Tenvero is designed for shared mailbox administration workflows. This page summarizes what the product is built to do, which systems it connects to, and how permissions are scoped.
Tenvero uses mapped AD security groups as the administrator-facing source of truth for shared mailbox delegation. Reconciliation adds missing direct Exchange permissions and removes stale permissions only when those entries are Tenvero-owned.
Existing direct mailbox permissions can be adopted into Tenvero ownership through an explicit takeover workflow. The takeover process is non-destructive and does not intentionally remove existing direct access during adoption.
Tenvero uses app-only Exchange Online authentication with a LocalMachine certificate for unattended reconciliation. Interactive Microsoft Graph sign-in is used for Entra app provisioning and repair flows.
The scheduled task model is intended to run with a dedicated service account that has certificate private-key read access and only the required Windows and directory rights.
Tenvero stores operational configuration and logs on the customer-managed Windows host, including mailbox mapping state, reconciliation and audit logs, and licensing cache metadata. Core paths include C:\\ProgramData\\Tenvero and its subfolders.
Delegation Audit is read-only by design: it identifies drift and invalid delegate states without directly changing AD group membership or Exchange delegation.
Paid and trial licenses are tenant-bound to a Microsoft Entra tenant. One license covers one tenant and can be activated on multiple administrator installations for that tenant.
Trial duration is 30 days with no post-trial grace. License state is validated before reconciliation operations that would modify delegation state.
This summary is intentionally conservative. If you need exact role assignments, endpoint lists, retention policies, or enterprise deployment controls for a security review, contact the Tenvero team for the current production detail set.
Contact: [email protected]