Overview
The Microsoft Office 365 integration enables ThreatAware to access Microsoft 365 and Intune data, providing visibility into user identities, device management, and security events. This helps you validate identity and device controls within your Microsoft 365 environment.Connection Method: OAuth 2.0 (Microsoft Authentication)
Setup Time: 10 minutes
Access Required: Global or Company Administrator account
Data collected
The Microsoft Office 365 integration provides:- User identity information
- Device management and enrollment status
- Security events and policies
- Identity risk detection
- Organisational policies and settings
Use cases
Identity Management
Monitor user identities and access within Microsoft 365
Device Enrollment
Track device management and Intune enrollment status
Security Event Monitoring
Monitor security events and risk detections
Compliance Validation
Verify organisational policies and security controls
Setup instructions
1
Log in to ThreatAware
Navigate to the ThreatAware dashboard and go to Settings → Integrations. Use the search bar to find Microsoft Intune and click Connect - a pop-up window will appear.
2
Authorize Microsoft Office 365
Click the Authorize button in the ThreatAware pop-up. You will be redirected to Microsoft’s login page.
3
Log in with Microsoft Administrator Account
Log in using a Global Administrator or Company Administrator account. Ensure you use an account with sufficient permissions to grant API access. If prompted about your organisation, select the correct tenant.
4
Review and Accept Permissions
Review the permissions requested by ThreatAware. The integration requires Read-only permissions for organisational policies, security actions, security events, identity risk events, user profile information, usage reports, and directory data. Click Accept or Consent to grant these permissions.
5
Complete Authorization
After accepting permissions, you will be redirected back to ThreatAware. A success message will confirm the connection is established. If the connection fails, you can attempt authorization again.
6
Verify Connection
Check the integration status displays as Active in Settings → Integrations. Data collection will begin within 1 hour. Verify Microsoft 365 data appears in ThreatAware.
Permissions required
The Microsoft Office 365 integration requires the following read-only permissions:- Read your organisation’s policies
- Read your organisation’s security actions
- Read your organisation’s security events
- Read all identity risk events
- Read all identity risk user information
- Read all users’ full profiles
- Read all usage reports
- Read directory data
- Sign in and read user profile
No Write Access
ThreatAware operates in read-only mode and does not require or request write permissions to your Microsoft 365 environment. All data collection is for monitoring and analysis purposes only.
Verification and testing
After setup, verify the integration is working correctly:-
Check Integration Status
- Navigate to Settings → Integrations in ThreatAware
- Confirm Microsoft Intune/Office 365 shows Active status
- Check the last sync timestamp
-
Verify Data Collection
- Wait 60 minutes for the initial data poll
- Search for a known user or device in ThreatAware
- Verify Microsoft 365 data appears in the details
-
Test Security Queries
- Create a test query to filter users or security events from Microsoft 365
- Verify the data matches your expectations
Troubleshooting
Insufficient Permissions
Insufficient Permissions
Symptoms: Authorization completes but integration shows permission errorsSolutions:
- Verify your administrator account has sufficient privileges
- Ensure you accepted all requested permissions during authorization
- Check that your Microsoft 365 tenant has not restricted API access
- Have a Global Administrator retry the authorization
- Contact your Microsoft 365 tenant administrator if access remains restricted
Connection Timeout
Connection Timeout
Symptoms: Authorization process times out or appears to hangSolutions:
- Check your internet connection is stable and fast
- Verify Microsoft’s login service is accessible (not blocked by firewall)
- Try again from a different network if available
- Ensure cookies and JavaScript are enabled in your browser
- Contact ThreatAware support if timeouts persist
No Data After 1 Hour
No Data After 1 Hour
Symptoms: Integration shows active but no Microsoft 365 data appearsSolutions:
- Verify there is user and device data in your Microsoft 365 tenant
- Check that Intune enrollment is active in your environment
- Confirm the administrator account that authorised still has permissions
- Review ThreatAware integration logs for error messages
- Wait additional time - first sync may take longer than 1 hour
- Contact ThreatAware support if data collection continues to fail
Important notes
Administrator Requirements
- Only a Global Administrator or Company Administrator can authorise the Microsoft Office 365 integration
- Regular users cannot complete the authorization process
- If needed, have your tenant administrator perform this setup
Additional resources
Microsoft Office 365 API Documentation
Official Microsoft Graph API documentation for detailed permissions and capabilities
ThreatAware Support
Contact ThreatAware support for integration assistance