Coming soon

One console for the hybrid Microsoft estate you actually run

Omni ITM is a hybrid IT management platform covering on-premises Active Directory, Entra ID, Microsoft 365, Intune, Exchange Online, SharePoint and Azure. Sixteen areas, one console. Each area is a permission you grant on its own, and every change lands in an audit trail you can search. A scheduled automation can't run live until a report-only run has shown you what it would do.

One email when early access opens. Nothing else, and you can ask us to delete your details whenever you like.

  • Active Directory and Entra ID together
  • One permission per area
  • Remote tools on Windows and Android
  • Installs on your phone for on-call
Omni ITM console showing one hybrid profile for Alex Morgan: account status, groups, mailbox, devices and licences.

The hybrid problem

One ticket, six admin portals

A shared mailbox ticket sounds like a two-minute job. "I can't get in." So you check the group in on-premises Active Directory. The permission is in the Exchange admin center. Sign-in risk is over in Entra ID. And you still don't know which device they were on. Nothing you learn in one console follows you into the next. The jobs that carry real risk go the same way. Leavers, bulk changes and licence clean-ups end up as a checklist someone keeps in their head, or a script only one person on the team trusts.

  • Hybrid is the starting point

    Omni ITM treats on-premises Active Directory and Entra ID as one estate. Directory search runs against a warm index, so results land while you're typing. Open a person and you get their Entra ID, Exchange Online, Intune and licence detail together in one profile.

  • Fewer places to look

    Sixteen areas sit in one console. No working out which portal owns the thing you need to change, and no losing what you learned by the time you get there.

  • Safe enough to hand over

    A technician gets the areas they need as separate permissions, and not much beyond them. Every change goes into an audit trail you can search. Automations stay report-only until a report-only run has shown you what they'd do live. Delegating work stops being a risk you carry personally.

What it does

Sixteen areas of hybrid IT management

The console opens on Home, showing accounts, licences, devices and update compliance across the estate. Behind it are sixteen areas, each a permission in its own right, so access can be scoped to what someone actually does. We've grouped them here into six themes.

Identity and access

Fix an access problem without leaving the profile

Search the directory, open a person, and the whole picture is on one screen. Joiners and leavers, password resets, MFA and group membership all start from there, so you're not opening a second tool to finish a job you started. Your OU layout and naming conventions live inside the wizards, which is where they're useful.

  • Unified user search and profileType-ahead search, then one profile. It shows account status and lockout state, group memberships, licences, mailbox and OneDrive, Intune devices, MFA methods, and thirty days of sign-in history. No guessing which system owns which bit.

  • Guided account creationOne wizard for standard accounts, another for generic and service accounts built from templates that set the OU, groups and licences for you. Usernames are checked for clashes as you type. Service account naming isn't optional: the wizard won't let you past it.

  • Process LeaverOne run does the lot: disable the account, strip its groups, hide the mailbox from address lists and move it to your leavers OU. Then convert the mailbox to shared, turn on archiving, set forwarding and wipe enrolled devices. It reports every step, requires a ticket number, and can be scheduled for the leaving date.

  • Everyday account actionsReset a password, clear a lockout, enable, disable, move someone between OUs and business units, or restore an account from your inactive users OU. All from the profile, with no remote session and no script.

  • MFA managementRevoke sign-in sessions, force MFA re-registration, remove a single authentication method, set the preferred one. Everything you need at five o'clock when someone's lost their phone.

  • Group management across AD and Entra IDSecurity, distribution and Microsoft 365 groups, on-premises and cloud, static or rule-based. Rules preview before you save them: the on-premises builder shows you exactly who it would add and who it would remove. Naming prefixes are enforced when the group is created.

  • Licence and MFA hygieneStanding reports for MFA registration, licence usage, licences still sitting on disabled accounts, inactive accounts, and accounts with the wrong UPN or location. Bulk enable and disable where that's sensible. You find these before an audit does.

Endpoints, servers and remote support

Fix a PC, a server or a phone from where you are

The remote toolbox is where most of the work happens. Open it from a user's profile, an asset row, a file server or a session host, and it's the same toolbox every time. It runs over a lightweight Windows service agent, keeps a recent inventory snapshot so a powered-off machine still shows you something, and queues whatever you asked for until the device reconnects. On call at 11pm, that queue is the difference between fixing it now and ringing someone at home.

  • Remote toolbox on WindowsA live terminal that runs as SYSTEM, as the signed-in user, or against a named session on a multi-session host. Then a file browser, services, processes, local users and groups, drives, startup items, installed software, Windows Update actions and the last 48 hours of event log. The terminal and the file browser both pop out into their own window.

