Install and customize EntraGUARD: from setup to white-label
From the downloaded setup to a fully branded audit workstation in about fifteen minutes: installation, shared-machine behaviour, offline licence activation, white-label customization and per-client report branding.
Before you install: prerequisites
EntraGUARD is a self-contained Windows desktop application. You need:
- Windows 10/11 or Windows Server 2019+, 64-bit;
- administrator rights for the installation only — the setup creates the shared data folder with the right permissions;
- nothing else: no agent, no database server, no framework to pre-install. The audit itself is strictly read-only against the Microsoft tenants you assess.
Step 1 — Run the installer
Launch the setup and follow the wizard. Behind the scenes it does two things:
- installs the application under
Program Files; - creates the data folder
C:\ProgramData\EntraGUARD— companies, control packs, audit history and exports live there, with permissions that let every Windows account on the machine read and write them.
Shared audit workstation. Several consultants on the same machine see the same companies and the same audit history — while each Windows account keeps its own active company. Nothing to configure: it is the default behaviour.
Step 2 — First launch
Three quick actions make the workstation operational:
- Activate the licence — Settings > Licence, paste the key. Activation is fully offline: nothing ever leaves the machine, which matters when the workstation lives in an air-gapped audit room.
- Create the first company — the Companies page holds one isolated workspace per audited client: name, Microsoft tenant, contact, sector, internal reference. Settings, connectors and audit history are strictly separated per company.
- Configure a first connector — start with Entra ID, then add Active Directory or Azure as the engagement requires. Automatic provisioning creates the read-only app registration for you.
Step 3 — Make it yours: white-label branding
EntraGUARD is built for consultancies and MSPs who deliver reports under their own name. Open Settings > Customization and fill in your identity once — it is applied everywhere:
| Field | Where it appears |
|---|---|
| Application name | Window title and interface |
| Your logo | Interface + header of every HTML and PDF report |
| Company name & website | Report headers and the cover page of the executive report |
| Slogan & contact | Footer of every generated report |
From then on, every deliverable — detailed report, executive summary, remediation plan, framework view — carries your brand across all 323 controls.
Step 4 — Customize per client
Branding also works at the company level. Open a company sheet to set:
- the client's logo — it lands on the dark cover page of the executive report, in the "Audited company" block, exactly where a CISO expects it;
- the export preferences — which formats to produce (CSV, JSON, Excel, HTML, PDF) and which report type to favour for this client.
Tip. Keep the JSON export as your archival format: it embeds, control by control, the queries that were executed and the offending objects found — the evidence trail that makes an audit defensible when a finding is challenged.
Step 5 — Theme and language
Two last switches, one click away on the dashboard:
- Dark / light theme — applied instantly to the whole interface;
- English / French — interface and generated reports are fully bilingual, so you can work in one language and deliver in the other.
Post-install checklist
- Licence activated (Settings > Licence);
- first company created with its tenant reference;
- at least one connector configured, connection test green;
- branding filled in (Settings > Customization) — generate a blank PDF to check the rendering;
- first audit launched, report reviewed with your logo on it.
Total time from download to a white-labelled, audit-ready workstation: about fifteen minutes.
Run it on your own terms
EntraGUARD ships as a complete, self-hosted product — 323 automated controls, white-label by design.
Get the terms