Skip to content

Connect Microsoft 365

Trimtab scans a client's Microsoft 365 tenant with a read-only app. A Global Administrator of the tenant approves it once.

Connect the tenant

  1. In the Bridge, open Clients and find the client.
  2. Under Microsoft 365, select Connect Microsoft 365.
  3. Sign in as a Global Administrator of the client's tenant.
  4. Review the permissions and select Accept.
  5. You return to the Bridge and see Tenant connected. The first scan runs within a couple of minutes. Select View tenant.

Unverified publisher

Microsoft may label the app as unverified until Trimtab completes Microsoft's publisher verification. The permissions it asks for are all read-only, listed below.

Enable Exchange Online checks

Exchange settings need one extra step: assigning a read-only directory role to the Trimtab app.

  1. In the client's Microsoft Entra admin center, go to Identity → Roles & admins → Roles & admins.
  2. Search for and open Global Reader.
  3. Select Add assignments, then search for Trimtab M365 Scanner, select it, and assign it.
  4. Back in the Bridge, open the tenant and select Scan now. Role changes can take up to an hour to reach Exchange Online.

Until the role is assigned, the Exchange checks show as not evaluated. The DMARC check still runs because it only uses public DNS.

What Trimtab can access

Permission Type Used for
Policy.Read.All Microsoft Graph, application Security defaults, Conditional Access, consent and guest settings
Directory.Read.All Microsoft Graph, application Users, groups, and domains
RoleManagement.Read.Directory Microsoft Graph, application Global Administrator count
AuditLog.Read.All Microsoft Graph, application MFA registration and sign-in activity
SecurityEvents.Read.All Microsoft Graph, application Microsoft Secure Score
SharePointTenantSettings.Read.All Microsoft Graph, application SharePoint and OneDrive sharing settings
Organization.Read.All Microsoft Graph, application Organization name and verified domains
Exchange.ManageAsApp Exchange Online, application Read-only Exchange settings (requires the Global Reader role)

Trimtab doesn't read email, files, chats, or calendars.

Licensing notes

  • Microsoft Entra ID P1 is needed for the MFA registration and inactive account checks. Without it, those show as not evaluated and don't affect the score.
  • Tenants without Exchange Online show the Exchange checks as not evaluated.

Scans

Tenants are scanned once a day. To scan now, open the tenant in the Bridge and select Scan now, or select Rescan tenants on the Fleet page to scan every tenant.

Disconnect a tenant

  1. Open the tenant in the Bridge and select Disconnect. Trimtab stops scanning it.
  2. To remove access completely, delete Trimtab M365 Scanner from the tenant's Entra admin center → Enterprise applications.

Reconnect

If permissions change in a future release, select Connect Microsoft 365 again for the same client and approve. The tenant keeps its history.