Complete feature list

Everything Avvi can do, by asking

263 capabilities across Microsoft 365, Entra ID, Intune, and on-premises Windows. Each one runs from a plain-English request in chat — no admin console, and inside the permissions your organization has granted that person in Avvi.

263 capabilities 113 confirmation-gated 128 read-only 29 categories

No capability matches that. Try a broader word, or ask us.

Mailbox Access & Delegation 5

  • Grant a user Full Access to another mailbox (with or without Send As)
  • Remove/revoke mailbox access
  • View who has permissions on a given mailbox
  • View which mailboxes a given user has been delegated access to
  • Interactive permission-type picker (Full Access / +Send As / +Send on Behalf / All) when a request is ambiguous

Send As / Send on Behalf Permissions 6

  • Grant Send As permission on a mailbox
  • Revoke Send As permission
  • Grant Send on Behalf permission
  • Revoke Send on Behalf permission
  • View current Send As permissions on a mailbox
  • View current Send on Behalf permissions on a mailbox

Email Forwarding & Out-of-Office 6

  • Set email forwarding rules on a mailbox (with or without keeping a copy)
  • Remove email forwarding
  • Check current forwarding status/configuration
  • Set an out-of-office / automatic-reply message
  • Remove an out-of-office message
  • Check current out-of-office status

Inbox Rules & Mail Hygiene 5

  • List a user’s inbox rules
  • Disable a suspicious or unwanted inbox rule
  • Delete an inbox rule
  • View mailbox statistics (size, item count, quota)
  • View mailbox usage over time

Mailbox Lifecycle Management 10

  • Create a shared mailbox
  • Delete a shared mailbox
  • Convert a shared mailbox to a regular user mailbox
  • Convert a user mailbox to a shared mailbox
  • Reassign an email address from one mailbox to another
  • Add an email alias to a mailbox
  • Remove an email alias
  • List all mailboxes the current user can manage
  • Search/filter mailboxes by name or email
  • Get detailed configuration/settings for a specific mailbox

Message Tracing & Delivery Diagnostics 2

  • Trace email delivery across the tenant (sender/recipient/date filters) — diagnoses “did my email actually send?” issues
  • Get full delivery detail/timeline for a specific traced message

Quarantine & Spam Management 4

  • Search quarantined messages (by sender, recipient, date, or reason)
  • Get full detail on a specific quarantined message
  • Release a quarantined message (individually or in bulk)
  • Add a sender to the tenant’s safe-sender/allow list

Directory & Recipient Lookup 3

  • Search users across the tenant by name/email
  • Resolve an ambiguous name/email to the correct recipient
  • Look up general tenant/user information

User Lifecycle Management 15

  • Create a new user (with license/group assignment)
  • Onboard a user (full new-hire setup workflow)
  • Offboard a user (full departure workflow: disable, revoke access, convert mailbox, etc.)
  • Enable a user account
  • Disable a user account
  • Update a user’s profile fields (title, department, phone, office, etc.)
  • Clone an existing user’s settings (groups, licenses) onto a new account
  • Invite a guest/external user
  • Set or update a user’s manager
  • Request/upload a user’s profile photo
  • Delete a user’s profile photo
  • View a user’s group memberships
  • Remove a user from all groups (offboarding helper)
  • Get a user’s full profile (job title, department, account status, creation date — *declarative Graph tool*)
  • View a user’s manager and direct reports (org chart lookup — *declarative Graph tools*)

Passwords, MFA & Account Security 9

  • Reset a user’s password
  • Check a user’s MFA (multi-factor authentication) status
  • Bulk MFA status check across all users in the tenant
  • Reset/clear a user’s MFA registration
  • Unlock a locked-out user account
  • Create a Temporary Access Pass (TAP) for passwordless/MFA-free sign-in
  • Delete a Temporary Access Pass
  • Check when a user’s password was last changed
  • View a user’s registered authentication methods (password, phone, FIDO2 keys, Authenticator app, etc. — *declarative Graph tool*)

Licensing — Microsoft 365 Direct 7

  • Query available license SKUs in the tenant
  • View a user’s assigned licenses
  • View all licensed users
  • Batch-lookup licenses for multiple users
  • Check license seat availability before assigning
  • Assign a license to a user
  • Remove a license from a user

