Before you begin
- Create or identify the correct Alignr client.
- Have the Microsoft tenant ID belonging to that client, rather than your MSP’s tenant ID or its Alignr Organization ID.
- Use a role with
integration.readto view connection settings andintegration.manageto change them. You also need access to the client. - For Direct, arrange for a client administrator who can approve the requested Microsoft application permissions. For Partner Center, your partner authorisation, customer consent and GDAP access must be in place.
Understand the default and the client choice
The default chooses a method; it does not authorise every client. The partner account itself is selected at workspace level. There is no separate partner-account picker in the client form.
Alignr uses the selected route for Microsoft evidence. If it is incomplete, the client has a visible setup gap; Alignr does not silently switch to the other route to fill it.
Set your usual workspace connection
Open Settings → Microsoft. Under How your clients connect, choose Default connection method:- Usually Partner Center
- Usually Direct
- Choose Partner Center · use your partner account.
- Choose an enabled live Partner account, or select Add partner connection.
- Select Save Microsoft defaults.
- Select Authorise partner account and complete Microsoft’s authorisation.
- Return to each client’s Connections tab to confirm its customer assignment and access.
Connect a client outside your partner relationship
Use this path when the client is not in Partner Center, has no suitable GDAP relationship, or needs the supported Direct route for Intune device checks.1
Open the client's Microsoft settings
Open Clients, select the client, then Connections. Find How this client connects in the Microsoft section.Check the client name before making changes. This is a client preference, so you do not need to change the workspace default for your other clients.
2
Save a Direct preference
Set Connection method to Direct. Enter the client’s Microsoft tenant ID and select Save preference.Checkpoint: the saved summary says Currently using Direct. Choosing an option without saving has not changed the active route.
3
Prepare the direct connection
Under Authorise this client directly, leave Use my own Microsoft application unticked to use the Alignr application. Select Set up direct connection.Alignr prepares the client’s Entra ID and Intune connections and their client mappings. Preparing those records is not Microsoft consent.If this client already has a direct connection, review the existing connection panel instead of creating another. For a different application or tenant, see Replace an existing connection.
4
Authorise the client tenant
Select Authorise Microsoft in the direct-access panel. Complete the Microsoft authorisation with an administrator of the intended client tenant. Review the requested access on Microsoft’s screen.Alignr uses the client’s direct consent for this route; a partner GDAP relationship is not its prerequisite. Do not authorise your MSP tenant in place of the client’s tenant.
5
Check access, then collect
Return to the client’s connection and select Check access. Review the available and unavailable capabilities. For device evidence, also follow Check Microsoft Intune access and review that connection.Once the required access is available, open the relevant integration, use Sync now when available and inspect Sync history. Confirm fresh evidence belongs to the intended client before running checks.Checkpoint: the client uses Direct, its tenant is correct, and current observations come from its selected connection.
Connect a client through your partner account
In Clients → select client → Connections, choose Use workspace default when that default is Partner Center, or explicitly choose Partner Center. Confirm Microsoft tenant ID and select Save preference. Under Connect this Microsoft customer:- Confirm that the displayed customer name and tenant ID belong to this client.
- If an assignment is missing, use Assign Microsoft customer to review and link the correct customer record.
- Select Connect client. This checks access and, where authorised, requests missing customer read consent. Your existing GDAP roles must allow it.
- Review any unavailable capabilities. The access check does not create a GDAP relationship, collect evidence or run the client’s controls.
- Sync the selected connection, inspect collected observations and then run the assessment.
Change a preference deliberately
Changing the workspace default affects clients that inherit it. Clients explicitly set to Direct or Partner Center keep their chosen method. A client explicitly using Partner Center still depends on the partner account selected in workspace settings. To restore inheritance, open the client’s Connections, choose Use workspace default and select Save preference. Read the Currently using… summary to confirm the resolved method. If workspace setup is incomplete, the form asks you to finish it or choose a client-specific method. After a route change, review access, collect current evidence and evaluate again. A previous result does not prove the new connection is working.Replace an existing connection
For an existing Direct connection, expand Use a different Microsoft application or tenant and select Set up a different connection. Then prepare and authorise the intended new connection. Current Microsoft evidence stops contributing until the replacement is authorised and synced. Previous connections and history remain in Integrations. Review the tenant ID before proceeding; changing the client setting is not permission to use evidence from a different business. If your organisation needs its own application registration, select Use my own Microsoft application during direct setup and provide Application client ID and Application secret. That application still needs the required Microsoft permissions and consent. Keep the secret in the connection form, never in assessment notes or support screenshots.If setup needs attention
You are ready to continue when you can name the client’s selected method, its Microsoft tenant, the connection supplying its evidence and any capabilities still unavailable.
Next: check collection and coverage
Confirm that authorised access produces the observations your controls need.