Connect Microsoft 365¶
Trimtab scans a client's Microsoft 365 tenant with a read-only app. A Global Administrator of the tenant approves it once.
Connect the tenant¶
- In the Bridge, open Clients and find the client.
- Under Microsoft 365, select Connect Microsoft 365.
- Sign in as a Global Administrator of the client's tenant.
- Review the permissions and select Accept.
- You return to the Bridge and see Tenant connected. The first scan runs within a couple of minutes. Select View tenant.
Unverified publisher
Microsoft may label the app as unverified until Trimtab completes Microsoft's publisher verification. The permissions it asks for are all read-only, listed below.
Enable Exchange Online checks¶
Exchange settings need one extra step: assigning a read-only directory role to the Trimtab app.
- In the client's Microsoft Entra admin center, go to Identity → Roles & admins → Roles & admins.
- Search for and open Global Reader.
- Select Add assignments, then search for Trimtab M365 Scanner, select it, and assign it.
- Back in the Bridge, open the tenant and select Scan now. Role changes can take up to an hour to reach Exchange Online.
Until the role is assigned, the Exchange checks show as not evaluated. The DMARC check still runs because it only uses public DNS.
What Trimtab can access¶
| Permission | Type | Used for |
|---|---|---|
| Policy.Read.All | Microsoft Graph, application | Security defaults, Conditional Access, consent and guest settings |
| Directory.Read.All | Microsoft Graph, application | Users, groups, and domains |
| RoleManagement.Read.Directory | Microsoft Graph, application | Global Administrator count |
| AuditLog.Read.All | Microsoft Graph, application | MFA registration and sign-in activity |
| SecurityEvents.Read.All | Microsoft Graph, application | Microsoft Secure Score |
| SharePointTenantSettings.Read.All | Microsoft Graph, application | SharePoint and OneDrive sharing settings |
| Organization.Read.All | Microsoft Graph, application | Organization name and verified domains |
| Exchange.ManageAsApp | Exchange Online, application | Read-only Exchange settings (requires the Global Reader role) |
Trimtab doesn't read email, files, chats, or calendars.
Licensing notes¶
- Microsoft Entra ID P1 is needed for the MFA registration and inactive account checks. Without it, those show as not evaluated and don't affect the score.
- Tenants without Exchange Online show the Exchange checks as not evaluated.
Scans¶
Tenants are scanned once a day. To scan now, open the tenant in the Bridge and select Scan now, or select Rescan tenants on the Fleet page to scan every tenant.
Disconnect a tenant¶
- Open the tenant in the Bridge and select Disconnect. Trimtab stops scanning it.
- To remove access completely, delete Trimtab M365 Scanner from the tenant's Entra admin center → Enterprise applications.
Reconnect¶
If permissions change in a future release, select Connect Microsoft 365 again for the same client and approve. The tenant keeps its history.