Licensing — Pax8 / CSP Purchasing 11

  • View available licensing channels (direct Microsoft vs. CSP/Pax8)
  • Search the Pax8 product catalog
  • List Pax8-connected companies/tenants
  • List current Pax8 subscriptions and costs
  • Purchase a new Microsoft 365 / SaaS subscription through Pax8
  • Increase or reduce subscription seat counts on an existing Pax8 subscription (single unified action)
  • Cancel an active Pax8 subscription
  • Add license seats (direct-channel equivalent)
  • Reduce license seats (direct-channel equivalent)
  • Built-in spend-guard controls and per-order approval thresholds to prevent runaway purchases
  • Automatic license-propagation tracking after a seat purchase (detects and reports Microsoft-side assignment delays)

Security Groups 8

  • List all security groups
  • Get details on a specific security group
  • Create a security group
  • Update a security group’s name/description
  • Delete a security group
  • List members of a security group
  • Add a member to a security group
  • Remove a member from a security group

Distribution Lists, Contacts & M365 Groups 13

  • Create a distribution list
  • Create a Microsoft 365 Group
  • Create a mail contact
  • Create an external contact
  • Update a distribution list
  • Delete a distribution list
  • Add a member to a distribution list
  • Remove a member from a distribution list
  • View a distribution list’s members
  • View a distribution list’s owners
  • Get a distribution list’s details
  • List all distribution lists in the tenant
  • View group ownership across all group types, and which groups a user owns

Microsoft Teams Management 11

  • List all Teams in the tenant
  • List members of a Team
  • Add a member to a Team
  • Remove a member from a Team
  • List channels within a Team
  • Create a Team channel
  • Delete a Team channel
  • Create a new Team
  • Archive a Team
  • Unarchive a Team
  • Get a user’s real-time Teams presence (Available / Busy / In a Meeting / Offline, etc. — *declarative Graph tool*)

Device Management (Intune) & Endpoint Security 10

  • List all Intune-managed devices for a user
  • Check a device’s compliance status
  • Sync a device (force policy check-in)
  • Remotely restart a device
  • Remotely lock a device
  • Retire a device (remove company data, keep personal data)
  • Remotely wipe a device (full factory reset)
  • Retrieve a device’s BitLocker recovery key
  • Get Local Administrator Password Solution (LAPS) password for a device
  • List all LAPS-managed devices in the tenant

Tenant Security Investigations & Threat Detection 13

  • Run a full, automated tenant-wide security investigation on a specific user (sign-ins, risk state, inbox rules, forwarding, mailbox permissions, message trace, directory audit — one command instead of a dozen manual lookups)
  • Run a map-reduce security investigation across every user in the tenant simultaneously (two-phase triage: cheap signals score every account, then deep-dive only on flagged accounts)
  • Scan the entire tenant for suspicious sign-in activity
  • Get bulk risky-user status across the tenant
  • View individual risk detections and threat indicators
  • Dismiss a confirmed-safe user risk flag
  • Search sign-in logs by IP address
  • Get failed sign-in attempts for a user
  • Search the tenant’s directory audit logs
  • Audit mailbox send events (who sent what, on whose behalf)
  • Audit mailbox delegation changes (who was granted/removed access, and when)
  • Audit SharePoint external-sharing activity
  • List active Conditional Access policies and named locations, and inspect a specific policy’s configuration

SharePoint Management 7

  • List all SharePoint sites in the tenant
  • Browse files/folders within a SharePoint document library
  • Get details on a specific SharePoint site
  • View a SharePoint site’s permissions and membership
  • Add a member to a SharePoint site
  • Remove a member from a SharePoint site
  • Generate a SharePoint usage/activity report

OneDrive Management 19

  • View a user’s OneDrive storage usage
  • Generate a OneDrive usage report across users
  • View a user’s OneDrive activity report
  • Browse a user’s OneDrive folder structure
  • Search within a user’s OneDrive contents
  • List a user’s OneDrive recycle bin contents
  • Restore a deleted OneDrive file from the recycle bin
  • Copy a OneDrive file
  • View a file’s version history
  • Restore a previous file version
  • List a file’s current sharing permissions
  • Create a new file-sharing link
  • Grant direct file access to a specific person
  • Revoke an existing sharing link
  • List all externally shared files in a user’s OneDrive
  • List all files shared with a user
  • Add a OneDrive shortcut
  • Remove a OneDrive shortcut
  • Send a notification to a user about a file

