Directory & search

Devices and mail contacts, plus the one search box that finds any object in the tenant and opens it where it is managed. Licences and admin roles are documented under Tenant.

One box, under Entra, that searches every kind of object at once: users, groups, devices, mailboxes, Microsoft 365 group mailboxes, mail contacts, admin roles, and both recycle bins. Each result's button opens the object on the page that owns it, and Back returns you to your results with the query intact.

It matches substrings, not prefixes

Microsoft Graph's own search matches the beginnings of words, so searching mith will not find Smith. CloudSergeant builds its own index of the tenant instead and matches anywhere in the value — which is what makes partial names and fragments work. Type at least two characters to start.

It matches things no column shows

Being handed an identifier out of a sign-in log or an audit entry is the case this page exists for, so the index covers far more than the visible columns:

  • Object ids, device ids, role template ids and contact GUIDs — paste a GUID straight out of a portal URL.
  • The username (UPN) as well as the mail address.
  • A group's alias.
  • Every secondary SMTP address a user, group, mailbox or contact carries — being given sales@ and finding nobody would be a gap.
  • The values of a user's custom extension attributes, including your tenant's own directory extensions. These are where organisations keep cost centres, employee numbers and site codes, and they appear in no column anywhere in the app.

Because a mailbox can carry a dozen aliases, matches like these are not given columns — the row's tooltip tells you why a result came back.

One refusal does not break the page

The index is built from several sources, published as each one arrives, so you can start searching users while the slower mailbox reads are still running. If you hold directory rights but no Exchange role, the mailbox and contact sources fail and the status line says so — you still get working user, group, device and role search.

Devices

Every registered device, filterable by operating system and join type. The card shows the OS and version, join type, management state, compliance, sign-in status, registration date, last sign-in, and the registered owner and users.

You can enable, disable or delete a device, and add it to or remove it from groups. Those lifecycle actions need a privileged baseline permission and a device-administrator role — see Sign-in & permissions.

BitLocker recovery keys

The card can reveal a device's BitLocker recovery key. This is the most privileged thing CloudSergeant does, so it is the only read in the whole app that is written to the activity log — recording that a key was revealed, by whom, and for which device. The key itself is never logged.

Contacts

External people in the global address list: no account and no mailbox, but a valid member of a distribution group. The card has three sections — General, Email addresses, and Contact information — plus create and delete.

These are Exchange objects, so this page needs an Exchange role rather than a directory one; Microsoft Graph can only read them. Both the display name and the external address are editable, and a save can change both at once.

There is no recycle bin for a mail contact. Deleting one removes it outright, and the delete panel says so.

A contact synchronised from on-premises AD is read-only throughout, with the reason shown on the card.