Support/Products/Veri-Docs

Veri-Docs

Starter

Veri-Docs generates professional standard operating procedures directly from your live Microsoft 365 configuration. SOPs document what is configured, how each policy is set up, and which users or groups are affected — all formatted with your company branding.

18Policy types
4Export formats
~60sGeneration time
StarterMin tier

How Veri-Docs Works

Step-by-step walkthrough from start to finish

1

Connect Your Tenant

A Global Administrator approves read-only access to your Microsoft 365 configuration via Microsoft's standard admin consent flow. No passwords or secrets are shared — authentication uses X.509 certificates with HSM-backed key storage.

2

Select Output Formats

Choose which formats to generate: Markdown, HTML, PDF, or DOCX. On paid plans, all four formats are available simultaneously. Company branding (logo, name, colors) is automatically applied.

3

Generate SOPs

Veri-Docs reads your live M365 configuration via the Microsoft Graph API and generates one SOP per policy type found in your tenant. Conditional Access, Intune profiles, compliance policies, app protection, enrollment restrictions, and more — 18 policy types in total.

4

Download & Archive

Documents are stored in your searchable archive. Download individual files or the entire job as a ZIP. Every generation is versioned and timestamped for audit trails.

Data Handling

What data is collected, processed, stored, and what is never accessed

Data collected during SOP generation

  • Microsoft 365 policy configurations (Conditional Access, Intune, SharePoint, etc.) — read-only, via Graph API
  • User and group display names referenced in policy assignments
  • Named location names and IP ranges in Conditional Access policies
  • License SKU names assigned to your tenant

How data is processed

  • Policy data is read from the Graph API by the worker container (Azure Container Apps Job)
  • Data is structured into SOP documents using Veri-Docs formatting templates
  • Company branding (logo, name, colors) is applied from your Settings
  • Documents are generated in the requested formats (Markdown, HTML, PDF, DOCX)
  • Processing completes in approximately 60 seconds

What is stored after generation

  • Generated SOP documents in Azure Blob Storage (encrypted at rest)
  • Job metadata (timestamp, status, format selections) in Azure Table Storage
  • Retention: 30 days (Starter), 90 days (Professional), 3 years (Enterprise/MSP)

Data Veri-Docs never accesses

  • Email content, mailbox data, or calendar entries
  • File contents in SharePoint or OneDrive
  • User passwords, MFA secrets, or authentication tokens
  • Sign-in logs, audit logs, or activity data
  • Device hardware details or installed applications

Permissions

Every Graph API permission used, when it's requested, and why

Permission Model

Veri-Docs uses read-only app permissions granted via Microsoft admin consent. No write permissions are ever requested. All authentication uses X.509 certificate credentials with HSM-backed key storage in Azure Key Vault — no client secrets.

Policy.Read.All
Read
Always

Read Conditional Access policies and named locations

DeviceManagementConfiguration.Read.All
Read
Always

Read Intune device configuration profiles and compliance policies

DeviceManagementManagedDevices.Read.All
Read
Always

Read managed device inventory for enrollment profiles

Directory.Read.All
Read
Always

Read user and group display names for policy assignment context

Organization.Read.All
Read
Always

Read tenant name and license SKUs for document headers

Safety Controls

  • Read-only access — Veri-Docs cannot modify any tenant configuration
  • X.509 certificate authentication — no client secrets in the system
  • No raw tenant data stored between jobs — only generated documents are retained
  • Revoke access at any time from Settings or Entra admin center
  • All data encrypted at rest (AES-256) and in transit (TLS 1.2+)

Capabilities

18 M365 policy types — Conditional Access, Intune device config, compliance policies, security baselines, app protection, enrollment profiles, update rings, Autopilot, and more
Export formats: Markdown, HTML, PDF, and DOCX
Automatic version numbering and date stamping
Company branding (logo, colors, name) applied to all outputs
Policies grouped by type with full configuration details
User and group assignment context included in each SOP

Frequently Asked Questions

What are the 18 policy types?
SOPs cover Conditional Access policies, Intune device compliance and configuration profiles, security baselines, app protection policies, enrollment restrictions, Windows Update rings, Autopilot deployment profiles, SharePoint sharing settings, and more. Every policy detected in your tenant gets a professionally formatted SOP.
Does Veri-Docs read my email or files?
No. Veri-Docs only reads policy configurations — the rules and settings that govern your tenant. It never accesses email content, file contents, user credentials, or activity data.
How long does generation take?
A typical SOP generation completes in about 60 seconds. Larger tenants with many policies may take slightly longer.
Can I customize the SOP format?
You can apply your company branding (logo, name, color scheme) from Settings → Branding. The document structure follows a standardized compliance-friendly format designed for auditors and IT teams.