Calendars, Contacts & Scheduling Assistant 9

  • List a user’s calendar events within a date range
  • List all of a user’s calendars (personal, shared, group)
  • View sharing permissions on a specific calendar (find out who has access to “the HR calendar,” etc.)
  • List a user’s Outlook contacts
  • Get mail tips for recipients before sending (out-of-office status, full mailbox, external-recipient warnings, etc.)
  • List all meeting/conference rooms in the organization (capacity, building, floor, equipment)
  • List room lists (rooms grouped by building/floor)
  • List Planner task-board plans for a Team/group
  • Get mailbox settings (timezone, working hours, language, auto-reply config) for a user

Directory, Governance & Admin-Role Visibility 16

  • Get a user’s full profile (title, department, phone, office, account status, creation date)
  • List a user’s direct reports and their manager (org-chart lookup)
  • Get tenant organization details (name, verified domains, technical info)
  • List all domains configured in the tenant, with verification status
  • List soft-deleted (recently removed) users — recoverable within 30 days
  • Restore a soft-deleted user
  • List soft-deleted Microsoft 365 Groups — recoverable within 30 days
  • Restore a soft-deleted group (recovers the group and all its content: Teams, SharePoint, mailbox)
  • List Azure AD app registrations in the tenant
  • List enterprise applications (installed service principals)
  • View the permission roles exposed by a specific enterprise application
  • View which users/groups/apps have been assigned roles on an enterprise application
  • List OAuth2 app-consent grants tenant-wide (shadow-IT / risky-app detection)
  • List all activated admin directory roles (Global Admin, Exchange Admin, etc.) and see who holds each one
  • List tenant-wide group settings (naming policy, guest-access policy, creation restrictions)
  • List devices a specific user owns in Azure AD (distinct from Intune-managed devices)

License Optimization & Stale Account Cleanup 4

  • Get a user’s last interactive/non-interactive sign-in timestamp
  • List users inactive for a specified number of days (e.g. “who hasn’t logged in for 90 days?”) — for license reclamation
  • List all guest/external users in the tenant (security audit of long-lived external access)
  • Get metadata on a user’s profile photo

Service Health, Message Center & Secure Score 8

  • Get Microsoft 365 service health overview across Exchange, Teams, SharePoint, Intune, etc. — answers “is Exchange down?”
  • List active/recent service health incidents with impact and classification
  • Get the full timeline/detail of a specific service health incident
  • List Message Center posts (upcoming changes, new features, deprecations) — proactive change management
  • Get full detail on a specific Message Center post
  • Get the tenant’s current Microsoft Secure Score
  • List Secure Score improvement recommendations, ranked by score impact and implementation cost
  • Get an Office 365 active-user activity report across all M365 services over a selectable period (7/30/90/180 days)

On-Premises Infrastructure — Avvi Connector 37

Everything in this section runs through the on-premises Avvi Connector, which extends Avvi from Microsoft 365 into local Active Directory and Windows hosts.

Server & workstation control

  • Remotely restart a server (with scheduled delay and optional end-user notification)
  • Remotely restart a workstation (with scheduled delay and optional end-user notification)
  • Multi-device coordinated restart scheduling
  • List all Avvi Connectors enrolled for a tenant, with status and enabled modules
  • Restart the connector’s own bound Windows host
  • Trigger an immediate connector self-update check
  • Uninstall the connector from a host entirely

On-prem Active Directory management (hybrid identity)

