Skip to main content

Privacy Mode and report transparency

The Zation FinOps Platform analyses Microsoft 365 usage per user, so it necessarily processes personal data: display name, user principal name (UPN), job title, department, and usage counters. Privacy Mode lets you replace that identity with a pseudonymous identifier across the Platform, and report transparency lets you choose per download how much identity a generated file carries.

This page describes what each control does, what it does not do, and where the boundaries are. Read it before you rely on either one in a data protection impact assessment.

Privacy Mode

Privacy Mode is a per-tenant setting with three states. Change it under platform.zation.io → Organization Settings → Privacy. Your Platform administrators can change it themselves; it does not require a request to Zation.

ModeWhat the Platform shows for a userTypical use
OffDisplay name. UPN and identifiers are available in the column picker.Default. Full transparency.
User IDZation User ID. Display name and UPN are removed.Works-council agreements or an internal policy against naming individual users.
AnonymizedZation User ID only. The Microsoft Entra ID object ID is removed as well.Strictest setting. Makes support cases harder to resolve.

The setting applies to the whole account. When it is on, every user of your organisation sees the pseudonymous identifier — administrators included. There is no per-user or per-role exception, and nobody on your side can switch it off for their own view.

A change needs no re-sync, no re-onboarding and no support ticket, and it applies to the data the Platform has already collected — not only to what it collects from that point on. Screens follow the new setting the next time they load; generated files are filtered on the server when they are built, so start a fresh download rather than reusing one that was already running.

Privacy Mode is pseudonymisation, not anonymisation

The Zation User ID is derived from your tenant's Microsoft Entra ID object ID, not from a one-way hash. Anyone holding a directory export of your own tenant can match a Zation User ID back to the user it belongs to, and Zation can resolve it internally for support. Under the Swiss revDSG and the GDPR this remains pseudonymised personal data. Treat the mode as an access control inside your organisation, not as a route out of scope.

Report transparency

The Microsoft 365 user export is generated by the Platform and downloaded as a CSV or XLSX file. Because the file leaves the Platform, you choose how much identity it carries. Three levels:

LevelIdentifier in the fileAlso includedRemoved
TransparentDisplay name, UPN, and Entra ID object IDEvery columnNothing
TechnicalEntra ID object IDLicences, cost, activity dates, usage counters, countryDisplay name, UPN, phone number, job title, job code, department, division, cost centre, office location
AnonymizedZation User IDThe same as TechnicalThe same as Technical, plus the Entra ID object ID

Technical and Anonymized remove more than the direct identifiers. Job title, department, and cost centre are removed as well, because the combination of those three is frequently unique in a single tenant and can be matched against your own HR list without any identifier from Zation. Leaving them in would make the level cosmetic.

What is deliberately kept at every level: all dates stay day-exact, and all measures — licence cost, storage, message and call counters — stay verbatim. Rounding them would break the 30/60/90-day inactivity thresholds and the cost figures the report exists for.

How the two controls interact

Privacy Mode sets a ceiling; the transparency level chooses within it.

Privacy ModeTransparentTechnicalAnonymized
OffAvailableAvailableAvailable
User IDBlockedAvailableAvailable
AnonymizedBlockedBlockedAvailable

The Platform hides the blocked options in the download dialog, but the block itself is applied server-side, when the file is built. A request that asks for more than the mode allows is lowered to the ceiling rather than refused, and the downgrade is written to the audit trail together with the level that was requested.

Why Anonymized mode also blocks the Technical level

The Technical level identifies each row by the Microsoft Entra ID object ID. Anonymized mode exists precisely to remove that identifier, so offering Technical there would hand back the value the mode was set to withhold.

If the Platform cannot read your tenant's privacy setting when you request an export, the download fails with an error rather than falling back to a more revealing level.

Archived monthly snapshots

Alongside the live export, the Platform archives one snapshot of the Microsoft 365 user data per calendar month and keeps it for twelve months. A snapshot is a point-in-time record of who held which licence at that month's sync, so it is written with the full column set whatever your Privacy Mode is at the time.

The download works in every mode. With Privacy Mode off, you get the file exactly as archived. With Privacy Mode on, the identifying columns are removed from the file as it is served, giving you the same shape as an Anonymized export: the Zation User ID plus every licence, cost, and activity column.

Two points specific to archives:

  • You cannot pick the transparency level per snapshot. An archive carries no Entra ID object ID, so the Technical level has no identifier to use there. Privacy Mode on always yields the Anonymized shape.
  • Snapshots archived before August 2026 predate the Zation User ID column. When Privacy Mode is on, those download without any per-row identifier — the licence and usage figures are intact, but two rows cannot be told apart. This cannot be repaired retroactively.

Enabling Privacy Mode filters what is served; it does not rewrite snapshots already stored. If you need those deleted rather than filtered, ask Zation — that is a manual request, not an effect of the setting.

What Privacy Mode controls, and what it does not

Privacy Mode governs who sees identity, not what the Platform stores. That distinction is deliberate, and it is what keeps the Platform useful while the mode is on.

The identity stays in the backend, by design. Licence optimisation is a per-user calculation: matching a licence to its holder's actual usage, recognising the same person across daily syncs, attributing cost to a cost centre, and keeping an audit record of who held which licence when. All of that needs a stable, real identity. If Privacy Mode deleted or overwrote it, the recommendations, the sync, and the audit trail would stop working — and turning the mode off again would not bring them back. So the identity is retained and the presentation of it is restricted, which is also why switching the mode is fully reversible in both directions and needs nothing rebuilt.

Files the Platform generates are filtered before they are built. The Microsoft 365 user export never contains identity that your mode and the chosen transparency level exclude. The filtering happens on the server, so there is no step in the browser that could be bypassed or skipped.

Screen masking is applied in the browser

For the Platform's on-screen tables, the restriction is applied in the browser: the API response that feeds a table still carries display name and UPN in every mode, and the row key itself is derived from the UPN — for the reason described above, since the same values drive the calculation behind the table.

What this means for your assessment: a person who can already sign in to the Platform for your tenant can read those values using their browser's developer tools, even while Privacy Mode is on. Every such person is someone you have already granted Platform access to, inside your own tenant's access boundary.

Privacy Mode is therefore an account-wide rule about how your organisation works with the data — it takes individual users out of the picture for everyone on your side at once, which is the works-council and internal-policy case it was built for. It is not a technical barrier against someone you have already authorised.

The ceiling applies to everyone. The transparency ceiling your Privacy Mode sets is applied when the file is built, for every account that requests one. There is no role that generates a more revealing export than your mode permits.

Every export is audited. The audit trail records who downloaded what, when, at which transparency level, which level was originally requested, and whether it was lowered. Audit records cannot be deleted.

Not the same as Microsoft's concealed user names

Microsoft 365 has its own tenant setting, Display concealed user names in reports. The two are unrelated and are owned by different parties:

Zation Privacy ModeMicrosoft concealed user names
Owned byYou, inside the PlatformYour Microsoft 365 tenant administrator
ScopeThe Platform's screens and filesMicrosoft Graph usage reports
Effect on adoption dataNoneUsage cannot be matched to users — all adoption figures read zero

If Microsoft's setting is on, the Platform detects it and shows a banner asking your administrator to turn it off. Turning on Zation's Privacy Mode is not a substitute, and turning off Microsoft's setting does not weaken Privacy Mode.