Docs
relyance.ai ↗
Browse docs

Microsoft 365

Updated November 4, 2025View as Markdown ↗

Microsoft_365_logo.png

Microsoft 365 is a cloud-based productivity platform. It provides a suite of online products such as Microsoft Teams, Word, Excel, PowerPoint, Outlook, OneDrive, and more.

You can connect Microsoft 365 to Relyance AI in two ways. Pick one under Authentication Method on the connection wizard's Authentication step:

  • Relyance app (admin consent). A Microsoft Entra administrator grants the Relyance AI application read access to your tenant once. Relyance then connects as that application, not as a person, so the connection doesn't depend on any one user's account or sign-in. You don't create an app registration or handle any secret. See Connect with the Relyance app (admin consent).
  • Oauth2 / App Token. A user signs in to Microsoft during the wizard and Relyance connects on their behalf. This is the original method and keeps working for existing connections. The steps are below.

Both methods offer the same checkboxes for which Microsoft 365 data is scanned. See Choose what is scanned.

Connect with Oauth2 / App Token

In the Relyance AI application:

  1. Login to your Relyance AI account.
  2. Navigate to the Settings (bottom-left corner).
  3. Select Integrations.
  4. Search and locate the Microsoft 365 integration card and click on it.
  5. Click on the Add Connection button on the top right.
  6. Provide a meaningful name for the integration and click on the Add button.
    Screenshot
  7. In the Overview section, select the integration features you wish to enable for the integration, review the Scope and Permission, and Endpoint details and click on Continue. Note: For more details, see Integration Features.
    Screenshot 2025-11-04 101627.png
  8. In the Connection section, provide the appropriate values and click on Continue,
    • Connection Name: This property allows you to update the integration specified in Step 6. If you have multiple integrations for the same vendor, you may want to assign distinct names to each. This helps streamline filtering by Discovery Source across the Inventory, Visual Maps, Assets, and Data Flow Analysis pages.
    • Rescan Frequency: This property allows you to configure how often Relyance executes scans against this Vendor connection.
    • Business Atlas Associations (required): the business entities or products that newly discovered third parties, services and assets from this integration are attributed to. Choose at least one from the Select Associations dropdown — the wizard will not advance past this step without one. Note: For more details, see Business Atlas.
      Screenshot
  9. In the Authentication section, choose Oauth2 / App Token, choose what to scan (see Choose what is scanned), and click on Continue.
    Screenshot
  10. Review the configuration summary from the Completion section and click on Finish.
    Screenshot
  11. Confirm the integration Status reflects Connected.

In Microsoft Entra

Someone with the Global Administrator or Privileged Role Administrator role does these steps. Only those roles can grant an application tenant-wide access to Microsoft Graph.

  1. Note your tenant ID. In the Microsoft Entra admin center, open Overview and copy the Tenant ID, for example 00000000-1111-2222-3333-444444444444.

  2. Grant admin consent. Open this link in a browser, replacing <your-tenant-id> with the tenant ID from step 1:

    https://login.microsoftonline.com/<your-tenant-id>/adminconsent?client_id=4662deb0-baed-4ae4-a175-2f4fa1a7ff3e

    Sign in, review the permissions listed under Permissions the Relyance app requests, and click Accept. Microsoft then sends your browser to a Relyance page, which you can close. The consent is already recorded.

  3. Check that consent was granted. In the Entra admin center, open Enterprise applications, find Relyance AI (application ID 4662deb0-baed-4ae4-a175-2f4fa1a7ff3e), and open Permissions. Every permission should show as granted for your organization.

In the Relyance AI application

  1. Log in to your Relyance AI account.
  2. Open Settings (bottom left) and select Integrations.
  3. Find the Microsoft 365 integration card and click it, then click Add Connection.
  4. Follow the wizard. On the Authentication step, choose Relyance app (admin consent) and fill in:
    • Tenant ID: from step 1.
    • The scan checkboxes: see Choose what is scanned.
    • Data Storage Location: where Relyance stores the data it collects.
  5. Click Authenticate and finish the wizard, then confirm the connection shows Connected.

To remove Relyance's access, delete the Relyance AI enterprise application from your tenant in the Entra admin center. This revokes the consent. Relyance can't get new access tokens after that, and any token already issued expires within about 90 minutes. Scans on the connection fail until consent is granted again.

Permissions the Relyance app requests

These are Microsoft Graph application permissions, all read-only. Admin consent grants them to the Relyance AI application in your tenant only. The consent screen also shows User.Read, the standard sign-in permission, which Relyance doesn't use to read your data.