  • Unlock an on-prem AD user account
  • Enable / disable an on-prem AD user account
  • Reset an on-prem AD password (delivered via one-time-use secure link — never shown in plaintext)
  • Hybrid password reset: resets AD password with real-time progress tracking and one-time-click reveal delivery
  • Add/remove an on-prem AD user to/from an approved group
  • Create, rename, or delete an on-prem AD security group
  • Update approved AD user attributes (with automatic verification and rollback on any unexpected change)
  • Move a user to an approved Organizational Unit
  • Create a new on-prem AD user (naming-policy enforcement, uniqueness checks, automatic rollback on partial failure)
  • Full hybrid onboarding: create AD user, add groups, trigger Entra sync, confirm completion — one workflow
  • Full hybrid offboarding: disable AD account, sync disabled state to Microsoft 365, revoke all cloud sessions, optionally reclaim licenses
  • Full hybrid enable: re-enable an AD account and sync the enabled state to Microsoft 365
  • Discover AD domain structure (domains, domain controllers, OUs, groups) — powers the “sync from AD” setup wizard
  • Search on-prem AD groups by name
  • Push updated identity-sync configuration to the connector, with automatic connector restart
  • Trigger an on-demand Entra Connect delta sync cycle (rate-limited)
  • Check Entra Connect sync scheduler status and recent sync error count

End-user self-service & helpdesk (RDS sessions)

  • List active Remote Desktop (RDS) sessions on a host
  • Log off your own RDS session (self-service, rate-limited)
  • Log off another user’s RDS session (helpdesk, requires confirmation)
  • Find which RDS host a specific user is currently logged into

Workstation diagnostics & safe self-repair

  • Get real-time system diagnostics (CPU, RAM, disk, uptime, OS version)
  • Get network diagnostics (DNS resolution, gateway connectivity, active adapters)
  • List top running processes by memory usage
  • Pull recent Application/System event log errors and warnings
  • List pending Windows updates
  • Flush the local DNS cache
  • Restart an allow-listed Windows service (e.g. Print Spooler, Time Service, Search, Audio)
  • Clear temporary files to free disk space
  • Reset the network adapter (release/renew DHCP, reset Winsock/IP stack — no reboot required)

IP Intelligence & Support Utilities 3

  • Look up geolocation and ISP metadata for a public IP address (used during security investigations)
  • Contact Avvi support directly from chat
  • Check the status of a long-running background job

Scheduling Engine 4

  • Schedule any supported action to run at a future date/time (not just reboots — password resets, access grants, license changes, etc.)
  • List all scheduled tasks
  • Cancel a scheduled task
  • Schedule temporary access grants and their scheduled removal

AI Chat Interaction Framework 4

  • Interactive numbered-choice disambiguation (e.g., picking from multiple matching users/licenses)
  • Multi-step action planning for compound requests (“do X and Y and Z”)
  • Single-action and multi-action confirmation workflows (see Trust & Safety below)
  • Custom parameter-collection forms when a request needs structured input mid-conversation

Platform Administration & Compliance 12

Administrative capabilities of the platform itself, rather than actions run from chat.

  • 3-tier data isolation: SaaS Admin (Avvi platform) → MSP Organization → Client Tenant, enforced at database, API, and UI layers
  • 4-level role-based access control: Master Admin (full MSP access) → MSP Admin (configurable per-feature) → Tenant AI Admin (group-scoped) → Tenant AI User (individually toggled permissions)
  • Granular per-feature permission toggles for MSP admins (20+ categories: mailbox, licensing, security investigations, device management, SharePoint, Teams, service health, etc.)
  • Granular per-feature permission toggles for individual end users, disabled by default for new capabilities
  • Full audit trail on every action — who, what, when, where, why — with 7-year retention for compliance-relevant events
  • Session security: 1-hour idle timeout, 8-hour absolute session cap, admin-forced session termination
  • AI self-healing: automatic detection and recovery from transient tool/API failures without human intervention
  • AI incident intelligence dashboard: tracks failure patterns and proposes improvements to the AI’s own tool orchestration
  • Time-boxed, justified, fully audited support access grants for Avvi staff (SOC2 CC6.1/CC6.3 just-in-time access pattern)
  • Recurring Access Review cycles with per-item retention tracking — supports SOC 2 CC8.1 audit evidence
  • Change management and incident response evidence tracking — supports SOC 2 CC7.3/CC7.4 audit evidence
  • Multi-channel licensing support: direct Microsoft billing and CSP/Pax8 reseller billing, side by side

Every action is written to a full audit trail — who, what, when, and in which tenant. See security and trust for how tenant isolation, approvals, and least-privilege scoping work, or the platform overview for how this looks day to day.

We value your privacy

We use cookies to improve your experience, analyse traffic and measure our marketing. You can choose what to allow. Cookie Policy