User manual

Every feature of EasySwitch365 explained step by step – from the first customer session to the PowerShell commands that sign in right inside the customer tab. Last updated: June 2026 · Version 0.3.

1. What EasySwitch365 is

EasySwitch365 is the command center for Microsoft 365 for MSPs and IT administrators. Every customer (tenant) gets a fully separated browser session. You manage several customers in parallel, without constantly signing out and back in, and without sign-ins, cookies or tokens ever mixing.

The app has three areas:

2. System requirements

PlatformRequirement
WindowsWindows 10/11 (64-bit). PowerShell 7 is recommended for the PowerShell commands (installable from inside the app via winget at the click of a button). Windows PowerShell 5.1 is available as a fallback.
macOSmacOS 11+ (Apple Silicon, M1/M2/M3 …). PowerShell 7 is required for the PowerShell commands (installable from inside the app via Homebrew at the click of a button). Note: Apple Silicon only for now, no Intel build.

PowerShell is not needed for plain tenant management in the browser – only for the console commands.

3. Installation & activating your license

  1. Download the package (the link arrives with your purchase email) and install it (Windows: unzip and start EasySwitch365.exe · macOS: unzip and drag EasySwitch365.app to “Applications”).
  2. On first launch you are asked for your license key – enter it and click Activate.
  3. The license is activated for this device and then re-checked online at launch and regularly while you work. A brief offline period is bridged; if the connection is down for longer, the device is released, or the subscription is cancelled, the app locks. You can see the status anytime in the license menu (the “License” button at the bottom left).
No work data or customer data is transferred during this – only the license key and an anonymous device fingerprint.
Windows – first launch: The app is digitally signed (EV code-signing certificate from our partner “Conto IT”) and starts without any security warning. The verified publisher shown is “Conto IT”. If Windows still shows a SmartScreen notice in rare cases: “More info” → “Run anyway”.
macOS – first launch: The app is signed and notarized by Apple (verified developer “Conto IT”). It opens without any security warning – just drag EasySwitch365.app to “Applications” and start it. (Apple Silicon, macOS 11+.)

4. Adding & managing customers

Use “+ Add customer” (bottom left) to create a new isolated session. The dialog offers:

FieldMeaning
Display nameThe customer’s name in the list (e.g. “Contoso GmbH”).
Tenant domainThe customer’s verified tenant domain (e.g. company.onmicrosoft.com). Among other things it lets the cross-tenant guard compare against the actually connected tenant.
Real company domain (for AI, optional)Many admin accounts only have an .onmicrosoft address. Enter the real company domain here (e.g. mueller.com) – the AI assistant uses it for accurate e-mail addresses and PowerShell commands.
Start pageWhich portal loads when opening – Admin Center, Entra, Exchange, etc.
Custom URLOptionally a different start URL (e.g. a customer SharePoint).
Custom portals (optional)Any number of extra web portals per customer (label + URL) – e.g. phone system, time tracking, backup console or documentation. They later open with a single click inside the isolated customer session. Only the URLs are stored, no passwords.
Logo / letterUpload your own logo or use a coloured letter as a marker.

Edit & delete: Hover over an entry in the list – two icons appear on the right: “⋯” opens the edit dialog, the trash icon deletes the customer directly. The edit dialog also has a “Delete customer” button at the bottom left. When you delete – after a confirmation prompt – the associated isolated session is removed from the device too.

Collapse the bar: Use the arrow button (chevron) next to the logo to collapse the left customer bar into a slim icon rail – customers stay clickable as avatars, but you gain more room for the browser. Click again to expand; the state is remembered after a restart.

Pin & sort customers

When you hover over a customer, a small pin icon appears on the logo. Clicking it keeps the customer permanently at the top of the list – handy for the customers you work with most. You can also change the whole order by drag and drop.

Tip – control the session per customer: In the customer dialog you can tick “Don’t save sign-in” – then this customer’s browser session is not stored on the device (you sign in again each time). And via “Clear browser data” (in the edit dialog) you can remove a customer’s sign-in and browser data at any time. More under Security & privacy.

