The list
Every user in the tenant, searchable by display name, mail address, username (UPN), and every secondary SMTP address the account carries. The username matters: it is what a sign-in log, an audit entry or a helpdesk call gives you, and an account with a mailbox shows its mail address in the grid rather than the name it signs in with.
Filters narrow by sign-in status and on-premises synchronisation. The list is read once per tenant — use Refresh after a change made elsewhere. Double-clicking a row is the same as its Edit button.
The column is named Last sign-in when Entra ID P1 or P2,
AuditLog.Read.All, and a suitable reader role allow CloudSergeant to show the
exact timestamp of the account's last successful interactive or non-interactive sign-in in
your computer's local time. Microsoft notes that this property can take up to 24 hours to
update.
When that read is refused, the column is named Last activity and CloudSergeant automatically falls back to the newest Exchange, OneDrive, SharePoint, Teams, Skype for Business or Viva Engage activity date in Microsoft's 180-day Active Users usage report. It has day precision and can lag by up to 48 hours. None in 180d means that report contains no recent activity, while Unavailable means neither source could be used. If the tenant conceals names in usage reports, the page offers the same confirmed Show names in reports action as the OneDrives page.
The user card
Nine sections down the left, with a save bar pinned to the bottom. Save writes the profile fields; sections that write immediately say so, so "no changes to save" after a membership edit is expected rather than a failure.
General
Names, job title, department, company, employee ID and type, hire and leave dates, manager, office and postal address, usage location and preferred language.
The profile picture lives here too, with Change / Download / Remove. It writes immediately, because the picture is not one of the fields Save sends. Any image is re-encoded to JPEG for you — Microsoft accepts only JPEG, and a PNG is the common case. For an account with a mailbox the picture is stored in Exchange, so it can take a while to appear in Outlook and Teams, and can fail outright while a new mailbox is still being provisioned.
Account
Split into Account details and On-premises synchronization. Here you block or allow sign-in, read the same dynamic Last sign-in or Last activity value shown in the list, read the object id and user type, and rename the username using a split editor over your verified domains. The primary email address is a separate, Exchange-owned thing and is changed on the mailbox card.
Renaming validates locally first — malformed names and duplicates already in the loaded list are caught before the request — but Microsoft remains the final authority. You cannot rename the account you are signed in as. The on-premises half holds the read-only sync status and a separately confirmed Immutable ID reset.
Authentication
Everything to do with credentials and sessions:
- Reset password — generated or set, optionally requiring a change at next sign-in.
- Revoke sessions — signs the account out everywhere.
- Require multifactor re-registration — the "reset MFA" action.
- Registered methods — every method the account holds. Phone and recovery email can be added, edited and deleted; a Temporary Access Pass can be created and deleted; Authenticator, passkeys, security keys, software OATH, Windows Hello and platform methods are delete-only, because Microsoft Graph cannot provision or edit those remotely. The password itself is shown but not deletable — it is not a second factor.
The pass is secret material. It is displayed until you dismiss it or leave the card, is never written to the activity log, and cannot be recovered afterwards — creating a new one invalidates the old. Creating a pass while one already exists is treated as destructive and asks for confirmation.
Every write in this section is disabled for the account you are signed in as: wiping your own authentication methods under a conditional-access policy can lock you out mid-session. Managing methods on an account that itself holds an admin role needs Privileged Authentication Administrator.
Roles
Directory (admin) roles held by the user, with add and remove. The picker offers the whole catalogue, not just roles somebody already holds — assigning one nobody holds yet activates it in the tenant, which is a one-way, tenant-wide change, so the confirmation says so.
Only direct, active assignments are shown. A PIM-eligible assignment is not a membership, and a role held through a role-assignable group belongs to the group — neither appears here and neither can be changed here.
Both directions confirm. This is the one write in the app that changes who can administer the tenant.
Groups, Devices, Licenses
- Groups — add and remove membership. Writes immediately.
- Devices — the devices registered to or owned by the user, with a jump to the device card.
- Licenses — tick the SKUs and press Apply license changes. Assigning a licence needs a usage location on the account, so the app puts one there when the user is created.
Extension attributes and Attributes
Extension attributes is the fifteen extensionAttribute1–15
slots plus any directory extensions your tenant defines — editable, with their own Save,
because they are a nested property the ordinary profile save cannot express.
Attributes is a read-only dump of everything Microsoft Graph knows about the account, including properties the card does not surface, with a search box and a Hide empty toggle. A property that could not be read still gets a row saying which permission it would need — so you can tell "this is empty" from "I could not look".
These are not the mailbox's custom attributes. The five multi-valued
ExtensionCustomAttribute slots belong to the mailbox and live on
the mailbox card. The naming invites exactly the
wrong guess, so both sections say which is which.
Creating a user
A five-step wizard: Basics → Product licenses → Optional settings → Review → Finish.
Display name and username are derived from the names you type, and stop being derived the moment you edit them yourself. The Review step lists anything that would fail, filed against the step that owns it, with a link straight to it.
Once the account exists, Microsoft offers no way to un-create it — so phone numbers, licences, group memberships and admin roles are applied afterwards as independent steps, each reporting its own result on the Finish page. A user created with two of four licences assigned tells you exactly that, rather than being rolled back. Role assignment is the one part that may simply be unavailable, because it needs the baseline role-management permission and Privileged Role Administrator.
Finish offers Create another and Open the new user.
Offboarding: deleting a user
The Delete action on the card's bottom bar opens a flow modelled on the Microsoft 365 admin center's, because deleting a leaver is rarely just a deletion. You can:
- Release the mail aliases immediately, so another account can take the address.
- Remove delegate access from the mailbox.
- Give another user access to the mail — converts the mailbox to shared and grants Full Access.
- Give another user access to the OneDrive files. This shares the top folder; for a durable handover with full control, add a site collection administrator from the OneDrive card.
If a handover you asked for does not succeed, the account is not deleted — that handover is precisely the data the deletion would put behind a 30-day clock. The result page says what failed and offers an explicit Delete anyway. This is the opposite of the create wizard's behaviour, and deliberately so: here the irreversible step comes last, so stopping still leaves everything recoverable.
Two situations are refused before the panel even opens:
- The account you are signed in as.
- An account synchronised from on-premises AD. Delete it in AD and let the change synchronise — deleting it in the cloud would either be refused or be undone by the next sync, so reporting success would be a lie.
Converting the mailbox to shared is confirmed by re-reading it, not by a success code: Exchange keeps reporting the old type for a while after the change, so the app polls until it can see the result. If it cannot confirm within the wait, it tells you the change was submitted and not to convert by hand — it does not claim a refusal.
Deleted users
Accounts deleted in the last 30 days, with Restore and Delete permanently. The grid deliberately opens with nothing selected, and neither action is a double-click, because both sit next to each other and one of them cannot be undone.
Restoring does not bring the licences back. Reassign them from the Licenses section afterwards.
After a delete or restore the app updates its own list rather than re-reading the directory. Microsoft keeps returning a just-deleted object for several seconds, so re-reading would put the user straight back on screen and read as a silent failure.