Microsoft 365

Microsoft 365 is a cloud-based productivity platform. It provides a suite of online products such as Microsoft Teams, Word, Excel, PowerPoint, Outlook, OneDrive, and more.
You can connect Microsoft 365 to Relyance AI in two ways. Pick one under Authentication Method on the connection wizard's Authentication step:
- Relyance app (admin consent). A Microsoft Entra administrator grants the Relyance AI application read access to your tenant once. Relyance then connects as that application, not as a person, so the connection doesn't depend on any one user's account or sign-in. You don't create an app registration or handle any secret. See Connect with the Relyance app (admin consent).
- Oauth2 / App Token. A user signs in to Microsoft during the wizard and Relyance connects on their behalf. This is the original method and keeps working for existing connections. The steps are below.
Both methods offer the same checkboxes for which Microsoft 365 data is scanned. See Choose what is scanned.
Connect with Oauth2 / App Token
In the Relyance AI application:
- Login to your Relyance AI account.
- Navigate to the Settings (bottom-left corner).
- Select Integrations.
- Search and locate the Microsoft 365 integration card and click on it.
- Click on the Add Connection button on the top right.
- Provide a meaningful name for the integration and click on the Add button.

- In the Overview section, select the integration features you wish to enable for the integration, review the Scope and Permission, and Endpoint details and click on Continue. Note: For more details, see Integration Features.

- In the Connection section, provide the appropriate values and click on Continue,
- Connection Name: This property allows you to update the integration specified in Step 6. If you have multiple integrations for the same vendor, you may want to assign distinct names to each. This helps streamline filtering by Discovery Source across the Inventory, Visual Maps, Assets, and Data Flow Analysis pages.
- Rescan Frequency: This property allows you to configure how often Relyance executes scans against this Vendor connection.
- Business Atlas Associations (required): the business entities or products that newly discovered third parties, services and assets from this integration are attributed to. Choose at least one from the Select Associations dropdown — the wizard will not advance past this step without one. Note: For more details, see Business Atlas.

- In the Authentication section, choose Oauth2 / App Token, choose what to scan (see Choose what is scanned), and click on Continue.

- Review the configuration summary from the Completion section and click on Finish.

