Gather the prerequisites
- The client’s Microsoft tenant ID and the matching Alignr client.
- An Alignr account with
integration.readandintegration.manage, plus access to the client. - For Direct, a client administrator authorised to grant the requested application permissions.
- For Partner Center, an authorised partner user with MFA, an active customer relationship, the relevant GDAP role assignments and customer application consent.
- Licences for the Microsoft workloads being assessed. For example, reading
signInActivityrequires Entra ID P1 or P2 as well asAuditLog.Read.All; an accessible user list does not establish this capability. Microsoft’s user API requirements.
Choose the permission model
Microsoft treats application permissions differently from delegated permissions even when their names are identical. Do not add delegated grants to a custom Direct application and expect application-token collection to work.
Direct: authorise the intended client
1
Select Direct in Alignr
Open Clients → select client → Connections → Microsoft setup. Set Connection method to Direct, enter the client’s Microsoft tenant ID, then Save preference.
2
Prepare the selected application
Under Authorise this client directly, use the Alignr application unless your deployment requires a custom registration. Select Set up direct connection to prepare the Entra and Intune connections.If the shared application is unavailable, ask the deployment administrator to configure it or use the supported custom-application option. Creating an Alignr client does not configure a Microsoft application.
3
Review and grant consent
Select Authorise Microsoft. Confirm that Microsoft’s screen identifies the intended client and application, and review the requested access before approving it.The approver must be able to consent to Graph application permissions. Microsoft lists Privileged Role Administrator for granting any API permission; Application Administrator or Cloud Application Administrator alone does not cover Microsoft Graph application roles. Use an appropriately authorised role under your organisation’s policy. Microsoft admin-consent prerequisites.
4
Probe the available workloads
Return to Alignr and select Check access. Review each available and unavailable capability. Follow Check Microsoft Intune access for device coverage.The consent return verifies the selected tenant and authorisation ceremony. It is not a full workload test. A sample that passes does not prove access to every user or mailbox.
Direct read-permission reference
For the read families used by the current collectors, review these Graph application permissions. This is a preparation reference, not a claim about the exact grants configured on your deployment’s shared application. The Microsoft consent screen and saved application grants remain the record of what is actually requested and approved.
Some APIs accept broader alternatives; do not add broad write access to solve a read-coverage gap. Microsoft documents
AuditLog.Read.All for the registration report. Reports.Read.All alone is not the documented permission for that endpoint. The report also does not work for disabled users, so absence of a row is not proof of no registration.
For a custom application, review its API permissions in Microsoft Entra, choose the appropriate application permissions and grant authorised admin consent. Supply its Application client ID and Application secret through Alignr’s custom-application form. The custom registration must also support the consent callback configured for your Alignr deployment; obtain that exact callback from the deployment administrator rather than inventing one.
Partner: authorise the MSP, then the customer
- In Settings → Microsoft, choose Partner Center · use your partner account, select or add the partner connection and Save Microsoft defaults.
- Select Authorise partner account and sign in to the intended MSP partner tenant with MFA. The current authorisation requests Partner Center
user_impersonation,offline_access, and GraphUser.Read/User.Read.Allfor the MSP staff-directory preview. This is not customer Graph consent. Partner Center authentication. - Review and assign the customer’s tenant to its Alignr client.
- Open the client’s Connections, confirm the saved Partner Center route and tenant ID, then select Connect client.
- Review the result. This action checks access and can request missing customer read consent where authorised; it does not create GDAP relationships or grant the partner user new customer roles.
Complete the evidence loop
Each arrow is a task to complete, not an automatic trigger. Use Sync now on the relevant integration and inspect Sync history. Then inspect current observations for a known client account or device and run the standard.Resolve the specific gap
Finish when: the selected tenant is correct, required workload access has been checked, fresh observations are visible and the resulting assessment can be traced to them. These instructions combine current Alignr behaviour with Microsoft’s published requirements; they do not certify access in your tenant without those checks.