Built with PII lifecycle and access control in mind from day one.
As a contact management and distribution platform, everything below reflects how contact data moves, where it lives, and what happens when someone's access changes.
Sign in with your existing Microsoft account
The admin portal uses Microsoft's own sign-in (MSAL) — anyone with the right permission signs in with the Microsoft 365 account they already have. No separate username or password to create, remember, or store on our end. This applies to portal access only — the credentials used to connect devices work differently, through a separate deployed profile or manual passphrase.
Two ways in, one standard of security
For company-managed devices, iSync365 can deploy a configuration profile the same way most enterprise tools do — the credential itself is never visible to the end user. For personal or unmanaged devices, setup is manual: an admin provides a secure passphrase, and can regenerate it at any time, instantly invalidating the old one.
Where your contact data actually lives
On Outlook, contacts are written directly into each person's own mailbox inside your organization's Microsoft 365 tenant. On mobile, iSync365 uses a dedicated, company-provisioned CardDAV account for every device — never an account tied to anyone's personal cloud service. Your data remains protected and under your control, not scattered across other people's personal accounts.
Removed immediately, no exceptions
Whether someone's unassigned from a single list, or a whole list is deleted, iSync365 removes that data immediately. Nothing for your team to track down or double-check. The one honest caveat: a device only shows the change once its own server connection refreshes — a device-side interval outside our control — but the access itself is gone right away on our end, not held for a later scheduled run.
Built on modern standards, not a protocol being phased out
Many contact-sync tools rely on an older Microsoft protocol called Exchange ActiveSync (EAS) — one Microsoft itself is actively retiring: outdated EAS client versions lose access to Exchange Online starting March 2026, with legacy authentication being phased out entirely by the end of the year. Real security issues have also been documented in older EAS implementations along the way. iSync365 doesn't use EAS at all. Mobile devices connect through CardDAV, an open, modern standard, and Outlook sync runs through Microsoft's current Graph platform — both built around today's security practices, not a protocol on its way out.
Zero-touch on managed devices, still simple without MDM
Managed devices get zero-touch setup through a deployed profile. Unmanaged devices need a one-time manual entry instead — but unlike the typical fallback for devices without MDM, there's no Microsoft sign-in prompt to get through and no third-party app to install.
What about contacts already floating around in a spreadsheet?
A shared spreadsheet doesn't have a real access-control model — it's usually emailed as an attachment, forwarded, and copied, with no way to know who ended up with it or to pull it back once it's out. There's no per-person targeting, and no way to revoke access when someone leaves or changes roles. iSync365 treats list membership as a real, admin-controlled permission — access is granted and removed on purpose, not by whoever happened to get forwarded a file.
