Skip to main content

Microsoft 365 Integration

Connect your Microsoft 365 tenant to Securtea

Microsoft 365M365integrationGraph API

Microsoft 365 Integration

The Microsoft 365 integration is the foundation of Securtea. It connects to your M365 tenant via Microsoft Graph API to monitor security configurations and compliance.

Overview

What It Enables

With Microsoft 365 connected, you can:

  • Run compliance assessments
  • Monitor configuration drift
  • Backup M365 configurations
  • Track Secure Score
  • Collect compliance evidence

How It Works

Securtea connects via:

  1. Azure App Registration - Your application identity in Entra ID
  2. Microsoft Graph API - Microsoft's unified API
  3. Application Permissions - Read-only access to configurations

Connection Status

Viewing Connection

Go to Settings > Integrations > Microsoft 365:

FieldDescription
StatusConnected or not
Tenant IDYour M365 tenant
Client IDApp registration ID
Last SyncRecent data fetch
HealthConnection health

Health Indicators

StatusMeaning
ConnectedWorking normally
Authentication ErrorCredentials issue
Permission ErrorMissing permissions
Service ErrorMicrosoft service issue

Setup Requirements

Prerequisites

Before connecting:

  • Azure Portal access (admin)
  • Global Admin or Application Admin role
  • Your M365 tenant details

What You'll Create

The setup creates:

  • App registration in your Entra ID
  • Client secret for authentication
  • API permission grants

Detailed setup guide →

Managing Connection

Testing Connection

Verify the connection is working:

  1. Go to Microsoft 365 integration
  2. Click Test Connection
  3. View test results

Tests verify:

  • Authentication succeeds
  • Permissions are granted
  • API calls work

Updating Credentials

To update client secret:

  1. Generate new secret in Azure Portal
  2. Go to Microsoft 365 settings
  3. Click Update Credentials
  4. Enter new client secret
  5. Save and test

Refreshing Connection

Force a data refresh:

  1. Go to Microsoft 365 integration
  2. Click Refresh Data
  3. Latest data fetched immediately

Data Access

What Securtea Reads

With this integration, Securtea reads:

CategoryData
UsersProfile info, MFA status
GroupsSettings, membership
PoliciesConditional Access, security
MailFlow rules, protection settings
SharePointTenant settings, sharing
Secure ScoreCurrent score, recommendations

What Securtea Doesn't Access

Securtea never reads:

  • Email content
  • Document contents
  • User passwords
  • Personal files

Multi-Tenant Support

Enterprise Plan Feature

Enterprise customers can connect multiple tenants:

  • Multiple M365 environments
  • MSP client tenants
  • Subsidiary organizations

Adding Tenants

For each tenant:

  1. Click Add Tenant
  2. Complete app registration
  3. Grant permissions
  4. Test connection

Security Considerations

Credential Storage

  • Client secrets are encrypted at rest
  • Never displayed after initial save
  • Access logged for audit

Access Monitoring

Monitor integration access:

  • Azure AD sign-in logs
  • Securtea activity logs
  • Microsoft Graph audit logs

Secret Rotation

Rotate client secrets regularly:

  1. Create new secret in Azure
  2. Update in Securtea
  3. Verify connection
  4. Delete old secret in Azure

Recommended: Rotate every 6-12 months

What's Next?

Global Search

Search for pages, settings, and documentation