Docs / Integration Guides / Microsoft 365 / InfraAudit
Microsoft 365 / InfraAudit
Integration guide
InfraAudit's Microsoft 365 collection uses delegated Microsoft Graph permissions via a client's own admin consent — Graften never stores a client's M365 admin password.
Setup
- From the client's record, go to Connections → Add Connection → Microsoft 365.
- You'll be sent through Microsoft's admin consent flow for the client's tenant. The client's own Global Admin (or someone with sufficient delegated permissions) needs to approve this — it can't be done on their behalf without their tenant access.
- Once consented, POST /api/v1/audit/run with that client's ID kicks off a real audit using Microsoft Graph, Exchange Online, and Teams APIs to inventory users, licensing, mailboxes, Conditional Access policies, and admin roles.
Common setup issues
- Conditional Access blocking the audit's own sign-in — if the client has strict CA policies (e.g. blocking legacy auth or unfamiliar locations), the audit's own service connection can get blocked. This needs an explicit CA exclusion for Graften's audit service principal.
- Missing public folder mailboxes — older M365 tenants sometimes have public folders that were never properly migrated, which can cause partial EXO collection. Not something Graften can fix — flag it back to the client as a finding, not a Graften bug.
- **Deprecated
ApplicationImpersonationrole** — Microsoft has been phasing this out tenant-by-tenant; if a tenant's already had it removed, certain legacy EXO calls will fail and the collector falls back to a reduced permission set automatically.