Getting Started
This page is for someone who already has access to a running CET2 instance and wants to start using it. If you're setting up a new CET2 deployment, go to the Deployment Guide instead.
Signing in
- Go to your CET2 portal URL (e.g.
https://portal.clefsoft.co.uk). - Sign in with your Microsoft Entra ID account.
- MSP staff sign in with their home-tenant account and, once assigned a role, can reach every onboarded customer tenant they're scoped to.
- Customer administrators sign in with their own organisation's account. The first sign-in triggers a one-time consent prompt for the CET2 application.
- If you see "Your access hasn't been set up yet", you're authenticated but have no role assignment yet — ask your MSP/IT provider to grant you access (see RBAC).
Finding your way around
| Area | What it shows |
|---|---|
| Dashboard | Tenant-level summary: device counts, compliance state, recent activity |
| User search | Search a tenant's users; jump straight to their assigned devices |
| Devices | Full managed-device list with compliance, encryption, and last check-in |
| Apps | The Intune application catalog and install-status reporting |
| Findings | Security/compliance posture checks, with failing-device drill-down |
| Intune dashboard | Ring/donut breakdowns by compliance, OS, and configuration state |
| Autopilot | Autopilot-registered device identities |
| Windows Updates | Update ring/policy status across the tenant |
| Expiry Alerts | Apple Push (APNs) certificate, VPP, and DEP/ABM token expiries |
| Access Control | (Admins) manage RBAC role assignments |
Taking an action
Actions (device sync, retire, wipe; user disable/enable, revoke sessions, reset access) appear as icon buttons on the relevant detail page, and only when your role grants the permission for that action.
- Click the action icon. A confirmation dialog opens.
- Enter a reason — every action requires a business justification, which is permanently recorded.
- For destructive actions (disable user, retire/wipe device), type the target's name to confirm.
- Confirm. If the action requires a fresh sign-in (step-up), you'll be redirected to re-authenticate and the action completes automatically when you return.
- The outcome appears as a banner, and a row is added to the target's Action history.
Next steps
- Understand how access is controlled: RBAC
- See the full list of supported Graph-backed features: Architecture Overview
- Deploying a new instance or onboarding a new customer tenant: Deployment Guide