- Confirm the integration Status reflects Connected.
Connect with the Relyance app (admin consent)
In Microsoft Entra
Someone with the Global Administrator or Privileged Role Administrator role does these steps. Only those roles can grant an application tenant-wide access to Microsoft Graph.
Note your tenant ID. In the Microsoft Entra admin center, open Overview and copy the Tenant ID, for example
00000000-1111-2222-3333-444444444444.Grant admin consent. Open this link in a browser, replacing
<your-tenant-id>with the tenant ID from step 1:https://login.microsoftonline.com/<your-tenant-id>/adminconsent?client_id=4662deb0-baed-4ae4-a175-2f4fa1a7ff3eSign in, review the permissions listed under Permissions the Relyance app requests, and click Accept. Microsoft then sends your browser to a Relyance page, which you can close. The consent is already recorded.
Check that consent was granted. In the Entra admin center, open Enterprise applications, find Relyance AI (application ID
4662deb0-baed-4ae4-a175-2f4fa1a7ff3e), and open Permissions. Every permission should show as granted for your organization.
In the Relyance AI application
- Log in to your Relyance AI account.
- Open Settings (bottom left) and select Integrations.
- Find the Microsoft 365 integration card and click it, then click Add Connection.
- Follow the wizard. On the Authentication step, choose Relyance app (admin consent) and fill in:
- Tenant ID: from step 1.
- The scan checkboxes: see Choose what is scanned.
- Data Storage Location: where Relyance stores the data it collects.
- Click Authenticate and finish the wizard, then confirm the connection shows Connected.
To remove Relyance's access, delete the Relyance AI enterprise application from your tenant in the Entra admin center. This revokes the consent. Relyance can't get new access tokens after that, and any token already issued expires within about 90 minutes. Scans on the connection fail until consent is granted again.
Permissions the Relyance app requests
These are Microsoft Graph application permissions, all read-only. Admin consent grants them to the Relyance AI application in your tenant only. The consent screen also shows User.Read, the standard sign-in permission, which Relyance doesn't use to read your data.
| Area | Permission | What Relyance reads with it |
|---|---|---|
| Directory | Directory.Read.All |
Users, groups, applications and other directory objects |
GroupMember.Read.All |
Group memberships | |
Application.Read.All |
App registrations and the third-party applications connected to your tenant | |
RoleManagement.Read.Directory |
Directory role assignments, such as who holds administrator roles | |
Policy.Read.All, Policy.Read.PermissionGrant |
Tenant policies, including which applications users may consent to | |
ConsentRequest.Read.All |
Pending requests from users for admin consent to applications | |
CustomSecAttributeAssignment.Read.All |
Custom security attributes assigned to users and applications | |
AuditLog.Read.All |
Directory audit and sign-in logs | |
| SharePoint and OneDrive | Sites.Read.All |
SharePoint sites, document libraries and their files' metadata |
Files.Read.All |
Files in SharePoint and OneDrive, to classify their content | |
| Copilot | Reports.Read.All |
Microsoft 365 Copilot usage reports |
AuditLogsQuery.Read.All |
The Purview audit log, for the files and sites Copilot accessed | |
CopilotPackages.Read.All |
The Microsoft 365 Copilot agent and app catalog | |
AiEnterpriseInteraction.Read.All |
The text of users' Copilot prompts and responses | |
| Teams | Team.ReadBasic.All, TeamMember.Read.All |
Teams and their members |
Channel.ReadBasic.All, ChannelSettings.Read.All |
Channels in each team and their settings |
Consent covers the whole application, so all of these are granted even if you turn a scan off. Turning a scan off stops Relyance from reading that data. See the next section.
Choose what is scanned
Both authentication methods have four checkboxes, all on by default. Turn one off and Relyance skips that data on every following scan.
| Checkbox | What it scans | Main permissions it uses |
|---|---|---|
| Scan SharePoint files | Files in SharePoint document libraries, who they're shared with, and the personal data in their content | Sites.Read.All, Files.Read.All |
| Scan OneDrive files | Files in users' OneDrive, who they're shared with, and the personal data in their content | Files.Read.All |
| Scan Copilot activity and agents | Copilot usage, the files and sites Copilot accessed (from the audit log), Copilot Studio agents, the agent catalog and the agent registry. Doesn't read prompts or responses | Reports.Read.All, AuditLogsQuery.Read.All, CopilotPackages.Read.All |
| Scan Copilot prompts and responses | The text of users' Copilot prompts and responses, and the personal data in them | AiEnterpriseInteraction.Read.All |
Users, groups, licences and applications from Microsoft Entra are always scanned; no checkbox controls them. Relyance needs them to work out who the sharing links, file access and Copilot activity belong to.
Authentication methods and fields
Pick one of these under Authentication Method on the connection wizard's Authentication step. This table is generated from the integration catalog, so it always matches what the form actually asks for.
| Method | Required | Optional |
|---|---|---|
| Oauth2 / App Token | — | Scan SharePoint files, Scan OneDrive files, Scan Copilot activity and agents, Scan Copilot prompts and responses |
| Relyance app (admin consent) | Tenant ID |
Scan SharePoint files, Scan OneDrive files, Scan Copilot activity and agents, Scan Copilot prompts and responses |
Verify the connection is really working
For a Relyance app (admin consent) connection:
- Authentication fails when admin consent hasn't been granted, or was granted in a different tenant from the Tenant ID on the connection. Check both in the Entra admin center under Enterprise applications → Relyance AI → Permissions.
- A scan area stops working after someone changed the app's permissions in Entra. Grant admin consent again with the link in step 2 to restore them.
For an Oauth2 / App Token connection:
- Connected but nothing discovered is admin consent on
User.Read.All. - Data subject requests fail while discovery works. DSR handling needs
User.ReadWrite.AllandDirectory.ReadWrite.All— write scopes, granted separately from the read-only discovery scope. Enabling the DSR feature without adding and re-consenting them leaves requests failing while everything else looks healthy. offline_accessis what keeps the connection alive. Without it the refresh token is not issued and the connection stops at the first token expiry, typically an hour in, which reads as an intermittent fault rather than a missing scope.
Manage this integration with Terraform
Connections for this integration can be managed as code with the Relyance Terraform provider. Non-secret fields go in auth.params; secret fields go in auth.secrets_wo, which is write-only — never stored in Terraform state. Rotate secrets by bumping auth.secrets_wo_version.
OAuth (browser authorization)
The OAuth (browser authorization) method uses a browser authorization flow, so the connection is created in the Relyance app. Manage it in Terraform afterwards by importing it (terraform import relyance_integration_connection.example microsoft365/<connection_id>) or reading it with the relyance_integration_connection data source.
OAuth client credentials
resource "relyance_integration_connection" "microsoft365_1" {
vendor = "microsoft365"
name = "<your connection name>"
auth = {
method = "oauth-client-credentials"
params = {
tenant_id = "<tenant_id>"
data_storage_location = "us"
}
}
scans = { "property-inspection" = { enabled = true } }
}