Area Permission What Relyance reads with it
Directory Directory.Read.All Users, groups, applications and other directory objects
GroupMember.Read.All Group memberships
Application.Read.All App registrations and the third-party applications connected to your tenant
RoleManagement.Read.Directory Directory role assignments, such as who holds administrator roles
Policy.Read.All, Policy.Read.PermissionGrant Tenant policies, including which applications users may consent to
ConsentRequest.Read.All Pending requests from users for admin consent to applications
CustomSecAttributeAssignment.Read.All Custom security attributes assigned to users and applications
AuditLog.Read.All Directory audit and sign-in logs
SharePoint and OneDrive Sites.Read.All SharePoint sites, document libraries and their files' metadata
Files.Read.All Files in SharePoint and OneDrive, to classify their content
Copilot Reports.Read.All Microsoft 365 Copilot usage reports
AuditLogsQuery.Read.All The Purview audit log, for the files and sites Copilot accessed
CopilotPackages.Read.All The Microsoft 365 Copilot agent and app catalog
AiEnterpriseInteraction.Read.All The text of users' Copilot prompts and responses
Teams Team.ReadBasic.All, TeamMember.Read.All Teams and their members
Channel.ReadBasic.All, ChannelSettings.Read.All Channels in each team and their settings

Consent covers the whole application, so all of these are granted even if you turn a scan off. Turning a scan off stops Relyance from reading that data. See the next section.

Choose what is scanned

Both authentication methods have four checkboxes, all on by default. Turn one off and Relyance skips that data on every following scan.

Checkbox What it scans Main permissions it uses
Scan SharePoint files Files in SharePoint document libraries, who they're shared with, and the personal data in their content Sites.Read.All, Files.Read.All
Scan OneDrive files Files in users' OneDrive, who they're shared with, and the personal data in their content Files.Read.All
Scan Copilot activity and agents Copilot usage, the files and sites Copilot accessed (from the audit log), Copilot Studio agents, the agent catalog and the agent registry. Doesn't read prompts or responses Reports.Read.All, AuditLogsQuery.Read.All, CopilotPackages.Read.All
Scan Copilot prompts and responses The text of users' Copilot prompts and responses, and the personal data in them AiEnterpriseInteraction.Read.All

Users, groups, licences and applications from Microsoft Entra are always scanned; no checkbox controls them. Relyance needs them to work out who the sharing links, file access and Copilot activity belong to.

Authentication methods and fields

Pick one of these under Authentication Method on the connection wizard's Authentication step. This table is generated from the integration catalog, so it always matches what the form actually asks for.

Method Required Optional
Oauth2 / App Token — Scan SharePoint files, Scan OneDrive files, Scan Copilot activity and agents, Scan Copilot prompts and responses
Relyance app (admin consent) Tenant ID Scan SharePoint files, Scan OneDrive files, Scan Copilot activity and agents, Scan Copilot prompts and responses

Verify the connection is really working

For a Relyance app (admin consent) connection:

  • Authentication fails when admin consent hasn't been granted, or was granted in a different tenant from the Tenant ID on the connection. Check both in the Entra admin center under Enterprise applications → Relyance AI → Permissions.
  • A scan area stops working after someone changed the app's permissions in Entra. Grant admin consent again with the link in step 2 to restore them.

For an Oauth2 / App Token connection:

  1. Connected but nothing discovered is admin consent on User.Read.All.
  2. Data subject requests fail while discovery works. DSR handling needs User.ReadWrite.All and Directory.ReadWrite.All — write scopes, granted separately from the read-only discovery scope. Enabling the DSR feature without adding and re-consenting them leaves requests failing while everything else looks healthy.
  3. offline_access is what keeps the connection alive. Without it the refresh token is not issued and the connection stops at the first token expiry, typically an hour in, which reads as an intermittent fault rather than a missing scope.

Manage this integration with Terraform

Connections for this integration can be managed as code with the Relyance Terraform provider. Non-secret fields go in auth.params; secret fields go in auth.secrets_wo, which is write-only — never stored in Terraform state. Rotate secrets by bumping auth.secrets_wo_version.

OAuth (browser authorization)

The OAuth (browser authorization) method uses a browser authorization flow, so the connection is created in the Relyance app. Manage it in Terraform afterwards by importing it (terraform import relyance_integration_connection.example microsoft365/<connection_id>) or reading it with the relyance_integration_connection data source.

OAuth client credentials

resource "relyance_integration_connection" "microsoft365_1" {
  vendor = "microsoft365"
  name   = "<your connection name>"

  auth = {
    method = "oauth-client-credentials"
    params = {
      tenant_id = "<tenant_id>"
      data_storage_location = "us"
    }
  }

  scans = { "property-inspection" = { enabled = true } }
}