Skip to main content
Use this guide to prepare the Microsoft side of a connection. Then follow Microsoft connections for each client for Alignr’s default, override and mapping controls. For a first client, Direct is the route when the client is outside your partner relationship. Partner Center uses your MSP’s delegated customer access. Intune device evidence currently uses Direct.

Gather the prerequisites

  • The client’s Microsoft tenant ID and the matching Alignr client.
  • An Alignr account with integration.read and integration.manage, plus access to the client.
  • For Direct, a client administrator authorised to grant the requested application permissions.
  • For Partner Center, an authorised partner user with MFA, an active customer relationship, the relevant GDAP role assignments and customer application consent.
  • Licences for the Microsoft workloads being assessed. For example, reading signInActivity requires Entra ID P1 or P2 as well as AuditLog.Read.All; an accessible user list does not establish this capability. Microsoft’s user API requirements.
GDAP means granular delegated admin privileges. A partner relationship, application consent and the delegated user’s assigned roles are separate prerequisites. Microsoft’s GDAP application guidance explains that relationship.

Choose the permission model

Microsoft treats application permissions differently from delegated permissions even when their names are identical. Do not add delegated grants to a custom Direct application and expect application-token collection to work.

Direct: authorise the intended client

1

Select Direct in Alignr

Open Clients → select client → Connections → Microsoft setup. Set Connection method to Direct, enter the client’s Microsoft tenant ID, then Save preference.
2

Prepare the selected application

Under Authorise this client directly, use the Alignr application unless your deployment requires a custom registration. Select Set up direct connection to prepare the Entra and Intune connections.If the shared application is unavailable, ask the deployment administrator to configure it or use the supported custom-application option. Creating an Alignr client does not configure a Microsoft application.
3

Review and grant consent

Select Authorise Microsoft. Confirm that Microsoft’s screen identifies the intended client and application, and review the requested access before approving it.The approver must be able to consent to Graph application permissions. Microsoft lists Privileged Role Administrator for granting any API permission; Application Administrator or Cloud Application Administrator alone does not cover Microsoft Graph application roles. Use an appropriately authorised role under your organisation’s policy. Microsoft admin-consent prerequisites.
4

Probe the available workloads

Return to Alignr and select Check access. Review each available and unavailable capability. Follow Check Microsoft Intune access for device coverage.The consent return verifies the selected tenant and authorisation ceremony. It is not a full workload test. A sample that passes does not prove access to every user or mailbox.

Direct read-permission reference

For the read families used by the current collectors, review these Graph application permissions. This is a preparation reference, not a claim about the exact grants configured on your deployment’s shared application. The Microsoft consent screen and saved application grants remain the record of what is actually requested and approved. Some APIs accept broader alternatives; do not add broad write access to solve a read-coverage gap. Microsoft documents AuditLog.Read.All for the registration report. Reports.Read.All alone is not the documented permission for that endpoint. The report also does not work for disabled users, so absence of a row is not proof of no registration. For a custom application, review its API permissions in Microsoft Entra, choose the appropriate application permissions and grant authorised admin consent. Supply its Application client ID and Application secret through Alignr’s custom-application form. The custom registration must also support the consent callback configured for your Alignr deployment; obtain that exact callback from the deployment administrator rather than inventing one.

Partner: authorise the MSP, then the customer

  1. In Settings → Microsoft, choose Partner Center · use your partner account, select or add the partner connection and Save Microsoft defaults.
  2. Select Authorise partner account and sign in to the intended MSP partner tenant with MFA. The current authorisation requests Partner Center user_impersonation, offline_access, and Graph User.Read / User.Read.All for the MSP staff-directory preview. This is not customer Graph consent. Partner Center authentication.
  3. Review and assign the customer’s tenant to its Alignr client.
  4. Open the client’s Connections, confirm the saved Partner Center route and tenant ID, then select Connect client.
  5. Review the result. This action checks access and can request missing customer read consent where authorised; it does not create GDAP relationships or grant the partner user new customer roles.
The current customer-consent request contains these delegated Graph permissions:
The assigned GDAP roles must also permit the workload reads. For example, the registration-report API documents delegated roles including Reports Reader, Security Reader, Security Administrator and Global Reader. A consented scope alone is insufficient. Delegated mailbox settings access also does not establish access to every customer’s mailbox; inspect the sampled check and collected evidence before relying on it.

Complete the evidence loop

Each arrow is a task to complete, not an automatic trigger. Use Sync now on the relevant integration and inspect Sync history. Then inspect current observations for a known client account or device and run the standard.

Resolve the specific gap

Finish when: the selected tenant is correct, required workload access has been checked, fresh observations are visible and the resulting assessment can be traced to them. These instructions combine current Alignr behaviour with Microsoft’s published requirements; they do not certify access in your tenant without those checks.