.

Two things it never records: a password (only that one was reset), and the value of a BitLocker recovery key (only that one was revealed — which is the single most privileged thing the app does, so it is the one read that gets a log line at all).

What the app keeps on your machine

Everything CloudSergeant itself writes lives under %LocalAppData%\CloudSergeant\:

FileWhat it is
msal.cacheThe encrypted Microsoft token cache. This is what makes relaunch silent.
device.idAn opaque installation GUID. It contains no user, machine or organisation data.
entitlement-*.binLicence state, encrypted with Windows DPAPI for your user account.
window.jsonWindow position and size.
logs\The daily activity log described above.
updates\A downloaded installer waiting to run, and the log the installer writes. Deleted on the next launch and when you uninstall.

None of it is configurable, and there is no settings file to edit. Configuration is embedded in the executable, so a file placed next to the .exe is never read.

Three things sit outside that folder, and all three belong to Windows or to the installer rather than to the running app: the application itself (%LocalAppData%\Programs\CloudSergeant, or Program Files for an all-users install), one registry value under Software\CloudSergeant recording where it was installed, plus the entry in Apps and Features; and a folder of native libraries that .NET unpacks under %TEMP% the first time a given build runs. Uninstalling removes the application, the registry value and updates\, and deliberately leaves your sign-in, licence state and activity log in place.

Limits worth knowing up front

You are responsible for the changes you direct

CloudSergeant makes these changes only because you chose to run them, using your own signed-in permissions. Several of them below cannot be undone once run — read the recoverability of an action before you run it, and see Terms — Limitation of liability.

  • The mailbox tools handle email only. Calendar items, contacts, tasks and notes are never read, moved or deleted.
  • Folder sizes are not shown in the folder tree. Microsoft Graph does not expose a folder size, so rather than guess, the app sums the size of the messages that actually matched your filters and reports that instead.
  • Permanent delete cannot be undone from Outlook. Only administrator recovery through eDiscovery can reach those messages, subject to your retention policy.
  • Mailbox content tools are unavailable in a delegated customer tenant. A separate sign-in as a customer-tenant mailbox user is the session-only way through. The reason is here.
  • A GDAP partner token cannot open OneDrive files. OneDrive file tools use a separate customer-tenant sign-in there; emptying a recycle bin remains home-tenant only.
  • Objects synchronised from on-premises AD cannot be edited or deleted in the cloud. The app locks those fields and says so, rather than letting a write fail or be silently reverted by the next sync.
  • No .pst. Export and import use .zip; a .pst is neither written nor read.

All topics

Sign-in & permissions The delegated model, the baseline permissions the app requests, per-tenant consent, and what to check when something returns 403. Users The user card, the create wizard, the guided offboarding flow and the 30-day recycle bin. Groups All four group types, assigned versus dynamic membership, mail settings, and what deleting one costs. Directory & search Devices, contacts, and the search box that finds any object. Compare Two users or two groups, every Microsoft Graph property, differences highlighted. Mailboxes Nine sections of Exchange settings, mailbox and folder permissions, and converting a mailbox to shared. Mailbox tools Restricted sender unblocking and Quarantine actions, including marked rows and GDAP, plus Cleanup, Copy / Move and Export / Import. OneDrives The tenant usage report, storage quota, sharing, access and lock settings, including the exact GDAP limitations. OneDrive tools Cleanup, Copy / Move and Export / Import for files — including ZIP behavior, duplicate handling and the customer-tenant sign-in path. Tenant The organisation's Microsoft 365 profile, its verified domains, licences and who holds them, admin roles, and the roles you personally hold here. Delegated administration GDAP tenant switching, managing your GDAP relationships, what works in a customer tenant and what cannot. Settings Preferences, your CloudSergeant subscription, the activity log folder, and version information. Licences & offline use The two plans, the licence states, the Beta Trial, and how long the app works without a network.