> ## Documentation Index
> Fetch the complete documentation index at: https://docs.threataware.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Microsoft Office 365

> Connect ThreatAware to Microsoft Intune and Office 365 for identity and device management

## Overview

The Microsoft Office 365 integration enables ThreatAware to access Microsoft 365 and Intune data, providing visibility into user identities, device management, and security events. This helps you validate identity and device controls within your Microsoft 365 environment.

<Info>
  **Connection Method**: OAuth 2.0 (Microsoft Authentication)
  **Setup Time**: 10 minutes
  **Access Required**: Global or Company Administrator account
</Info>

## Data collected

The Microsoft Office 365 integration provides:

* User identity information
* Device management and enrollment status
* Security events and policies
* Identity risk detection
* Organisational policies and settings

## Use cases

<CardGroup cols={2}>
  <Card title="Identity Management" icon="users">
    Monitor user identities and access within Microsoft 365
  </Card>

  <Card title="Device Enrollment" icon="laptop">
    Track device management and Intune enrollment status
  </Card>

  <Card title="Security Event Monitoring" icon="shield-alert">
    Monitor security events and risk detections
  </Card>

  <Card title="Compliance Validation" icon="clipboard-check">
    Verify organisational policies and security controls
  </Card>
</CardGroup>

## Setup instructions

<Steps>
  <Step title="Log in to ThreatAware">
    Navigate to the ThreatAware dashboard and go to **Settings → Integrations**. Use the search bar to find **Microsoft Intune** and click **Connect** - a pop-up window will appear.
  </Step>

  <Step title="Authorize Microsoft Office 365">
    Click the **Authorize** button in the ThreatAware pop-up. You will be redirected to Microsoft's login page.
  </Step>

  <Step title="Log in with Microsoft Administrator Account">
    Log in using a **Global Administrator** or **Company Administrator** account. Ensure you use an account with sufficient permissions to grant API access. If prompted about your organisation, select the correct tenant.
  </Step>

  <Step title="Review and Accept Permissions">
    Review the permissions requested by ThreatAware. The integration requires **Read-only** permissions for organisational policies, security actions, security events, identity risk events, user profile information, usage reports, and directory data. Click **Accept** or **Consent** to grant these permissions.
  </Step>

  <Step title="Complete Authorization">
    After accepting permissions, you will be redirected back to ThreatAware. A success message will confirm the connection is established. If the connection fails, you can attempt authorization again.
  </Step>

  <Step title="Verify Connection">
    Check the integration status displays as **Active** in **Settings → Integrations**. Data collection will begin within 1 hour. Verify Microsoft 365 data appears in ThreatAware.
  </Step>
</Steps>

## Permissions required

The Microsoft Office 365 integration requires the following **read-only** permissions:

* Read your organisation's policies
* Read your organisation's security actions
* Read your organisation's security events
* Read all identity risk events
* Read all identity risk user information
* Read all users' full profiles
* Read all usage reports
* Read directory data
* Sign in and read user profile

<Info>
  **No Write Access**
  ThreatAware operates in read-only mode and does not require or request write permissions to your Microsoft 365 environment. All data collection is for monitoring and analysis purposes only.
</Info>

## Verification and testing

After setup, verify the integration is working correctly:

1. **Check Integration Status**
   * Navigate to **Settings → Integrations** in ThreatAware
   * Confirm Microsoft Intune/Office 365 shows **Active** status
   * Check the last sync timestamp

2. **Verify Data Collection**
   * Wait 60 minutes for the initial data poll
   * Search for a known user or device in ThreatAware
   * Verify Microsoft 365 data appears in the details

3. **Test Security Queries**
   * Create a test query to filter users or security events from Microsoft 365
   * Verify the data matches your expectations

## Troubleshooting

<AccordionGroup>
  <Accordion title="Authorization Failed" icon="triangle-exclamation">
    **Symptoms**: Authorization page appears but connection fails or shows error

    **Solutions**:

    * Ensure you are logged in with a **Global Administrator** or **Company Administrator** account
    * Verify your account has not been locked or disabled
    * Check that you accepted the permissions correctly
    * Clear your browser cache and try authorising again
    * If the issue persists, try in an incognito/private browser window
  </Accordion>

  <Accordion title="Insufficient Permissions" icon="ban">
    **Symptoms**: Authorization completes but integration shows permission errors

    **Solutions**:

    * Verify your administrator account has sufficient privileges
    * Ensure you accepted all requested permissions during authorization
    * Check that your Microsoft 365 tenant has not restricted API access
    * Have a Global Administrator retry the authorization
    * Contact your Microsoft 365 tenant administrator if access remains restricted
  </Accordion>

  <Accordion title="Connection Timeout" icon="clock">
    **Symptoms**: Authorization process times out or appears to hang

    **Solutions**:

    * Check your internet connection is stable and fast
    * Verify Microsoft's login service is accessible (not blocked by firewall)
    * Try again from a different network if available
    * Ensure cookies and JavaScript are enabled in your browser
    * Contact ThreatAware support if timeouts persist
  </Accordion>

  <Accordion title="No Data After 1 Hour" icon="database">
    **Symptoms**: Integration shows active but no Microsoft 365 data appears

    **Solutions**:

    * Verify there is user and device data in your Microsoft 365 tenant
    * Check that Intune enrollment is active in your environment
    * Confirm the administrator account that authorised still has permissions
    * Review ThreatAware integration logs for error messages
    * Wait additional time - first sync may take longer than 1 hour
    * Contact ThreatAware support if data collection continues to fail
  </Accordion>

  <Accordion title="Re-authorization Required" icon="refresh">
    **Symptoms**: Integration shows as needing re-authorization or consent update

    **Solutions**:

    * Return to **Settings → Integrations** and reauthorize the integration
    * Use the same Microsoft 365 Global Administrator account
    * Accept all permissions when prompted again
    * The connection should resume normal operation after reauthorization
  </Accordion>
</AccordionGroup>

## Important notes

<Info>
  **Administrator Requirements**

  * Only a **Global Administrator** or **Company Administrator** can authorise the Microsoft Office 365 integration
  * Regular users cannot complete the authorization process
  * If needed, have your tenant administrator perform this setup
</Info>

<Tip>
  **Tenant Access**

  * ThreatAware can only access data from the Microsoft 365 tenant where authorization was performed
  * If you have multiple tenants, authorise separately in each tenant for complete visibility
  * Use the Global Administrator account from each tenant for authorization
</Tip>

## Additional resources

<CardGroup cols={2}>
  <Card title="Microsoft Office 365 API Documentation" icon="book" href="https://docs.microsoft.com/graph/">
    Official Microsoft Graph API documentation for detailed permissions and capabilities
  </Card>

  <Card title="ThreatAware Support" icon="life-ring" href="mailto:help@threataware.com">
    Contact ThreatAware support for integration assistance
  </Card>
</CardGroup>

## Best practices

<Tip>
  **Security Governance**

  * Ensure only authorised administrators can authorise integrations
  * Document which administrator accounts have authorised ThreatAware
  * Review and audit the authorised applications in Microsoft 365 periodically
  * Remove the integration authorization if it is no longer needed
</Tip>

<Tip>
  **Monitoring and Maintenance**

  * Monitor the integration status regularly to ensure continuous data flow
  * If re-authorization is required, address it promptly
  * Verify data collection continues after any Microsoft 365 updates or changes
  * Keep ThreatAware and your Microsoft 365 environment up to date
</Tip>
