๐Ÿ“‹ GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROCโ€ฆSaaS discovery for data governanceFree enriched web chat widget๐Ÿš€ Enriched remote support without your laptop

Connect Microsoft 365

Connect or re-authorize your Microsoft 365 tenant so Lavawall can monitor it, without seeing any monitoring data yourself.

Where to find it
Microsoft 365 โ€บ Connect Microsoft 365
Who can use it
Users with the "authorize Microsoft 365 only" permission (connect without seeing monitoring data); you also need a Microsoft 365 administrator account to sign in
Plan
Microsoft 365 connection (authorize only)
For
Everyone

What the page is for

This page is for people who need to connect Microsoft 365 to Lavawall but should not see the monitoring results, such as an IT administrator at a client who only grants access. Users with this limited permission are sent here instead of the Microsoft 365 dashboard.

The page shows whether your Microsoft 365 tenant is already connected and, if so, which tenant. One button starts Microsoft's sign-in and consent process. You sign in with a Microsoft 365 administrator account and choose the level of access Lavawall gets.

No monitoring data is shown on this page. Only the authorization happens here.

What you see

The Connect Microsoft 365 page (illustration), with the company and status, connect microsoft 365 / re-authorize and microsoft 365 authorization numbered 1 to 3.
Illustration of the Connect Microsoft 365 page. Numbers match the list below.
  1. Company and status: your company name and a Connected badge with the tenant domain, or a note that the tenant is not yet connected.
  2. Connect Microsoft 365 / Re-authorize: starts the Microsoft sign-in. The button reads Re-authorize when a tenant is already connected.
  3. Microsoft 365 Authorization dialog: choose Read Only or Read + Write access.

How to connect Microsoft 365

  1. Click Connect Microsoft 365.
  2. In the Microsoft 365 Authorization dialog, choose the access level:
    • Read Only: monitor sign-ins, audit logs, security alerts, users and licences. No changes are made to your tenant.
    • Read + Write: everything in Read Only, plus locking or disabling accounts, revoking sessions, forcing password resets and managing conditional access.
  3. Sign in with a Microsoft 365 administrator account.
  4. Review the permissions Microsoft shows and accept them.
  5. You are returned to Lavawall and the page shows Connected with your tenant.

How to re-authorize

  1. Click Re-authorize.
  2. Choose Read Only or Read + Write. Choose Read + Write if you want to switch from read-only to response actions.
  3. Sign in as a Microsoft 365 administrator and accept the permissions again.

Tips

  • Use a Microsoft 365 administrator account that can grant consent for your whole organization.
  • Start with Read Only if you only need monitoring. You can re-authorize later to add Read + Write.
  • Re-authorize if Lavawall reports that the connection has stopped working or if you want to change the access level.

Troubleshooting

  • "This tenant is not yet connected." No Microsoft 365 tenant has been authorized for this company yet. Click Connect Microsoft 365.
  • Microsoft says you need admin approval. Sign in with an account that has administrator rights in Microsoft 365.
  • I can't see any Microsoft 365 data. That is expected with the authorize-only permission. Ask your provider or administrator for access to the Microsoft 365 dashboard.

Task guides that use this page

Still need help?

Search the support centre, or contact our support team and tell us which page you were on.

Names, companies, devices and figures in the pictures are examples. Other product and company names are trademarks of their respective owners.