An IT administrator reviews a dashboard monitoring Microsoft 365 services and cloud access in an office.
Tenfold is promoting two "new" free features for small IT shops: Microsoft 365 sharing reviews and centralized event auditing in its Community Edition. Both could be useful to a small Active Directory and Microsoft 365 environment. But the announcement is vendor marketing, both features have been in tenfold's platform for months, and the free edition has limits worth reading before you put it on a Docker host.

What tenfold announced​

On October 5, tenfold published a post on BleepingComputer listing two additions to its free Community Edition (CE). SC Media covered the post the next day. BleepingComputer labels the page "Sponsored and written by tenfold Software." That makes it paid vendor content, not independent reporting. The vendor says it has added shared content governance and real-time event auditing to its free Community Edition for organizations with under 150 users, and that the new features help teams manage Microsoft 365 sharing and investigate suspicious identity activity.

The two features:

  • Shared content governance for Microsoft 365. A central view of files shared across Teams, OneDrive and SharePoint. Tenfold says this covers SharePoint sites, Teams channels, one-on-one chats and files shared from users' OneDrives. Recurring access reviews then ask the owners of those files, channels or sites to check who still has access. Each reviewer gets a personal dashboard listing the items in scope and can confirm or revoke access.
  • Event auditing. Tenfold says this ingests and analyzes event logs, stores the event types you choose in its own database, and lets you filter by user, system or event type. Admins can save and share queries. The vendor's examples of suspicious activity are login spikes and newly created admin accounts.

Summary: One feature reviews who has access to shared Microsoft 365 files. The other is a searchable store of identity events. Every description of how they work comes from tenfold.

How new are these features?​

Not very. Tenfold's own blog lists a post called "Access Reviews for Shared Content" dated October 31, 2025, and an announcement of its auditing and log-analysis feature dated November 24, 2025. Its March 30, 2026 release notes for version 26.0 say event auditing gained more than 20 event types covering password changes, Group Policy and Kerberos authentication, plus saved and shareable queries.

Tenfold also says CE gets updates at the same time as its paid editions. Its Community Edition page says the edition is included in the normal update cycle and receives patches and new features at the same time as other editions, with no delay between regular and free users. If that's accurate, CE users have probably had at least early versions of both features for some time. The October post looks more like a reminder campaign than a product launch. That doesn't make the features worse, but "just got 2 new features" deserves some skepticism.

The Community Edition: what you get and what you don't​

Tenfold launched CE about a year ago. At the time, The Register's partner content described it as a free, full-featured version of its IGA solution for organizations with under 150 users. The vendor's product page says it can be used to manage up to 150 users and, aside from that restriction, includes all of tenfold's features and integrations, on par with the Enterprise Edition. The page lists automated on- and offboarding, self-service requests and password resets, privilege audits, role-based access control, and centralized permission governance for AD, file servers, M365, Exchange and more.

The limits are what deserve your attention:

ConstraintWhat it means in practice
150 managed users, counting admin and service accountsService accounts, break-glass admins and shared mailboxes with user objects can push a "120-person company" over the cap
No exclusions during setupTenfold says since you cannot exclude objects or OUs during setup, the Community Edition will not work in environments with more than 150 users. You can't scope it to one department of a bigger organization
Over the limit?Tenfold points those organizations that exceed this limit to a 30-day trial of its paid product instead
No upgrade pathPer tenfold's CE page, CE can't be upgraded to a paid edition. If you outgrow it, plan on a new deployment
Deployment modelDelivered as a Docker image you run yourself. It needs an internet connection so tenfold can check the identity count
Requesting itA business email tied to a named person. Personal and shared inboxes aren't accepted
SupportVideo tutorials and a community subreddit. Tenfold publishes no support commitments for CE

Summary: CE is free for good if you stay under 150 identities, but that count includes every non-human account. If you outgrow it, you start over rather than upgrade.