  • Attended assistance on Windows and AndroidOn Windows, attended assistance launches Microsoft Remote Help in the signed-in user's session, so there's no second remote-control stack to patch. On Android, the agent does attended screen view and control with the user's consent, plus file browsing, a shell runner, app actions and inventory. The Android agent is in the early access build, but it hasn't been verified against live hardware yet.

  • Offline job queueQueue a script, a service change, an uninstall or a Windows Update action against a machine that's switched off, and it runs the moment the agent reconnects. There's a jobs list, and you can cancel from it. Nobody has to ring the user and ask them to log in.

  • Fourteen tested remediation scriptsPrint spooler fix, Winsock reset, DNS flush, Teams cache clear, OneDrive reset, Windows Search rebuild and disk cleanup. Windows Update quick repair, full repair, diagnose and SetupDiag. Network diagnose, network repair, and Intune and GPO sync. Administrators add their own. A technician picks one and runs it.

  • Software and update controlList and uninstall applications, machine-scope, 32-bit and per-user alike. See what updates are installed and what's pending, install or remove a named KB, and check or move the Intune update ring the device sits in.

  • Intune device oversightCompliance state, operating system, model, serial and hardware detail for every managed device, with sync, wipe and the remote toolbox reachable from the list itself. For corporate against personal ownership, look at the standing report.

  • Server ManagementThe Windows server estate, discovered from Active Directory and probed to see what's actually up. From there you get SMB shares, free disk space, NTFS permissions, and live sessions you can sign out. A wizard builds a share end to end, folder, security groups and permissions included. Bulk certificate rollout across on-premises web servers scans and dry-runs before it touches anything.

  • Printer ManagementPrinters are packaged and deployed as Intune applications from the console. The driver library is versioned, and a new driver goes to a pilot ring before it goes to the fleet. Status comes off the printers themselves: toner, paper trays, model and serial.

Mail, files and collaboration

Sort it out while they're still on the phone

Shared mailboxes, delegation, mapped drives and SharePoint housekeeping sit in one area. "Who can get into what" stops being a trip through the Exchange admin center and a guess at whether an inbox rule is quietly forwarding somewhere.

  • Shared mailbox managementCreate one against a ticket number, with its aliases and first delegates set up in the same pass. After that: permissions, forwarding, calendars and calendar rights, automatic replies, archiving and litigation hold. You can read and remove inbox rules. Creating and editing them isn't supported.

  • Mailbox delegationFull access, send-as and send-on-behalf are three different things, granted separately and read back together. Work from the mailbox or from the person's profile. Forwarding that's been buried in an inbox rule shows up too.

  • Archiving and retentionTurn the online archive on or off, and apply a retention policy picked from the ones your tenant actually has. Start the managed folder assistant yourself instead of waiting for it to come round.

  • Drive ManagementDefine the drives once, as UNC shares, Azure Files or a fixed credential, and target them by security group. Add a device group and it narrows the target rather than widening it. Omni ITM renders the definitions into a script, publishes it, and updates the Intune platform script that applies it. There's off, sandbox and live, a preview before you deploy, and a warning when what's live has drifted from what's defined. A technician can re-apply one user's drives on one machine from the remote toolbox.

  • SharePoint housekeepingBrowse sites, libraries and folders, create a folder, and grant or remove permissions on an item. Manage site owners and members, roll a file back to an earlier version, and look through the recycle bin. It all runs under an application identity, so nobody needs site collection administrator.

Security Hub

Know which alert to look at first

Incidents and alerts from Microsoft Defender, risky users from Entra ID Protection, your secure score trend, endpoint vulnerabilities, email gateway threats and web filtering activity, in one view. If you have a dedicated SOC, they have better tools than this. If security is one of many things your team does, this is about the right size.

  • Consolidated security viewIncidents, alerts, risky users, secure score trend, vulnerability posture, email gateway threats and held messages, web filtering activity. Every row deep-links straight to that record in its own console.

  • Guided incident reportsEach incident comes with a plain-English summary, the users, devices and mailboxes actually involved, its related alerts, and a numbered remediation playbook. The playbook is picked from a curated library rather than written on the fly by a model. Export the lot as a PDF and attach it to the ticket.

  • Triage without leaving the consoleSet the status, classification and assignee, and leave a comment. It writes back to Defender, so your triage doesn't end up stranded in a second system.

  • AI-assisted next stepsSwitch it on and an optional assistant reads the context already gathered for an incident or a vulnerability, then suggests specific next steps. It has no way to act. It suggests the steps. You decide, and you carry them out.

