Security
Last updated 21 September 2026
Leysa makes changes in your Microsoft 365 organisation, so it's built to make the safe path the default. This page describes how, in plain terms. Found a problem? Email security@leysa.ai.
What Leysa can do in your tenant
- Leysa connects through an app a Global Administrator approves in Microsoft's own consent screen. You can see and remove it at any time in the Microsoft Entra admin centre → Enterprise applications.
- Leysa asks only to read your directory. Every change it makes is scoped to what an automation needs: people, groups, teams, licences, mailboxes and guest invitations.
- For mailbox, password and MFA tasks, an administrator also assigns Leysa two roles (Exchange Administrator and Authentication Administrator). Neither can change a Global Administrator or any other administrator.
- You can assign those two roles by hand, or let Leysa assign them during setup. If you choose that, Leysa acts using the administrator's own sign-in at that moment, and can't change roles on its own — before or after. The permission that allows it stays listed under Enterprise applications → Permissions, and you can remove it whenever you like; the two roles stay assigned.
- Leysa refuses to change any account that holds an admin role — no password or MFA resets, profile changes, offboarding, forwarding or mailbox access. It checks every role, including ones held through a group, and stops if it can't check.
Who can do what in Leysa
- Three roles: Owner, Admin and Operator. Operators only see and use the areas the Owner gives them.
- The Owner chooses which automations need approval. Nobody can approve their own request unless they're the workspace's only Admin, and those are labelled in Activity.
- Every run records who requested it, who approved it, when, and what happened at each step. Activity can be exported as a spreadsheet.
- Removing someone from the workspace ends their access within minutes and cancels their pending requests; their history stays in the audit trail.
Passwords
- Leysa generates temporary passwords itself — nobody types or sees one.
- The password is delivered through a one-time link that works once and expires (at most 7 days). Only the person who ran the automation, or the colleague it was emailed to, can get the link.
- Links only go to people inside your organisation, never to outside email addresses.
Data protection
- All traffic uses HTTPS. Microsoft 365 access tokens, temporary passwords and webhook secrets are encrypted with AES-256-GCM before they're stored; the database itself is encrypted at rest by our database provider.
- Data is stored and processed in Sydney, Australia. A few supporting services (email delivery, error reports and the AI assistant) run in Japan and the United States.
- Sign-in links are stored only as one-way hashes, so a copy of the database can't be used to sign in. Password-link addresses are stored encrypted and wiped as soon as the link is opened or expires.
- Sessions end after 30 minutes of inactivity (with a warning), and always after 12 hours.
- Error reports have names, email addresses and IDs removed before they leave our servers.
Your controls
- Disconnect Microsoft 365 at any time from the Integrations page, and remove the Leysa app from your tenant.
- The Owner can delete the whole workspace and its data in Settings → Profile.
- Webhooks are signed, so your systems can check a message really came from Leysa.