Features & Overview
Tenant Launcher is a tool for managed service providers who administer Microsoft 365 for many customers. It opens each client's admin centers in a completely isolated browser session, so a technician can move between dozens of tenants without signing out, and without the risk of making a change in the wrong one. This page walks through how it works and every feature it includes.
The problem it solves
A single browser can only hold one active Microsoft 365 login at a time. For an MSP technician who manages Microsoft 365 for many customers, that means a constant cycle of signing out of one tenant and back into another throughout the day. It's slow, and it introduces a real risk: making an administrative change while signed in to the wrong customer's tenant.
Tenant Launcher removes that cycle. Each customer gets its own isolated session — its own cookies and its own login — so multiple tenants can be open at the same time, side by side, each one clearly labeled and impossible to confuse with another.
How it works
Enter a display name and the client's SharePoint slug. Optionally add a link to their password vault entry.
Each client card has buttons for the Microsoft 365, Exchange, Entra, and SharePoint admin centers.
The portal opens in that client's own session — its own cookies, its own Microsoft login, separate from every other tenant.
Sign in to Microsoft once per client. The session persists, so the next launch drops you straight into the right tenant.
Core features
Every client runs in its own isolated session. Logins, cookies, and tokens never cross between tenants, so two clients can be open at once without interfering with each other.
Open the Microsoft 365 admin center, Exchange admin center, Microsoft Entra, or SharePoint admin center for any client directly from its card — no bookmarks, no typing URLs.
Attach a link to each client's password vault entry, such as an IT Glue record, so the right credentials are one tap away when you launch a portal.
Each client is assigned a color that carries through to its session, making it immediately obvious which tenant a given window belongs to.
When you sign in, your client list syncs to your account, so the same tenants are available whether you're on your desk workstation or a laptop.
Bring an existing client list in from a backup file, or export your list to move it between machines and keep an offline copy.
For teams
The Enterprise plan is built for MSPs with more than one technician. Instead of sharing a single login, each team member gets their own seat, and every portal they open is recorded in a central activity log that the account owner can review.
Add technicians to your account by email address. Each person receives a secure link and sets their own password — you never share or distribute a common login.
Enterprise is priced per seat, and the per-seat rate decreases as your team grows. Add or remove seats as your staffing changes.
Every portal access is logged with the technician's account, the client tenant, the portal type, and a timestamp. The log is filterable and exportable to CSV for compliance and internal review.
Manage members from one dashboard. Removing a technician frees their seat immediately and revokes their team access.
Where it runs
The Firefox extension delivers per-client isolation using Firefox's native Multi-Account Containers. Each client is mapped to its own container, so its Microsoft 365 sessions are walled off from every other tenant at the browser level. It installs from Firefox Add-ons and lives in your toolbar.
For technicians who work in Chrome or Edge, a desktop application is on the way. It provides the same per-client isolation using a separate browser profile for each tenant, along with the same client list, portal buttons, and vault links. The desktop app shares your account, so your clients and team stay in sync across both.
Security & privacy
Tenant Launcher never stores your Microsoft passwords, access tokens, or anything from inside a customer's tenant. Microsoft sessions stay in your browser. The only data kept on the account is what's needed to run it: your account email, your synced client list (names, SharePoint slugs, and optional vault links), your subscription status, and — for Enterprise teams — the portal activity log described above.
For a full breakdown of what is and isn't collected, and how sessions are isolated, see the security page and the privacy policy.
Who it's for
Free for your first three tenants. No card required, about a minute to set up.
Get started freeFirefox extension available now · Desktop app for Chrome & Edge coming soon