# Microsoft 365

![Microsoft_365_logo.png|400](https://assets.relyanceuat.xyz/images/docs/34605712862989/34605706610317_white.png)

Microsoft 365 is a cloud-based productivity platform. It provides a suite of online products such as Microsoft Teams, Word, Excel, PowerPoint, Outlook, OneDrive, and more.

You can connect Microsoft 365 to Relyance AI in two ways. Pick one under **Authentication Method** on the connection wizard's **Authentication** step:

- **Relyance app (admin consent)**. A Microsoft Entra administrator grants the Relyance AI application read access to your tenant once. Relyance then connects as that application, not as a person, so the connection doesn't depend on any one user's account or sign-in. You don't create an app registration or handle any secret. See [Connect with the Relyance app (admin consent)](#connect-with-admin-consent).
- **Oauth2 / App Token**. A user signs in to Microsoft during the wizard and Relyance connects on their behalf. This is the original method and keeps working for existing connections. The steps are below.

Both methods offer the same checkboxes for which Microsoft 365 data is scanned. See [Choose what is scanned](#choose-what-is-scanned).

## Connect with Oauth2 / App Token

#### In the Relyance AI application:

1. Login to your Relyance AI account.
2. Navigate to the **Settings** (bottom-left corner).
3. Select **Integrations**.
4. Search and locate the **Microsoft 365** integration card and click on it.
5. Click on the **Add Connection** button on the top right.
6. Provide a meaningful name for the integration and click on the **Add** button.\
![Screenshot](https://assets.relyanceuat.xyz/images/docs/34605712862989/34605706610957.png)
7. In the **Overview** section, select the integration features you wish to enable for the integration, review the **Scope and Permission**, and **Endpoint** details and click on **Continue**. **Note:** For more details, see [Integration Features](/docs/introduction-to-relyance-ai/integration-features/).\
![Screenshot 2025-11-04 101627.png](https://assets.relyanceuat.xyz/images/docs/34605712862989/40849959984525.png)
8. In the **Connection** section, provide the appropriate values and click on **Continue**,
    - **Connection Name**: This property allows you to update the integration specified in Step 6. If you have multiple integrations for the same vendor, you may want to assign distinct names to each. This helps streamline filtering by **Discovery Source** across the **Inventory**, **Visual** **Maps**, **Assets**, and **Data Flow Analysis** pages.
    - **Rescan Frequency**: This property allows you to configure how often Relyance executes scans against this Vendor connection.
    - **Business Atlas Associations** (required): the business entities or products that newly discovered third parties, services and assets from this integration are attributed to. Choose at least one from the **Select Associations** dropdown — the wizard will not advance past this step without one. **Note:** For more details, see [Business Atlas](/docs/other-settings/business-atlas-overview/).\
    ![Screenshot](https://assets.relyanceuat.xyz/images/docs/34605712862989/34605712846733.png)
9. In the **Authentication** section, choose **Oauth2 / App Token**, choose what to scan (see [Choose what is scanned](#choose-what-is-scanned)), and click on **Continue**.\
![Screenshot](https://assets.relyanceuat.xyz/images/docs/34605712862989/34605712848269.png)
10. Review the configuration summary from the **Completion** section and click on **Finish.**\
![Screenshot](https://assets.relyanceuat.xyz/images/docs/34605712862989/34684031512717.png)
11. Confirm the integration Status reflects **Connected.**

## Connect with the Relyance app (admin consent)

### In Microsoft Entra

Someone with the **Global Administrator** or **Privileged Role Administrator** role does these steps. Only those roles can grant an application tenant-wide access to Microsoft Graph.

1. **Note your tenant ID.** In the [Microsoft Entra admin center](https://entra.microsoft.com), open **Overview** and copy the **Tenant ID**, for example `00000000-1111-2222-3333-444444444444`.
2. **Grant admin consent.** Open this link in a browser, replacing `<your-tenant-id>` with the tenant ID from step 1:

    ```
    https://login.microsoftonline.com/<your-tenant-id>/adminconsent?client_id=4662deb0-baed-4ae4-a175-2f4fa1a7ff3e
    ```

    Sign in, review the permissions listed under [Permissions the Relyance app requests](#permissions-the-relyance-app-requests), and click **Accept**. Microsoft then sends your browser to a Relyance page, which you can close. The consent is already recorded.
3. **Check that consent was granted.** In the Entra admin center, open **Enterprise applications**, find **Relyance AI** (application ID `4662deb0-baed-4ae4-a175-2f4fa1a7ff3e`), and open **Permissions**. Every permission should show as granted for your organization.

### In the Relyance AI application

1. Log in to your Relyance AI account.
2. Open **Settings** (bottom left) and select **Integrations**.
3. Find the **Microsoft 365** integration card and click it, then click **Add Connection**.
4. Follow the wizard. On the **Authentication** step, choose **Relyance app (admin consent)** and fill in:
    - **Tenant ID**: from step 1.
    - The scan checkboxes: see [Choose what is scanned](#choose-what-is-scanned).
    - **Data Storage Location**: where Relyance stores the data it collects.
5. Click **Authenticate** and finish the wizard, then confirm the connection shows **Connected**.

**To remove Relyance's access**, delete the **Relyance AI** enterprise application from your tenant in the Entra admin center. This revokes the consent. Relyance can't get new access tokens after that, and any token already issued expires within about 90 minutes. Scans on the connection fail until consent is granted again.