5. The workspace

Quick links (top toolbar)

One click takes you straight into the respective portal within the active customer session – no re-authentication:

ButtonOpensWhat for
Adminadmin.microsoft.comMicrosoft 365 Admin Center – users, licenses, billing.
Entraentra.microsoft.comEntra ID (Azure AD) – identities, groups, Conditional Access.
Exchangeadmin.exchange.microsoft.comExchange Admin Center – mailboxes, mail flow.
Defendersecurity.microsoft.comMicrosoft Defender / Security Center.
Intuneintune.microsoft.comDevice management & endpoint management.
Azureportal.azure.comAzure portal for cloud resources.

Custom portals (third-party)

Besides the Microsoft 365 quick links you can store your own web portals per customer – for example the phone system, time tracking, a backup console or the customer documentation. Use the “Portals ▾” button in the toolbar to open them with a single click inside the same isolated customer session: sign in once, stay signed in. If you are already on a page you want to keep, save it straight from the menu via “+ Save current page as portal”. You set up, rename, sort and delete the portals in the customer dialog under “Custom portals”. No passwords are stored – only the addresses; you stay signed in through the customer’s encapsulated session.

Tabs, address bar & navigation

Within a customer session you can open several tabs. The back/forward arrows and the reload icon work just like in a browser. If a portal opens a new window (e.g. “open in new tab”), it stays signed in within the same customer session.

Tenant indicator below the address bar

As soon as you work in a customer session, a slim bar right below the address bar permanently shows which tenant you are in: “Working in Customer · domain.com”. The bar is colour-coded in the customer’s colour. At a glance you always know which environment you are changing, and you never work in the wrong tenant by accident. The bar is intentionally slim and barely costs any space; on the start screen (no customer active) it is hidden.

Reset

The Reset button reloads the current customer session and signs it out (clears that customer’s cookies/tokens) – useful when a sign-in is “stuck”. Other customers are unaffected.

6. Session isolation – how it works

Each customer runs in its own session partition. Cookies, sign-in tokens and cached data of one customer are technically separated from all others – like separate browser profiles, only automatic.

7. The knowledge base

Via “Knowledge” (toolbar) you open a collection of ready-made PowerShell commands for the most common admin tasks – grouped by topic and searchable.

Placeholders are filled in automatically

The commands contain the placeholder {tenant}. It is automatically replaced with the active customer’s domain. Values in angle brackets – e.g. <user@domain> – you still have to replace with real addresses.

Use a command: insert or copy

Each card has two actions:

Commands that change or delete something are marked as Danger (e.g. remove permission, set forwarding, disable account). Review before running!

Save your own commands

Via the + in the knowledge base you create your own entries (topic, title, description, command). These are saved and appear alongside the bundled commands. You can use {tenant} in your own commands too.

Bundled categories

Exchange connection · Mailbox info · Permissions (Full Access, Send As, Send on Behalf) · Sent items into the shared mailbox · Create/convert shared mailbox · Forwarding & out-of-office · Message trace · Entra/identity via Microsoft Graph (reset password, disable account, user info) · Teams & Security/Compliance · Setup (install modules).

Pin & sort commands per customer

The star on a command card moves it into a “★ Pinned” section at the very top – and this is per customer. That lets you build an individually documented command set for specific customers. Reorder the pinned commands by drag and drop. AI-generated commands can be stored here permanently, too.

8. The built-in console

Via “Console” you open a PowerShell console at the bottom that belongs to the active customer session. It shows at the top which shell is running (“PowerShell 7” or “Windows PowerShell”).

Adjust the height

At the top edge of the console there is a drag handle. Use it to make the console larger or smaller – the browser area adjusts automatically. The height is remembered. (Same on Mac and Windows.)

The buttons

ButtonFunction
⚙ Set upInstalls the required PowerShell modules once (Exchange Online, Microsoft Graph, Teams) for the current user. On Windows the execution policy is set appropriately first.
⚡ Connect ExchangeSigns in to Exchange Online – via device code directly in the customer tab (see below).
⚡ GraphConnects to Microsoft Graph (Connect-MgGraph -UseDeviceCode).
⚡ TeamsConnects to Microsoft Teams (Connect-MicrosoftTeams -UseDeviceAuthentication).
ClearClears the console output.
RestartRestarts the shell (e.g. after PowerShell 7 was just installed – the console then runs as PowerShell 7).