  • Live alertingA toast and a bell for new high and critical incidents, for web filtering events, and for network devices dropping off. The first check after you sign in only sets a baseline, so you don't get an alert for every problem you already knew about.

Assets and cost

Know what you own and what it costs

Asset management usually means a spreadsheet somebody updates twice a year. This one builds itself from endpoint management, the on-premises servers, cloud virtual machines and your service desk's own asset records. The last of those is the useful one: it carries the older kit modern management has never heard of. Azure and licence spend sit alongside it.

  • Unified asset inventoryComputers, servers, mobiles and network devices, merged from endpoint management, Active Directory, Azure and an external asset source. Hardware hashes and spreadsheets import into the same list, so the machine in the cupboard is on it too.

  • Warranty, tags and lifecycleWarranty expiry, asset tags with rules that apply themselves, and model, serial, service tag and IMEI. Set an asset to active, stored, retired or disposed and the next sync won't quietly undo it. Where the manufacturer supports it, warranty can be looked up live.

  • Azure and licence spendCost Analysis breaks Azure spend down by service, resource group, resource or any tag key you use, straight from the cost management API. Licence cost is worked out from your seat counts and unit prices, which also gives an estimated cost per user. All in pounds sterling.

  • Budgets, forecasts and wasteSet a monthly budget per subscription or host pool and you get an on-screen warning when spend goes over, or looks like it will. The month-end forecast is Azure's own. The waste report covers unassigned seats, licences still on disabled accounts, unattached disks and unused public IPs, and each list exports.

Automations, reporting and policy

Automate the routine work, and prove it first

Build a job that finds records and does something to them. It won't run live until a report-only run has shown you exactly what it would have done, and if you edit the job, it goes back behind that gate. The same filter builder sits underneath a report builder covering twenty data sources.

  • Gated automationsFive steps: find, actions, schedule and mode, notify, review. The action set is deliberately small: account, group, licence and archive actions. Report-only is the default, going live needs a report-only run that succeeded, and editing the job puts it back behind that gate.

  • Custom report builderTwenty data sources: users, groups and their members, computers, servers, mobiles, printers, mailboxes, licences, costs, sign-ins, network devices, and software and patch inventory. Pull in related data with one click, add calculated columns, filter, sort, group and chart the grouped result. No query syntax anywhere.

  • AI report draftingDescribe the report you want in plain English. What comes back is a definition, checked against the fields that actually exist, opened in the builder for you to look over before anything runs.

  • Standing reports and exportsSeventeen fixed reports covering licences, MFA, group members, distribution lists, drive mappings, OneDrive usage, inactive and misconfigured accounts and unmanaged devices. Each one exports to a branded PDF or CSV. Scheduling works on saved report builder templates: daily, weekly or monthly, emailed out, and every run kept as a snapshot.

  • Advanced ReportingUpdate and patch compliance, Windows versions and software inventory, all read out of your Log Analytics workspace. It will tell you how long your devices really take to pick up a security update, which is rarely the number you'd hope for. It carries its own permission.

  • Policy FinderAsk which endpoint management policies land on a user, a device or a group, nested groups included. Search covers the settings inside a policy as well as its name. Compare two users or two devices side by side, and check what a group would hand a device before you add it. "Why has this laptop got that setting?" becomes a lookup.

The console

A look at the screens

The areas you'd spend most of your day in. Every name, address, device and figure shown here is placeholder data.

Fix it from wherever you are

Open a terminal on a machine, run one of the tested repair scripts, or browse its files. Queue work against a device that is switched off and it runs when the device comes back. The console installs on your phone, so an engineer on site or on call can pick up a ticket without opening a laptop.

Remote toolbox on a managed PC: a live terminal, tested repair scripts, and jobs queued for a device that is offline.
Omni ITM on a phone showing Azure Virtual Desktop host pools, session counts and remote tool actions for each host.
  • Identity and access screen listing Active Directory and Entra ID accounts at Northwind Logistics with group membership.
    Identity and accessFix an access problem without leaving the profile
  • Device management screen showing Intune compliance, OS build and remote tools for a laptop named WKS-0142.
    Endpoints, servers and remote supportFix a PC, a server or a phone from where you are
  • Shared mailbox management screen setting full-access and send-as permissions for a fictional example.com mailbox.
    Mail, files and collaborationSort it out while they're still on the phone
  • Asset inventory and Azure cost view showing hardware, warranty dates and monthly spend by resource group.
    Assets and costKnow what you own and what it costs
  • Automation designer building a stale-account job in report-only mode with a record cap and email summary.
    Automations, reporting and policyAutomate the routine work, and prove it first

Security and trust

Who can do what, and what they did

The person closing the ticket usually shouldn't hold the highest privileges in the estate. It's an awkward fact to design around. So access is scoped area by area, the console records what people change, and anything that would change production on a schedule has to prove itself first.

