Entra Admin Toolkit privacy policy
Entra Admin Toolkit is published by Control Alt Delete Tech Bits. The extension provides a browser workspace for Microsoft cloud administration, local identity troubleshooting and user-initiated privileged role operations.
Entra Admin Toolkit has no developer-operated backend, advertising or telemetry. Extension data is processed locally or sent directly to the Microsoft service selected by the user.
Information handled by the extension
The extension handles the following information when the related feature is used:
- Microsoft account and tenant identifiers, including account display information, tenant ID and object ID returned during authentication. These values are used to confirm which account and tenant are connected.
- OAuth access and refresh tokens required for delegated Microsoft Graph and Azure management requests.
- Privileged role information, including role names, scopes, eligibility, active state, expiry time and the result of user-initiated role requests.
- Titles and URLs of supported administration pages when recent-page recording or saved pages are enabled.
- Preferences supplied by the user, including tenant labels, environment colours, favourites, app registration settings and PIM defaults.
- Text submitted to local utilities, such as JWTs, AADSTS error messages and application identifiers.
- Visible page text examined locally when screenshot privacy masking or identifier hover lookup is enabled.
How information is used
Information is used only to provide user-facing extension features. This includes displaying the connected account, retrieving eligible and active roles, submitting a role action requested by the user, opening and saving supported administration pages, showing local troubleshooting results, applying privacy masking and warning before an active role expires.
The extension does not use data to build advertising profiles, measure advertising, determine creditworthiness, make lending decisions or track users across unrelated websites.
Microsoft authentication and API communication
Authentication uses OAuth 2.0 authorisation code flow with PKCE. No client secret is used. The extension connects over HTTPS to:
login.microsoftonline.comfor Microsoft authentication.graph.microsoft.comfor Microsoft Entra directory role and PIM for Groups operations.management.azure.comfor Azure subscription and resource role operations.
Microsoft receives the information required to authenticate the user and complete the API request selected by the user. Microsoft’s handling of that information is governed by Microsoft’s own terms and privacy policies.
Information stored on the device
Access tokens, refresh tokens and cached role results are stored in chrome.storage.session and are cleared when the browser session ends.
Preferences, tenant labels, saved pages, favourites and up to 100 PIM action-history records are stored in local extension storage. Recent supported administration pages are stored locally only when that feature is enabled. These records remain until the user clears them, changes the related setting or removes the extension.
Configuration export occurs only after the user selects Export. The exported file contains preferences, tenant labels and saved pages. It excludes Microsoft tokens, cached roles, recent pages and PIM action history.
Local utilities and website content
JWT analysis, AADSTS lookup and identifier lookup are performed inside the extension. Submitted values are not sent to the publisher. JWT analysis decodes token content but does not validate the signature, issuer, audience or revocation state.
Screenshot privacy masking examines visible text on supported administration pages and adds local masking overlays. Examined text is not stored or transmitted. Masking is a convenience and cannot guarantee that every sensitive value will be covered.
Sharing and transfers
The publisher does not receive, sell or rent extension user data. The extension does not transfer user data to advertising platforms, data brokers or analytics providers. Human access to extension user data is not available because the extension has no publisher-operated data service.
The Donate button opens Buy Me a Coffee only after the user selects it. No Microsoft token, role information, tenant configuration or extension history is sent by the extension to Buy Me a Coffee.
Chrome permissions
The extension uses the following Chrome permissions:
sidePanelto display the extension interface.storagefor local preferences, session tokens and feature data described in this policy.identityfor interactive Microsoft authentication through Chrome’s protected redirect URI.alarmsfor optional role refreshes and expiry checks.notificationsfor optional role expiry warnings.- Named Microsoft host permissions for the administration workspace, authentication and user-requested API operations.
User choices and deletion
Users can disable recent-page recording, portal launcher controls, hover lookups, expiry notifications and screenshot privacy masking in Settings. Recent pages and PIM history can be cleared from the extension. Removing the extension clears its local Chrome storage. Users can also revoke application consent through their Microsoft Entra tenant.
Security
Network requests containing authentication or role information use HTTPS. Tokens are not exposed to supported administration pages. Users remain responsible for device security, Chrome profile access and the permissions granted to their Microsoft Entra app registration.
Limited Use compliance
Entra Admin Toolkit uses information obtained through Chrome APIs only to provide its stated administration features. Its use of information complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.
Changes to this policy
This policy may be updated when extension features or data practices change. The effective date at the top of the page will be revised when a new policy is published.
Contact
Privacy questions can be submitted through Control Alt Delete Tech Bits contact page. Do not include passwords, access tokens, refresh tokens, tenant exports or other sensitive information in a support request.
Independent status
Entra Admin Toolkit is independent software and is not affiliated with, authorised, sponsored or endorsed by Microsoft.