Passbeam

What can Passbeam support see of my clients' data?

As little as possible, on purpose, and the limits are enforced by the code rather than by a policy document.

Start with what does not exist to be seen. Passbeam holds no copy of your clients' directory — no users table, no devices table, nothing synced. Every account and device question is asked of Microsoft live, at the moment it is needed, and the answer is used and discarded. Private keys are generated on devices and never sent to us. And Passbeam never sees a single packet of the traffic on your clients' networks; it answers the question "may this device join" and has no part in what happens afterwards.

What we hold is identifiers and outcomes: which device or person authenticated, when, through which access point or switch, and the result with its reason. That is the record that answers "why can this person not get on the network", and it is the reason to keep it.

For support to look at your account at all, it opens a support view, and that view is deliberately crippled: it is read-only. While it is open, every action in the product refuses — support cannot issue a certificate, cannot revoke one, cannot change a setting, and cannot even write into your own support conversation as you. Replying to a ticket as Passbeam is a separate thing done from a separate place, with the view closed.

Every one of those views is written to an audit log that you can read, at Account, Audit log — including who looked and when. You are not relying on us to tell you.

Within your own account the same principle applies to your own people: access is scoped by role and can be narrowed to particular clients, every capability is checked in the action itself rather than only hidden in the interface, and there is a manifest checked against the source so that a new action cannot quietly ship without a permission check.

Related questions

Still stuck? Ask us, or read the rest of the knowledge base.