  • Permissions, area by area

    Each area of the console is its own permission. A few surfaces carry their own on top of that: the remote toolbox and Advanced Reporting are granted separately from the areas they sit behind. Administration stays admin-only, as does a small number of high-blast-radius settings inside areas that are otherwise grantable. You can hand someone the part of IT they need, and not much beyond it.

  • An audit trail you can search

    The audit log records sign-ins, every change, and reads other than the background status polling. Each entry has the person, the action, the path and the address it came from. Filter by action, person or date range, and export as CSV. Request bodies never go into the log, so nothing sensitive ends up in it. Entries are kept for a year.

  • Safety gates on automations

    An automation stays report-only until a report-only run has succeeded. Change what it finds or what it does and it's report-only again. If it matches more records than the cap you set, the whole run aborts before it changes anything, and a job can't overlap itself. Nothing runs on a schedule that a person hasn't switched on.

  • What the assistant is allowed to do

    The assistant appears in five places: incident guidance, vulnerability summaries, and drafting reports, automations and group membership rules. In every one of them it can only hand back text or a draft. It's given no tools to call, so there's no route from a suggestion to a change. It suggests the steps. You decide, and you carry them out. An automation it drafts arrives report-only and switched off, and until an administrator configures it, it does nothing at all.

Security Hub listing incidents and alerts with a numbered remediation playbook for a suspicious sign-in.
  • Per-area permissionsGrant someone the areas they should be using, one at a time.
  • Searchable audit trailIt records who signed in and who changed what. Filter it, then export it as CSV.
  • Safety gates on automationsReport-only first, a record cap that aborts before anything changes, and no run overlapping another.
  • Help on every screenA guide library reachable from every area, and a bug-or-idea form that attaches the console logs so you don't have to describe them.
  • Fast, and installable on a phoneRead screens tell you how old their data is and writes go live immediately, with keyboard search across users, groups, devices, mailboxes, servers, shares, drives and printers. Install it on your phone and it opens off the home screen without browser chrome. An engineer on site, or on call out of hours, works in the same console.
  • Network sites and virtual desktopsSite health comes off your network hardware and firewalls, with an alert when one drops. Host Pools does drain mode, restarts, forced sign-out and releasing a locked profile.

Hybrid coverage

Built for hybrid Microsoft environments

Most organisations aren't cloud-only, and won't be for years. Omni ITM is a hybrid IT management platform before it's anything else. It reads and writes across on-premises Active Directory and Entra ID together, and treats Microsoft 365, Intune, Exchange Online, SharePoint and Azure as one estate rather than five products with five consoles. On-premises work goes through a connector service you install inside your own network. That covers directory writes, file servers, printers and Exchange commands, so nothing on-premises needs to be reachable from the internet. One place to work, instead of the Entra admin center, Intune, the Exchange admin center and a folder of PowerShell scripts.

  • Active Directory

    Accounts, groups, OUs and the member server estate, discovered from the directory itself and managed next to their cloud counterparts.

  • Entra ID

    Cloud identity and groups, rule-based membership you can preview before saving, sign-in history, risky users, MFA methods, session revocation and device group membership.

  • Microsoft 365

    Licence assignment and hygiene, seat counts, an estimated cost per user, and the account lifecycle sitting behind all of it.

  • Intune

    Device compliance and hardware detail, applications and updates, update rings, printer and drive-mapping deployment, and policy lookups by user, device or group.

  • Exchange Online

    User and shared mailboxes, all three delegation types, inbox rules, forwarding, calendar rights, archiving, retention and litigation hold.

  • SharePoint

    Sites, libraries and folders, item and site permissions, version history and the recycle bin, all under an application identity rather than site collection admin.

  • Azure

    Virtual machines in the asset inventory, plus virtual desktop host pools and their user profiles. Spend by service, resource group, resource or tag, with budgets and forecasts, and update reporting from your Log Analytics workspace.

What Omni ITM can see and change is bounded by the permissions you grant it in your own directory and tenant, and by what the connector inside your network is allowed to do. It touches nothing you haven't consented to.

Questions

Common questions

Short answers, and if your question isn't here the contact form gets you a person.

What is Omni ITM?

