FAQ

Answers before your team commits rollout

Common questions from MSP, cloud security, and consulting teams evaluating Futrly.

How fast can we run first scan?

Most teams complete tenant connection, validation checks, and first scan in about 5 minutes.

What exactly gets validated before scanning?

Futrly validates consent health, Graph permissions, Resource Graph availability, subscription access, and required roles.

Which roles should we assign for best reporting quality?

Assign Directory Reader in Microsoft Entra ID, and assign Security Reader plus Reader on the Azure subscription scope being scanned. This combination gives the strongest report coverage with read-only access.

Can we limit scans to selected subscriptions?

Yes. Every tenant supports saved default subscription scope for controlled execution.

What happens when consent is revoked?

The tenant is flagged immediately, reconnect is prompted, and reporting dependencies are clearly marked.

What alerting comes with each plan?

Free has alerts disabled, Pro receives weekly digest email alerts, Enterprise receives real-time alert emails.

Who receives emails?

Owner/admin users and configured report recipients are included, with delivery state tracked in the platform.