Proxaradocs
Guides/Run the firm

Ending access

A leaver, a revoked consent, the off switch, and full teardown.

Updated August 2026

For whoever runs offboarding. Two endings happen in Microsoft, one is a console control, one is the closing run at the end of an evaluation or contract. Each says what it stops and what it does not.

1A leaver
2A revoked consent
3The connector off
4The firm leaves
Four ways access ends, and one honest limit.
1A leaver
The firm disables the account in Entra.
Microsoft refuses the next renewal. Proxara withdraws that person on its own.
That person: stopped
2A revoked consent
An administrator revokes the application in Enterprise applications.
New Microsoft access stops for the whole firm, without asking Proxara.
Firm: no new access
3The connector off
A firm owner turns the connection off in Proxara.
Everyone is disconnected at once. Work already running cannot finish.
Firm: stopped now
4The firm leaves
The closing run stops every live authority, then closes the file.
The environment and its records stay in place, in the firm’s own account.
Custody: retained
One honest limit
Proxara does not call Microsoft again while a stored token is more than two minutes from its own expiry. A token Microsoft has already issued may still be honoured on Microsoft’s side until it expires.
That is why the Proxara-side stop runs alongside the Microsoft revocation, not instead of it. A read already sent cannot become a brief: the record it must update is gone.
One honest limit
The four ways access ends, and what each one stops

A leaver

Disable the account in Entra. That is the whole step: at the leaver's next request Proxara erases their credentials, tokens, stand-in mappings and their private workspace.

What it does not stop. The withdrawal lands on next use, not on disabling, and the record of their work stays.

In the Entra admin center, an administrator revokes the application's permissions, disables its sign-in, or deletes its service principal. Each stops new Microsoft access firm-wide without asking Proxara.

What it does not stop. Nothing in Proxara watches for it, so the console reads live until the next request fails.

The connector turned off

One console control, for a firm owner only, stops the whole firm at once: grants revoked, credentials erased, tokens cancelled, stand-in mappings and private workspaces deleted rather than marked closed. Work already running cannot finish.

What it does not stop. The signed record, the assistant's registration and the firm's identity register remain. Only an owner restores it.

The end of an evaluation or contract

The closing run uses that same control, then reads the state back to confirm it stayed off. It closes the firm's file once every signed record is durably stored.

What it does not stop. It deletes nothing. Deleting or transferring the environment is a contractual step under the Data Processing Addendum, carried out by people.

Access is off when

The console shows the firm disconnected, and the next request from any assistant returns unavailable rather than reaching Microsoft.

What ends, what is retained, and the one mechanical caveat

Each class has its own expiry and method of erasure, and the firm owns all of them.

ClassEnds
Retrieved material and working copiesWith the work, or at its retention limit
The private workspace and its clear valuesAt expiry, or at once on revocation
Stand-in mappingsAt the work, purpose or destination boundary, by cryptographic erasure
Effect and verification historyUnder the firm's retention class for effects
Signed activity recordWrite once, under its own locked retention class

Mappings are durable and encrypted rather than memory-only, because binding, recovery, verification and repair depend on them.

Revoking on the Microsoft side stops new tokens being issued; how long Microsoft honours one already issued is Microsoft's timing, not Proxara's. The owner's switch takes effect immediately, so run both.

Next: The console, where the off switch lives, or the evaluation.