Help

Connect a Microsoft 365 tenant

Add the client in ConfigCheckup, have one of their Global Administrators approve read access, and the first assessment starts on its own. Most tenants are connected in under five minutes.

Before you start

  • The client's tenant ID: a GUID shown in the Entra admin centre under Identity → Overview.
  • Someone in the client tenant who is a Global Administrator or Privileged Role Administrator. Only these roles can approve an application for the whole organisation.
  • A ConfigCheckup account with the Consultant role or higher.

1. Add the tenant

  1. In ConfigCheckup, go to Tenants → Connect a tenant.
  2. Enter the client's name and their Microsoft tenant ID. Choose Production, or Pilot or Lab for test tenants, which are left out of your portfolio averages.
  3. Select Add tenant. The tenant is created as Pending consent and its page shows the consent link.

Copy the Admin consent link from the tenant's page and send it to the client's administrator. When they open it, Microsoft shows the name of the application and every permission it asks for. They sign in, review the list and select Accept.

A short note to send with the link:

This lets us assess your Microsoft 365 configuration. It grants access to settings, not to the content of mail, files or chats. You can remove it at any time in the Entra admin centre under Enterprise applications.

After they accept, Microsoft returns them to ConfigCheckup, the tenant changes to Connected and the first assessment is queued straight away.

3. Check the connection

The tenant page lists every permission that was actually granted under Access granted. If a required permission is missing, the tenant shows as Degraded and names what is missing. Optional permissions that were not granted do not stop the assessment: the checks that need them are reported as not assessed, never as passes.

Permissions requested

Every permission is a Microsoft Graph application permission (not delegated), so assessments run on schedule without anyone signed in.

Required

PermissionWhy
Organization.Read.AllTenant profile, verified domains, technical contacts and assigned plans.
Directory.Read.AllUsers, groups, devices and directory objects that underpin most checks.
User.Read.AllAccount state, licence assignment and sign-in activity per user.
Group.Read.AllMicrosoft 365 groups, ownership, membership and guest exposure.
GroupMember.Read.AllResolves the membership of groups targeted by Conditional Access.
Policy.Read.AllConditional Access policies, authorization policy, security defaults, auth methods policy.
RoleManagement.Read.DirectoryDirectory role assignments and PIM eligibility — the privileged access picture.
Application.Read.AllApp registrations, service principals, credential expiry and delegated consent grants.
AuditLog.Read.AllLast sign-in timestamps (dormant account detection) and directory audit retention.
Reports.Read.AllAuthentication method registration and service usage reports.
SecurityEvents.Read.AllMicrosoft Secure Score, control profiles and security alerts.

Optional, each widens coverage

PermissionWhy
IdentityRiskyUser.Read.AllIdentity Protection risky users and risk detections.
DeviceManagementConfiguration.Read.AllIntune compliance and configuration policies.
DeviceManagementManagedDevices.Read.AllEnrolled device inventory, compliance state and OS versions.
MailboxSettings.ReadInbox rules, to find mail being forwarded outside the organisation. Rule definitions only; no message content.
SharePointTenantSettings.Read.AllTenant-wide SharePoint and OneDrive sharing configuration.
TeamSettings.Read.AllTeams guest access and meeting policy posture.

Write permissions, used only by automation

These let approved fixes make changes. Holding them does nothing on its own: ConfigCheckup writes nothing until automation is switched on for that tenant and each change has been dry-run and approved. See turning on automation.

PermissionUsed to
Device.ReadWrite.AllDisable or delete inactive end-of-life devices in Entra ID through an approved action.
DeviceManagementManagedDevices.ReadWrite.AllDelete the Intune records of inactive end-of-life devices through an approved action.
Policy.ReadWrite.ConditionalAccessCreate or amend Conditional Access policies via an approved action.
User.ReadWrite.AllDisable dormant accounts, revoke sessions, clear stale licences.
RoleManagement.ReadWrite.DirectoryRemove stale or redundant privileged role assignments via an approved action.
SharePointTenantSettings.ReadWrite.AllSet an expiry on SharePoint and OneDrive "Anyone" links via an approved action.
Directory.ReadWrite.AllRemove redundant role assignments and stale directory objects.
Application.ReadWrite.AllRevoke risky delegated consent grants and unused app credentials.

Granting consent again

Consent covers the permissions the application had at the time it was given. Grant it again when new permissions have been added (for example, for automation), when the client removed some, or when the tenant shows as Degraded.

  1. Open the tenant in ConfigCheckup.
  2. In Re-grant admin consent, select Grant consent again if you are the client's Global Administrator, or copy the link and send it to them.
  3. After they accept, run an assessment. The granted permissions are checked again at the start of every assessment.

Many tenants at once

If you are a Microsoft partner with GDAP relationships, Tenants → Import from Partner Center lists your customers and adds them in one go. Each one still needs its own consent; the consent queue tracks which are waiting.

Consent errors

MessageWhat it means and what to do
AADSTS90094, “needs admin approval”The person signing in cannot approve for the whole organisation. A Global Administrator or Privileged Role Administrator must open the link.
AADSTS650056The application is asking for a permission it has not declared. Contact support; this is fixed on our side.
AADSTS700016The application is not in the client's directory: consent was never completed, or it was removed. Send the consent link again.
Tenant shows as DegradedA required permission is missing. Grant consent again, then run an assessment.
Many checks “not assessed”Optional permissions were not granted, or the tenant does not have the licence the check needs (Entra ID P1 or P2, Intune).

Disconnecting

Removing a tenant in ConfigCheckup deletes its assessments, findings and reports, but does not remove the application from the client's directory. To stop all access, the client deletes it in the Entra admin centre under Enterprise applications. Access stops immediately. More in data protection.