Connection status

Once a service is actually connected, its button turns green and reads “connected” (the app checks the real connection state – no false green). A small × next to it disconnects again instantly. If the device code from a previous session is still valid, the app connects without a new code (“no code needed” note); otherwise the login tab opens for the code and closes automatically once you’re signed in.

Input & history

Type commands into the input line and confirm with Enter. Use / to scroll through previously entered commands.

Device code directly in the customer tab

This is the key feature: for the connect commands EasySwitch365 automatically adds the device-code switch and opens the Microsoft confirmation page in the active customer’s tab, with the code on the clipboard. This way the sign-in is tied to the right customer session – no external browser and no account mix-up.

A clean device code in the customer tab for Exchange requires PowerShell 7. If it’s missing, the app offers a button at the top to install it. Connect-MgGraph and Connect-MicrosoftTeams also work with Windows PowerShell 5.1.

Tenant safety: each console stays with its customer

Every customer console is fully separated – a sign-in in one customer cannot affect another. After each connect, EasySwitch365 reads the actually connected tenant (Graph, Exchange and Teams) and compares it with the customer’s stored domain:

Technical background: the Graph sign-in is isolated per console (-ContextScope Process), and any earlier sign-in is disconnected before each connect – so a cached token from another customer is never reused by accident.

✨ AI assistant: PowerShell from plain language

Via “✨ AI command” in the console bar you describe in plain language what you want to do – e.g. “create a shared mailbox support”. EasySwitch365 suggests the matching Microsoft 365 PowerShell command, already scoped to the active tenant, with a short explanation. For multi-step tasks the assistant thinks ahead and works step by step: first create the object, then (once it is ready) the follow-up – and it asks a focused question when needed (e.g. the country for a license).

Security is built in. The command is never run automatically – it only goes into the input line; you review it and press Enter yourself. Every suggestion carries a risk label (low / medium / high); for high risk the app asks again before inserting whether you really want to work in this customer’s tenant. You can save the suggestion to the knowledge base with one click (stored per customer).

For the suggestion, your free-text request is sent to an AI service – only the request and the tenant domain, no customer data and no sign-ins.

9. Microsoft services & when to connect to which

ServiceCommandWhat for day to day
Exchange OnlineConnect-ExchangeOnlineMailboxes, permissions (Full Access, Send As), shared mailboxes, mail flow, forwarding, message trace. The most common use case.
Microsoft GraphConnect-MgGraphCreate/disable users, passwords, assign licenses, groups, sign-in/audit logs, Conditional Access, Intune. Central and future-proof.
Microsoft TeamsConnect-MicrosoftTeamsTeams policies, telephony, meeting and room settings.
Security & ComplianceConnect-IPPSSessionContent searches (eDiscovery), retention, DLP. Same module as Exchange.
The former modules MSOnline and AzureAD are being retired by Microsoft – their tasks are taken over by Microsoft Graph. That is why EasySwitch365 relies on Graph.

10. How sign-in works under the hood (API)

Microsoft 365 management runs in the background over Microsoft’s official REST APIs – above all the Microsoft Graph API. The PowerShell modules (Microsoft.Graph, ExchangeOnlineManagement, MicrosoftTeams) are convenient “wrappers” around these APIs: a cmdlet such as Update-MgUser sends a Graph API call in the background.

The device code flow

  1. You click a connect command. PowerShell requests a short device code from Microsoft.
  2. EasySwitch365 opens the confirmation page microsoft.com/devicelogin in the active customer’s tab and puts the code on the clipboard.
  3. You confirm there with the right admin account. Because this happens in the customer tab, the sign-in is tied to that customer session.
  4. Microsoft issues PowerShell a time-limited access token. All following commands use this token until you run Disconnect-… or it expires.