The event-auditing caveat Entra shops need to know​

Tenfold's October post lists Active Directory and Microsoft Entra ID integrations as part of the quick setup. A reader could easily assume event auditing covers Entra sign-ins too. It doesn't yet, by tenfold's own account. In a sponsored BleepingComputer article dated September 29, 2026, the vendor said event monitoring covered Windows and Active Directory events, and that Entra ID support and automated alerting were coming in future releases.

That has three practical consequences:

  1. Cloud-only or cloud-heavy tenants gain little. If your identity threats are mostly Entra sign-ins, password spray against Microsoft 365, or risky OAuth consents, this feature doesn't see them yet.
  2. There are no automated alerts. Tenfold mentions "real-time" ingestion, but by its own account it doesn't send alerts yet. Someone has to run the queries. A login spike nobody looks at is just a nicely formatted log entry.
  3. It isn't a SIEM. Tenfold describes collecting, enriching and querying Windows and AD events. It doesn't describe detection rules, retention guarantees or response automation. Treat it as a more convenient way to search domain controller logs, not as a replacement for monitoring tools.

Tenfold's September article does describe some useful details. It says session IDs are resolved to show which user made a change, and multi-step events, such as creating and then renaming a security group, are merged into a single entry. Anyone who has scrolled through raw Security log entries will see the appeal. Whether it works well in your environment is something to test, not take from a sponsored post.

Where this fits next to Microsoft's own tools​

In a separate September 2026 sponsored piece, tenfold argued that Microsoft 365's built-in sharing reports are hard to act on. It described SharePoint Advanced Management's sharing-link report as showing only the sites with the most new links in the past 28 days. It described site-level sharing reports as CSV exports that take a long time to run tenant-wide. That's a vendor criticizing a platform it sells add-ons for, so weigh it accordingly. The underlying problem is real, though: shared links and channel memberships tend to outlive the projects they were created for.

Tenfold's approach is to send reviews to the person who shared the content, not to IT. That makes sense, because the file owner is usually the only one who knows whether a departed freelancer still needs the project folder. But the vendor's announcement leaves out details a careful admin will want before deploying:

  • Which sharing-link types and external-guest scenarios are covered
  • What Microsoft 365 permissions the app needs in your tenant
  • Whether revocation happens right away or is queued
  • How reviews are scheduled and escalated when an owner ignores them

Should a small IT team try it?​

The case for trying it is real. Identity governance has long been priced and built for large enterprises, and a free tool that brings role-based provisioning, access reviews and Microsoft 365 sharing reviews to a small AD and M365 shop fills a real gap. If you're doing quarterly access reviews in a spreadsheet, almost anything is better.

Go in with a plan:

  1. Count every identity first. Include service accounts, admin accounts and stale objects. If you're near 150, clean up AD before you request CE.
  2. Treat the Docker host as sensitive infrastructure. An IGA tool can change group memberships and permissions. Lock down the host's access, patching and backups accordingly.
  3. Pilot shared-content reviews with one team. Check that revocations behave as expected before rolling reviews out to non-technical file owners.
  4. Don't rely on event auditing for cloud threats. Until Entra ID coverage and alerting arrive, keep your existing Entra sign-in monitoring in place.
  5. Plan your exit. With no upgrade path, growing past 150 identities means a new deployment, not a license change.

Bottom line: Tenfold's free edition looks like a capable governance option for very small Windows and Microsoft 365 environments. But the "new" features have existed in the platform since late 2025, event auditing currently covers only Windows and Active Directory, and the 150-identity cap is strict, with no upgrade path. Treat it as a tool to evaluate, not one to adopt on the strength of a sponsored post.

 

References

  1. Tenfold Community Edition adds new features for small organizations - SC Media SC Media 2026-10-06T14:20:53+00:00
  2. Secure enterprise sharing with access reviews for Microsoft 365 bleepingcomputer.com
  3. tenfold CE: Our free Identity Governance tool just got 2 new features bleepingcomputer.com