Integrations
Connect Microsoft 365 to bring identities, devices, software vulnerabilities and configuration posture into the platform: where to set it up, what a sync produces, and what removing a connection clears.
Integrations is where an admin connects your organisation's cloud and identity platforms. Once a connection is in place, its identities, devices and software vulnerabilities arrive as assets and findings, and its configuration checks feed Exposure, Compliance and Actions without anyone re-keying them.
Open it from Settings → Integrations. The Cloud connectors card shows one tile per provider. Microsoft 365 is available today; the other tiles are marked Coming soon.
Admins, main project
Only an organisation admin can manage connections. A connection belongs to the whole organisation, and what it collects lives in the main project, so its configuration results are viewed from the main project.
Connect Microsoft 365
- On the Microsoft 365 tile, choose Connect.
- A Microsoft administrator for your tenant approves read-only access once, in the consent window that opens.
- The tile shows the connection as authorised, and the first sync starts.
If your organisation prefers to register its own application instead, choose Configure, switch the authentication method, and enter that application's details. They're checked before they're saved, and the secret is never shown again once stored.
The connection only reads: nothing in your tenant is changed by a sync.
What a sync brings in
- Assets: the identities and devices in your tenant, with a device seen by more than one Microsoft source merged into a single asset.
- Software vulnerabilities: grouped by the software that causes them, with one finding per affected device. When a later sync no longer reports one, its finding is marked resolved; if it comes back, the finding reopens.
- Configuration posture: each check's pass or fail result, under Exposure → Configuration, mapped to the requirements it bears on. Choose View posture on the tile to go straight there.
- Remediation proposals: a failing check becomes one proposal under Actions for a person to approve. Once the check passes again, its action closes on its own.
- Compliance evidence: a failing check is attached to the requirements it affects, so the gap shows up where you assess it. See Gather evidence.
Keep it current
Each connection syncs automatically on a schedule. Choose Sync now on the tile, or on the Configuration page, to run one immediately. The tile shows when it last synced, and the reason if the last sync failed; Sync now stays available so you can try again once the cause is fixed.
You can also be emailed about what a connection finds, such as licences assigned beyond your entitlement or seats nobody uses. See Notifications.
Remove a connection
Choose Configure → Remove connection and confirm. Removing a connection:
- deletes its configuration posture results;
- withdraws the proposals it raised that are still pending, and cancels its open actions;
- marks its open findings resolved, while the assets and completed actions stay;
- keeps the evidence it produced as expired history, so past assessments still show what it supported.
Connecting again later rebuilds the posture results from a fresh sync. The removal is recorded in the audit log.
Preferences
Preferences: organisation profile, review cadence, document variables and scan modules, the dial on the whole loop, set once and revisited as things run.
Users and access
Add people, choose their role per project, approve people waiting to join, work with guests from other organisations, and remove or restore an account.