Omni ITM is a hybrid IT management platform from Flux-r Labs: one console for identities, devices, mailboxes, security and cost across on-premises Active Directory, Entra ID, Microsoft 365, Intune, Exchange Online, SharePoint and Azure. Sixteen areas sit behind it, each granted as its own permission. It suits IT teams whose estate is part on-premises and part cloud. It's in development, ahead of early access.

Can it manage on-premises Active Directory and Entra ID together?

Yes, that's the point of it. One search box covers the directory, and opening a person brings their on-premises account together with their Entra ID detail, mailbox, Intune devices and licences in a single profile. Groups work the same way: security, distribution and Microsoft 365 groups, on-premises or cloud, static or rule-based, from one place.

Does it replace the Entra admin center, Intune and the Exchange admin center?

For everyday work, largely yes. User and group management, licences, MFA, mailboxes and delegation, device compliance, updates and policy lookups all happen in Omni ITM instead of hopping between those consoles. It doesn't cover every corner of them. Tenant-wide configuration still belongs in Microsoft's own portals, and the security views deep-link straight to the record when you need to go there.

How do you stop someone on the service desk breaking something?

Mostly by scoping what they can reach: each area is a separate permission, so a technician gets what they need and not much else. Automations can't run live until a report-only run has shown what they'd do, and a record cap aborts the run before any change if it matched more than you expected. The audit trail records who changed what.

Is every action logged?

Every change is, yes. Sign-ins and reads are logged too, apart from the background status polling, which is deliberately left out. Each entry has the person, the action, the path and the address it came from, and you can filter by action, person or date range and export to CSV. Request bodies are never written. Entries are kept for a year.

Does it use AI to make changes on its own?

No. The assistant can only return text or a draft. It's given no tools to call, so there's no route from a suggestion to a change. It's used in five places: incident guidance, vulnerability summaries, and drafting reports, automations and group membership rules. It suggests the steps. You decide, and you carry them out. An automation it drafts arrives report-only and switched off.

How does it reach on-premises servers and devices?

Through two components you install yourself. A connector service runs inside your network and handles on-premises work: directory writes, file servers, printers and Exchange commands. Nothing on-premises has to be reachable from the internet. A lightweight Windows service agent sits on endpoints and servers for the remote toolbox, and queues jobs for machines that are switched off until they reconnect.

Which Microsoft services does it cover?

On-premises Active Directory, Entra ID, Microsoft 365, Intune, Exchange Online, SharePoint and Azure. In practice that means accounts and groups in both directories, licences and MFA, mailboxes and delegation, device compliance and updates, SharePoint permissions, and Azure spend, host pools and Log Analytics reporting. Microsoft Defender and Entra ID Protection feed the security views.

Can I give a technician access to just one area?

Yes. Each of the sixteen areas is a separate permission, so you can grant one and leave the rest. A couple of surfaces are granted on top of that rather than inside it: the remote toolbox and Advanced Reporting have their own permissions. Administration stays admin-only, along with a small number of high-blast-radius settings inside areas that are otherwise grantable.

When can we get it, and what will it cost?

Neither is settled yet, and we'd rather say so than invent a date. Omni ITM is in development and heading for early access. There's no published price and no tier structure to quote. Register your interest and you'll get one email when early access opens, with the commercial detail at that point. That's the only thing we'll send you.

Can I use Omni ITM on a phone?

Yes. It installs from the browser as a progressive web app, so it sits on your home screen and opens without browser chrome. The layout has breakpoints at 900, 720, 640 and 480 pixels, and the navigation collapses into a slide-in drawer. That matters most for an engineer on site, or on call out of hours, working from a phone.

What can I do remotely on a Windows PC or a mobile device?

On Windows: a live terminal that runs as SYSTEM, as the signed-in user, or against a named session on a multi-session host. Also a file browser, services, processes, event log, installed software, Windows Update actions and fourteen tested scripts. Attended assistance launches Microsoft Remote Help. On Android, the agent does attended screen view and control with the user's consent.

Early access

Register your interest

Omni ITM isn't generally available yet. Leave us an address and we'll come back to you when early access opens.

Only your work email is required.

How we handle your data: Privacy policy

One email when early access opens. That's the lot. No newsletter, nobody else gets your details, and you can ask us to delete them whenever you like.

Questions

Talk to us

Got a question about the permissions model, what the connector actually does on-premises, or what a pilot would involve? Send it over. A person reads these and a person replies.

How we handle your data: Privacy policy

We use what you send to answer you, and for nothing else. No newsletter, no marketing list.