Skip to main content

Overview

The Microsoft Office 365 integration enables ThreatAware to access Microsoft 365 and Intune data, providing visibility into user identities, device management, and security events. This helps you validate identity and device controls within your Microsoft 365 environment.
Connection Method: OAuth 2.0 (Microsoft Authentication) Setup Time: 10 minutes Access Required: Global or Company Administrator account

Data collected

The Microsoft Office 365 integration provides:
  • User identity information
  • Device management and enrollment status
  • Security events and policies
  • Identity risk detection
  • Organisational policies and settings

Use cases

Identity Management

Monitor user identities and access within Microsoft 365

Device Enrollment

Track device management and Intune enrollment status

Security Event Monitoring

Monitor security events and risk detections

Compliance Validation

Verify organisational policies and security controls

Setup instructions

1

Log in to ThreatAware

Navigate to the ThreatAware dashboard and go to Settings → Integrations. Use the search bar to find Microsoft Intune and click Connect - a pop-up window will appear.
2

Authorize Microsoft Office 365

Click the Authorize button in the ThreatAware pop-up. You will be redirected to Microsoft’s login page.
3

Log in with Microsoft Administrator Account

Log in using a Global Administrator or Company Administrator account. Ensure you use an account with sufficient permissions to grant API access. If prompted about your organisation, select the correct tenant.
4

Review and Accept Permissions

Review the permissions requested by ThreatAware. The integration requires Read-only permissions for organisational policies, security actions, security events, identity risk events, user profile information, usage reports, and directory data. Click Accept or Consent to grant these permissions.
5

Complete Authorization

After accepting permissions, you will be redirected back to ThreatAware. A success message will confirm the connection is established. If the connection fails, you can attempt authorization again.
6

Verify Connection

Check the integration status displays as Active in Settings → Integrations. Data collection will begin within 1 hour. Verify Microsoft 365 data appears in ThreatAware.

Permissions required

The Microsoft Office 365 integration requires the following read-only permissions:
  • Read your organisation’s policies
  • Read your organisation’s security actions
  • Read your organisation’s security events
  • Read all identity risk events
  • Read all identity risk user information
  • Read all users’ full profiles
  • Read all usage reports
  • Read directory data
  • Sign in and read user profile
No Write Access ThreatAware operates in read-only mode and does not require or request write permissions to your Microsoft 365 environment. All data collection is for monitoring and analysis purposes only.

Verification and testing

After setup, verify the integration is working correctly:
  1. Check Integration Status
    • Navigate to Settings → Integrations in ThreatAware
    • Confirm Microsoft Intune/Office 365 shows Active status
    • Check the last sync timestamp
  2. Verify Data Collection
    • Wait 60 minutes for the initial data poll
    • Search for a known user or device in ThreatAware
    • Verify Microsoft 365 data appears in the details
  3. Test Security Queries
    • Create a test query to filter users or security events from Microsoft 365
    • Verify the data matches your expectations

Troubleshooting

Symptoms: Authorization page appears but connection fails or shows errorSolutions:
  • Ensure you are logged in with a Global Administrator or Company Administrator account
  • Verify your account has not been locked or disabled
  • Check that you accepted the permissions correctly
  • Clear your browser cache and try authorising again
  • If the issue persists, try in an incognito/private browser window
Symptoms: Authorization completes but integration shows permission errorsSolutions:
  • Verify your administrator account has sufficient privileges
  • Ensure you accepted all requested permissions during authorization
  • Check that your Microsoft 365 tenant has not restricted API access
  • Have a Global Administrator retry the authorization
  • Contact your Microsoft 365 tenant administrator if access remains restricted
Symptoms: Authorization process times out or appears to hangSolutions:
  • Check your internet connection is stable and fast
  • Verify Microsoft’s login service is accessible (not blocked by firewall)
  • Try again from a different network if available
  • Ensure cookies and JavaScript are enabled in your browser
  • Contact ThreatAware support if timeouts persist
Symptoms: Integration shows active but no Microsoft 365 data appearsSolutions:
  • Verify there is user and device data in your Microsoft 365 tenant
  • Check that Intune enrollment is active in your environment
  • Confirm the administrator account that authorised still has permissions
  • Review ThreatAware integration logs for error messages
  • Wait additional time - first sync may take longer than 1 hour
  • Contact ThreatAware support if data collection continues to fail
Symptoms: Integration shows as needing re-authorization or consent updateSolutions:
  • Return to Settings → Integrations and reauthorize the integration
  • Use the same Microsoft 365 Global Administrator account
  • Accept all permissions when prompted again
  • The connection should resume normal operation after reauthorization

Important notes

Administrator Requirements
  • Only a Global Administrator or Company Administrator can authorise the Microsoft Office 365 integration
  • Regular users cannot complete the authorization process
  • If needed, have your tenant administrator perform this setup
Tenant Access
  • ThreatAware can only access data from the Microsoft 365 tenant where authorization was performed
  • If you have multiple tenants, authorise separately in each tenant for complete visibility
  • Use the Global Administrator account from each tenant for authorization

Additional resources

Microsoft Office 365 API Documentation

Official Microsoft Graph API documentation for detailed permissions and capabilities

ThreatAware Support

Contact ThreatAware support for integration assistance

Best practices

Security Governance
  • Ensure only authorised administrators can authorise integrations
  • Document which administrator accounts have authorised ThreatAware
  • Review and audit the authorised applications in Microsoft 365 periodically
  • Remove the integration authorization if it is no longer needed
Monitoring and Maintenance
  • Monitor the integration status regularly to ensure continuous data flow
  • If re-authorization is required, address it promptly
  • Verify data collection continues after any Microsoft 365 updates or changes
  • Keep ThreatAware and your Microsoft 365 environment up to date