Microsoft 365
Microsoft 365 (via Graph) integration
Reads each client's Microsoft 365 licenses — bought versus assigned — and, where allowed, who has set up MFA. Account addresses are checked against public breach data (Have I Been Pwned) and never stored; only counts are kept. Never mail or files, and nothing that can make changes.
Setup steps are for connected customers — sign in to read them.
What we find in Microsoft 365 (via Graph)
License waste (purchased vs assigned).
Every finding lands on your Client Upsell board as a named client with a number beside it — not a report you have to read.
What the Microsoft 365 (via Graph) connection does
Read — powers Client Upsell
Read your clients' stack
Licenses purchased versus assigned, and MFA registration where consented.
Read-only
We only ever read — we never change anything in Microsoft 365 (via Graph)
You make a view-only key using our setup steps. Our connection has no code that can write to Microsoft 365 (via Graph), and your key is encrypted and only used to read.
Microsoft 365 (via Graph) integration — common questions
- What does the Microsoft 365 (via Graph) integration read?
- Reads each client's Microsoft 365 licenses — bought versus assigned — and, where allowed, who has set up MFA. Account addresses are checked against public breach data (Have I Been Pwned) and never stored; only counts are kept. Never mail or files, and nothing that can make changes.
- What does MSProspector find in Microsoft 365 (via Graph)?
- License waste (purchased vs assigned).
- Is the Microsoft 365 (via Graph) connection read-only?
- Yes. We only ever read from Microsoft 365 (via Graph) — our Microsoft 365 (via Graph) connection has no code that can change anything, and an automated check on every change to our code blocks any that could. Please create a view-only key using the setup steps, so the key itself can't make changes either.