Why this detour? A PowerShell token and a browser cookie are technically different. The device code is the official bridge so the console uses exactly the identity that matches the visible customer session – rather than some account signed in anywhere on the system.

11. Language & appearance

At the bottom left you choose the language (German, English, Spanish, French, Turkish, Arabic) and toggle between light and dark mode. Your choice is remembered.

12. Security & privacy

App lock (optional): You can lock EasySwitch365 with a PIN — on Mac also via Touch ID — including auto-lock after a configurable period of inactivity. Enable it via “App lock” in the sidebar; off by default. Handy because you stay permanently signed in to the tenants. Note: it is an access lock, not extra encryption — session data stays OS-encrypted.

More about this in the privacy policy.

Sign-in security & protection against token theft

Phishing-resistant sign-in: EasySwitch365 has no authentication of its own — you sign in through Microsoft’s real page inside the isolated session. If your tenant enforces FIDO2, a passkey or a security key, it applies here unchanged, exactly as in a browser.

Token theft: Signed-in sessions are OS-encrypted, isolated per customer and never exported. For maximum hardening we recommend Microsoft Entra Token Protection / Conditional Access (device-bound tokens) — a stolen token is then worthless on another device.

Per-customer session control

Don’t save sign-in: Enable it per customer in the customer dialog – the session is then kept in memory only and discarded when you quit the app. No sign-in token stays on the device; you sign in to this customer every time. Ideal for especially sensitive tenants.

Clear browser data: Via “Clear browser data” in the edit dialog (or “Reset” in the toolbar) you can delete all browser data of a single customer anytime – cookies, sign-in tokens, cache and local storage. The customer, its domain and your knowledge base stay intact; you are only signed out of that tenant.

Settings & moving to a new computer

At the bottom left, “⚙ Settings” opens a menu with App lock, License, Technical details & privacy and the Move your configuration section.

With Export you save your customer list and knowledge base to a file; with Import you bring them back on another computer (existing entries are kept, only the missing ones are added). Ideal when switching devices.

Important: No passwords and no sign-ins are stored – only customer names, domains, logos and your commands. Sessions are kept encrypted and device-bound by the operating system; on the new device you sign in to each tenant once. Release the license on the old device via the License menu and activate it on the new one.

Check the service status

At easyswitch365.com/status you can see the live status of all services (license server, auto-update, AI assistant, self-service portals and more) at any time – checked automatically every hour, with a 24-hour history. Handy if something acts up: a quick look shows whether a service is the cause.

13. Troubleshooting

“PowerShell 7 missing” / console runs as “Windows PowerShell”

A bar appears at the top of the console with “Install PowerShell 7”. On Windows this installs via winget, on Mac via Homebrew – right in the console. Then click Restart; a full app restart is not needed.

“Connect Exchange” reports a window-handle error

Occurs only in Windows PowerShell 5.1. Fix: install PowerShell 7 (button at the top) and click Restart – the sign-in then runs cleanly in the customer tab.

SmartScreen (Windows) or Gatekeeper (macOS) blocks the launch

Windows: The app is EV-signed and starts without a warning; in rare cases “More info” → “Run anyway”. macOS: The app is signed and notarized by Apple and opens without a warning – just drag it to “Applications” and start it.

A command says “… is not recognized”

The matching module is not installed yet – just click ⚙ Set up once.

Red warning: “connected to a foreign tenant”

Appears when the actually signed-in tenant does not match the current customer’s domain (e.g. you authenticated the device code in the wrong tenant). Disconnect (×) and reconnect in the correct customer. If the warning persists despite the right sign-in, check that the customer has the correct (verified) tenant domain stored.

Release your license & move to a new device

The license is tied to one device. When switching, you release your old device yourself – this also works if it’s no longer available (you only need access to your inbox):

  1. Open easyswitch365.com/switch-device and enter your purchase email.
  2. You’ll receive a confirmation link at exactly that address – click “Release device” inside it.
  3. Your old device is removed and the license seat is freed.
  4. Install EasySwitch365 on the new device and activate with your license key.

Still have questions? Write to us at [email protected].