Avvi help and answers
Answers for MSP administrators running Avvi, grouped by topic. Each answer links to the full guide with steps and verification.
Getting started
What is Avvi and what can it do?
Avvi lets an MSP run Microsoft 365 administration in plain English across every client tenant through GDAP, with approval controls and a full audit trail on every action. Read the full article
How do I connect a client tenant to Avvi?
You add a client’s Microsoft 365 tenant by starting a connection in Avvi, then having a Global Administrator in that tenant grant admin consent so Avvi can act through GDAP. Read the full article
How do I grant admin consent for a client tenant?
A Global Administrator in the client tenant opens Avvi’s admin-consent request, reviews the requested permissions, and grants consent so Avvi’s application can operate in that tenant. Read the full article
How do I invite my team and set their permissions?
An MSP Master Admin invites technicians as MSP Admins, gates access with an Entra security group, and sets per-feature toggles so each technician sees only the tenants and actions they should. Read the full article
Consent and permissions
How do GDAP and admin consent work in Avvi?
GDAP delegates time-bound Entra roles to your technicians, while admin consent authorises Avvi’s application to call Microsoft 365 APIs in a tenant. Both are separate and both are required. Read the full article
Why does admin consent fail with an AADSTS error?
Admin consent fails most often because a non-admin tried to consent, a required service or app service principal is missing, or the tenant is only partially consented. A Global Administrator re-running tenant-wide admin consent resolves most cases. Read the full article
Why is a feature missing from my Avvi portal?
A missing feature or tenant is almost always a permission gap: your MSP Admin role is not in the mapped security group, a feature toggle is off, or the tenant’s GDAP roles or consent do not cover that action. Read the full article
What happens when GDAP or role permissions change?
When GDAP roles, security-group membership, feature toggles, or admin consent change, Avvi’s access changes with them, and a technician usually has to sign in again before the new scope takes effect. Read the full article
Using AI chat
How should I phrase requests so Avvi acts accurately?
Name the client tenant, identify the user by their full email or user principal name, and state the exact outcome you want, then review Avvi’s restatement before confirming. Read the full article
Why does Avvi ask me to confirm before making a change?
Avvi requires explicit confirmation before any action that creates, changes, disables, or deletes something, so nothing runs unattended. Read-only requests run without a confirmation step. Read the full article
What do I do when Avvi cannot complete a task?
When Avvi cannot complete a task it is usually a permission or consent gap, an action outside its supported scope, an unresolved request, or a Microsoft-side error. The chat message names which, and the fix follows from there. Read the full article
How do I read the audit history of Avvi’s actions?
Open the history for an Avvi action to see the original request, the exact action Avvi took, the tenant and object it affected, who approved it, the time, and the result. Read the full article
Account and security
Why did my Avvi session time out, and how do I sign back in?
Avvi sessions expire after a period of inactivity as a security measure. When prompted, sign in again through Microsoft and complete multi-factor authentication to resume where you left off. Read the full article
How does tenant isolation keep client data separate?
Avvi keeps every client tenant’s data separate: actions and data never cross between one client tenant and another, or between one MSP and another, and each action runs in the scope of a single named tenant. Read the full article
Where do I find the audit trail?
The audit trail lives in the Avvi portal and records every action across your tenants with the person who ran it, the tenant and object affected, who approved it, the time, and the result. Filter it by tenant, user, and date. Read the full article
Cannot find your answer
Browse the full help center, or contact support and a person will pick it up.
✦
Ask Avvi
Support assistant