LowerPlane supports multiple Microsoft integrations, each covering a different aspect of your Microsoft ecosystem. All use OAuth 2.0 via Microsoft Graph API with read-only permissions.

Microsoft Office 365

Users, mailbox security, licenses, MFA

Microsoft Entra ID

Identity, conditional access, sign-in logs

Microsoft Teams

Team membership, guest access, channels

Microsoft Intune

Device compliance, encryption, security

Dynamics 365 Sales

CRM user access and role monitoring

Microsoft Office 365

Connect Microsoft Office 365 to monitor user accounts, mailbox security, MFA enrollment, and license assignments.

Prerequisites

Ensure you have Global Administrator or Application Administrator access on your Microsoft Office 365 tenant.

How to Connect

1

Navigate to Integrations

Go to Settings > Integrations in LowerPlane.
2

Select Microsoft Office 365

Find Microsoft Office 365 under Identity & Access and click Connect.
3

Authorize

You will be redirected to the Microsoft login page. Sign in with your admin credentials and click Accept to grant read-only permissions.
4

Confirm

You will be redirected back to LowerPlane confirming the successful connection.

What’s Collected

User accounts, MFA status, license assignments, mailbox forwarding rules, groups, and audit logs.

Microsoft Entra ID

Connect Microsoft Entra ID (formerly Azure AD) to sync your user directory for managing onboarding and offboarding status.

Prerequisites

Ensure you have Global Administrator access on your Azure tenant.

How to Find Your Tenant ID

1

Sign in to Azure

Go to the Azure Portal and sign in with your admin account.
2

Open Microsoft Entra ID

Under Azure Services, select Microsoft Entra ID (or search for it in the top search bar).
3

Copy Tenant ID

In the Overview section, find Basic Information. Copy the Tenant ID — you’ll need it when connecting in LowerPlane.

How to Connect

1

Navigate to Integrations

Go to Settings > Integrations in LowerPlane.
2

Select Microsoft Entra ID

Find Microsoft Entra ID and click Connect.
3

Authorize with OAuth

You will be redirected to Microsoft. Sign in and grant consent for read-only directory access.
4

Confirm

Once authorized, LowerPlane begins syncing your user directory automatically.

What’s Collected

Users, groups, MFA enrollment, conditional access policies, sign-in logs, and administrative role assignments.

Microsoft Teams

Connect Microsoft Teams to monitor team membership, guest access, and communication security settings.

Prerequisites

Ensure you have Teams Administrator or Global Administrator access.

How to Connect

1

Navigate to Integrations

Go to Settings > Integrations in LowerPlane.
2

Select Microsoft Teams

Find Microsoft Teams and click Connect.
3

Authorize

Sign in with your admin credentials and grant the requested read-only permissions.
4

Add as Critical System

After connecting, go to Personnel > Access Reviews > Critical Systems and click Add Critical System. Search for “Microsoft Teams” and add it to start monitoring user access.

What’s Collected

Teams, channels, team members, guest users, and team settings.

Microsoft Intune

Connect Microsoft Intune to monitor device compliance, encryption status, and security configurations across managed Windows, macOS, iOS, and Android devices.

Prerequisites

Ensure you have Intune Administrator or Global Administrator access.

How to Connect

1

Navigate to Integrations

Go to Settings > Integrations in LowerPlane.
2

Select Microsoft Intune

Find Microsoft Intune and click Connect.
3

Authorize

You will be redirected to Microsoft. Sign in with your admin credentials and grant the necessary permissions for device security data.
4

Confirm

Once authenticated, you will be redirected back to LowerPlane confirming the successful connection. Device data begins syncing automatically.

What’s Collected

Managed devices, compliance status, encryption (BitLocker/FileVault) status, OS version, and device configuration profiles.

Microsoft Dynamics 365 Sales

Connect Microsoft Dynamics 365 Sales to monitor CRM user access, roles, and security configurations.

Prerequisites

Ensure you have System Administrator role in Dynamics 365.

How to Connect

1

Navigate to Integrations

Go to Settings > Integrations in LowerPlane.
2

Select Dynamics 365 Sales

Find Microsoft Dynamics 365 Sales and click Connect.
3

Authorize

Sign in and grant the requested permissions.
4

Add as Critical System

After connecting, go to Personnel > Access Reviews > Critical Systems and click Add Critical System. Search for “Microsoft Dynamics 365 Sales” and add it to start monitoring user access.

What’s Collected

CRM users, role assignments, and access control configurations.

Compliance Mapping

All Microsoft integrations contribute to the following framework controls:
FrameworkControlsCoverage
SOC 2CC6.1, CC6.2, CC6.3, CC6.6User access, authentication, and device security
ISO 27001A.5.15–A.5.18, A.8.1, A.8.2Access control, asset management
HIPAA164.312(a), 164.312(d)Access controls and authentication
GDPRArt. 5(1)(f), Art. 32Security of processing

FAQ

Yes. Each integration has its own OAuth consent and API permissions. Microsoft Office 365 covers productivity, Entra ID covers identity, Teams covers collaboration, Intune covers devices, and Dynamics 365 covers CRM.
No. All integrations use read-only API permissions. LowerPlane cannot create, modify, or delete any data in your Microsoft environment.
Basic user and MFA data works with any Microsoft Office 365 plan. Advanced features (conditional access policies, detailed sign-in logs) require Azure AD Premium P1 or P2.