Help
Connect a Microsoft 365 tenant
Add the client in ConfigCheckup, have one of their Global Administrators approve read access, and the first assessment starts on its own. Most tenants are connected in under five minutes.
Before you start
- The client's tenant ID: a GUID shown in the Entra admin centre under Identity → Overview.
- Someone in the client tenant who is a Global Administrator or Privileged Role Administrator. Only these roles can approve an application for the whole organisation.
- A ConfigCheckup account with the Consultant role or higher.
1. Add the tenant
- In ConfigCheckup, go to Tenants → Connect a tenant.
- Enter the client's name and their Microsoft tenant ID. Choose Production, or Pilot or Lab for test tenants, which are left out of your portfolio averages.
- Select Add tenant. The tenant is created as Pending consent and its page shows the consent link.
2. Send the consent link
Copy the Admin consent link from the tenant's page and send it to the client's administrator. When they open it, Microsoft shows the name of the application and every permission it asks for. They sign in, review the list and select Accept.
A short note to send with the link:
This lets us assess your Microsoft 365 configuration. It grants access to settings, not to the content of mail, files or chats. You can remove it at any time in the Entra admin centre under Enterprise applications.
After they accept, Microsoft returns them to ConfigCheckup, the tenant changes to Connected and the first assessment is queued straight away.
3. Check the connection
The tenant page lists every permission that was actually granted under Access granted. If a required permission is missing, the tenant shows as Degraded and names what is missing. Optional permissions that were not granted do not stop the assessment: the checks that need them are reported as not assessed, never as passes.
Permissions requested
Every permission is a Microsoft Graph application permission (not delegated), so assessments run on schedule without anyone signed in.
Required
| Permission | Why |
|---|---|
Organization.Read.All | Tenant profile, verified domains, technical contacts and assigned plans. |
Directory.Read.All | Users, groups, devices and directory objects that underpin most checks. |
User.Read.All | Account state, licence assignment and sign-in activity per user. |
Group.Read.All | Microsoft 365 groups, ownership, membership and guest exposure. |
GroupMember.Read.All | Resolves the membership of groups targeted by Conditional Access. |
Policy.Read.All | Conditional Access policies, authorization policy, security defaults, auth methods policy. |
RoleManagement.Read.Directory | Directory role assignments and PIM eligibility — the privileged access picture. |
Application.Read.All | App registrations, service principals, credential expiry and delegated consent grants. |
AuditLog.Read.All | Last sign-in timestamps (dormant account detection) and directory audit retention. |
Reports.Read.All | Authentication method registration and service usage reports. |
SecurityEvents.Read.All | Microsoft Secure Score, control profiles and security alerts. |
Optional, each widens coverage
| Permission | Why |
|---|---|
IdentityRiskyUser.Read.All | Identity Protection risky users and risk detections. |
DeviceManagementConfiguration.Read.All | Intune compliance and configuration policies. |
DeviceManagementManagedDevices.Read.All | Enrolled device inventory, compliance state and OS versions. |
MailboxSettings.Read | Inbox rules, to find mail being forwarded outside the organisation. Rule definitions only; no message content. |
SharePointTenantSettings.Read.All | Tenant-wide SharePoint and OneDrive sharing configuration. |
TeamSettings.Read.All | Teams guest access and meeting policy posture. |
Write permissions, used only by automation
These let approved fixes make changes. Holding them does nothing on its own: ConfigCheckup writes nothing until automation is switched on for that tenant and each change has been dry-run and approved. See turning on automation.
| Permission | Used to |
|---|---|
Device.ReadWrite.All | Disable or delete inactive end-of-life devices in Entra ID through an approved action. |
DeviceManagementManagedDevices.ReadWrite.All | Delete the Intune records of inactive end-of-life devices through an approved action. |
Policy.ReadWrite.ConditionalAccess | Create or amend Conditional Access policies via an approved action. |
User.ReadWrite.All | Disable dormant accounts, revoke sessions, clear stale licences. |
RoleManagement.ReadWrite.Directory | Remove stale or redundant privileged role assignments via an approved action. |
SharePointTenantSettings.ReadWrite.All | Set an expiry on SharePoint and OneDrive "Anyone" links via an approved action. |
Directory.ReadWrite.All | Remove redundant role assignments and stale directory objects. |
Application.ReadWrite.All | Revoke risky delegated consent grants and unused app credentials. |
Granting consent again
Consent covers the permissions the application had at the time it was given. Grant it again when new permissions have been added (for example, for automation), when the client removed some, or when the tenant shows as Degraded.
- Open the tenant in ConfigCheckup.
- In Re-grant admin consent, select Grant consent again if you are the client's Global Administrator, or copy the link and send it to them.
- After they accept, run an assessment. The granted permissions are checked again at the start of every assessment.
Many tenants at once
If you are a Microsoft partner with GDAP relationships, Tenants → Import from Partner Center lists your customers and adds them in one go. Each one still needs its own consent; the consent queue tracks which are waiting.
Consent errors
| Message | What it means and what to do |
|---|---|
AADSTS90094, “needs admin approval” | The person signing in cannot approve for the whole organisation. A Global Administrator or Privileged Role Administrator must open the link. |
AADSTS650056 | The application is asking for a permission it has not declared. Contact support; this is fixed on our side. |
AADSTS700016 | The application is not in the client's directory: consent was never completed, or it was removed. Send the consent link again. |
| Tenant shows as Degraded | A required permission is missing. Grant consent again, then run an assessment. |
| Many checks “not assessed” | Optional permissions were not granted, or the tenant does not have the licence the check needs (Entra ID P1 or P2, Intune). |
Disconnecting
Removing a tenant in ConfigCheckup deletes its assessments, findings and reports, but does not remove the application from the client's directory. To stop all access, the client deletes it in the Entra admin centre under Enterprise applications. Access stops immediately. More in data protection.