### Permissions the Relyance app requests

These are Microsoft Graph **application** permissions, all read-only. Admin consent grants them to the Relyance AI application in your tenant only. The consent screen also shows `User.Read`, the standard sign-in permission, which Relyance doesn't use to read your data.

| Area | Permission | What Relyance reads with it |
| --- | --- | --- |
| Directory | `Directory.Read.All` | Users, groups, applications and other directory objects |
| | `GroupMember.Read.All` | Group memberships |
| | `Application.Read.All` | App registrations and the third-party applications connected to your tenant |
| | `RoleManagement.Read.Directory` | Directory role assignments, such as who holds administrator roles |
| | `Policy.Read.All`, `Policy.Read.PermissionGrant` | Tenant policies, including which applications users may consent to |
| | `ConsentRequest.Read.All` | Pending requests from users for admin consent to applications |
| | `CustomSecAttributeAssignment.Read.All` | Custom security attributes assigned to users and applications |
| | `AuditLog.Read.All` | Directory audit and sign-in logs |
| SharePoint and OneDrive | `Sites.Read.All` | SharePoint sites, document libraries and their files' metadata |
| | `Files.Read.All` | Files in SharePoint and OneDrive, to classify their content |
| Copilot | `Reports.Read.All` | Microsoft 365 Copilot usage reports |
| | `AuditLogsQuery.Read.All` | The Purview audit log, for the files and sites Copilot accessed |
| | `CopilotPackages.Read.All` | The Microsoft 365 Copilot agent and app catalog |
| | `AiEnterpriseInteraction.Read.All` | The text of users' Copilot prompts and responses |
| Teams | `Team.ReadBasic.All`, `TeamMember.Read.All` | Teams and their members |
| | `Channel.ReadBasic.All`, `ChannelSettings.Read.All` | Channels in each team and their settings |

Consent covers the whole application, so all of these are granted even if you turn a scan off. Turning a scan off stops Relyance from reading that data. See the next section.

## Choose what is scanned

Both authentication methods have four checkboxes, all on by default. Turn one off and Relyance skips that data on every following scan.

| Checkbox | What it scans | Main permissions it uses |
| --- | --- | --- |
| **Scan SharePoint files** | Files in SharePoint document libraries, who they're shared with, and the personal data in their content | `Sites.Read.All`, `Files.Read.All` |
| **Scan OneDrive files** | Files in users' OneDrive, who they're shared with, and the personal data in their content | `Files.Read.All` |
| **Scan Copilot activity and agents** | Copilot usage, the files and sites Copilot accessed (from the audit log), Copilot Studio agents, the agent catalog and the agent registry. Doesn't read prompts or responses | `Reports.Read.All`, `AuditLogsQuery.Read.All`, `CopilotPackages.Read.All` |
| **Scan Copilot prompts and responses** | The text of users' Copilot prompts and responses, and the personal data in them | `AiEnterpriseInteraction.Read.All` |

Users, groups, licences and applications from Microsoft Entra are always scanned; no checkbox controls them. Relyance needs them to work out who the sharing links, file access and Copilot activity belong to.

<!-- auth-methods:begin (generated from the integration catalog; do not hand-edit) -->

## Authentication methods and fields

Pick one of these under **Authentication Method** on the connection wizard's **Authentication** step. This table is generated from the integration catalog, so it always matches what the form actually asks for.

| Method | Required | Optional |
| --- | --- | --- |
| **Oauth2 / App Token** | — | `Scan SharePoint files`, `Scan OneDrive files`, `Scan Copilot activity and agents`, `Scan Copilot prompts and responses` |
| **Relyance app (admin consent)** | `Tenant ID` | `Scan SharePoint files`, `Scan OneDrive files`, `Scan Copilot activity and agents`, `Scan Copilot prompts and responses` |

<!-- auth-methods:end -->

### Verify the connection is really working

For a **Relyance app (admin consent)** connection:

- **Authentication fails** when admin consent hasn't been granted, or was granted in a different tenant from the **Tenant ID** on the connection. Check both in the Entra admin center under **Enterprise applications** → **Relyance AI** → **Permissions**.
- **A scan area stops working after someone changed the app's permissions** in Entra. Grant admin consent again with the link in step 2 to restore them.

For an **Oauth2 / App Token** connection:

1. **Connected but nothing discovered** is admin consent on `User.Read.All`.
2. **Data subject requests fail while discovery works.** DSR handling needs
   `User.ReadWrite.All` and `Directory.ReadWrite.All` — *write* scopes, granted
   separately from the read-only discovery scope. Enabling the DSR feature without
   adding and re-consenting them leaves requests failing while everything else looks
   healthy.
3. **`offline_access` is what keeps the connection alive.** Without it the refresh
   token is not issued and the connection stops at the first token expiry, typically
   an hour in, which reads as an intermittent fault rather than a missing scope.

<!-- terraform-examples:begin (generated from the integration catalog; do not hand-edit) -->

## Manage this integration with Terraform

Connections for this integration can be managed as code with the [Relyance Terraform provider](https://registry.terraform.io/providers/Relyance/relyance/latest). Non-secret fields go in `auth.params`; secret fields go in `auth.secrets_wo`, which is write-only — never stored in Terraform state. Rotate secrets by bumping `auth.secrets_wo_version`.

### OAuth (browser authorization)

The **OAuth (browser authorization)** method uses a browser authorization flow, so the connection is created in the Relyance app. Manage it in Terraform afterwards by importing it (`terraform import relyance_integration_connection.example microsoft365/<connection_id>`) or reading it with the `relyance_integration_connection` data source.

### OAuth client credentials

```hcl
resource "relyance_integration_connection" "microsoft365_1" {
  vendor = "microsoft365"
  name   = "<your connection name>"

  auth = {
    method = "oauth-client-credentials"
    params = {
      tenant_id = "<tenant_id>"
      data_storage_location = "us"
    }
  }

  scans = { "property-inspection" = { enabled = true } }
}
```

<!-- terraform-examples:end -->
