Overview
The Microsoft Office 365 integration monitors your organization’s Microsoft Office 365 environment: user accounts, MFA enrollment, mailbox security settings, license assignments, and audit logs. LowerPlane uses read-only access via Microsoft Graph API with OAuth 2.0.Prerequisites
How to Connect
Authorize with Microsoft
You will be redirected to the Microsoft login page. Sign in with your admin credentials and review the requested permissions.
Grant Consent
Click Accept to authorize LowerPlane to read your organization’s directory and security data. Admin consent is required for organization-wide access.
Permissions Requested
LowerPlane requests the following Microsoft Graph API permissions (all read-only):| Permission | What It Grants | Why LowerPlane Needs It |
|---|---|---|
User.Read.All | Read all user profiles | List all users for access reviews, MFA verification, and offboarding checks |
Organization.Read.All | Read organization data | Read tenant settings, license assignments, and subscription details |
Reports.Read.All | Read usage reports | Access MFA registration status and credential usage reports |
Directory.Read.All | Read directory data | Read group memberships, roles, and organizational structure |
AuditLog.Read.All | Read audit logs | Collect sign-in and directory audit events for compliance evidence |
LowerPlane does not request write permissions. It cannot modify users, reset passwords, send emails, or change any settings in your Microsoft Office 365 tenant.
What LowerPlane Collects
User Accounts
All Microsoft Office 365 users with profile data: name, email, department, job title, account status (enabled/disabled), and last sign-in.
MFA Status
Multi-factor authentication enrollment status per user, including registered authentication methods.
License Assignments
License assignments per user (E3, E5, Business Premium, etc.) to verify appropriate access levels.
Mailbox Security
Mailbox forwarding rules, auto-reply configurations, and external sharing settings.
Groups & Roles
Security groups, Microsoft Office 365 groups, and administrative role assignments.
Audit Logs
Directory and sign-in audit events for security monitoring and compliance evidence.
Compliance Mapping
| Framework | Controls | What It Proves |
|---|---|---|
| SOC 2 | CC6.1, CC6.2, CC6.3 | User access controls, authentication, and authorization are managed |
| ISO 27001 | A.5.15, A.5.16, A.5.17, A.8.2 | Access control policy, user registration, and authentication management |
| HIPAA | 164.312(a), 164.312(d) | Access controls and person authentication for ePHI systems |
| GDPR | Art. 5(1)(f), Art. 32 | Security of processing and appropriate technical measures |
FAQ
What's the difference between Microsoft Office 365 and Microsoft Entra ID integrations?
What's the difference between Microsoft Office 365 and Microsoft Entra ID integrations?
Microsoft Office 365 covers the full productivity suite — users, licenses, mailbox settings, and usage reports. Microsoft Entra ID (Azure AD) focuses on identity infrastructure — conditional access policies, enterprise applications, and advanced sign-in analytics. You can connect both for comprehensive coverage.
Does this require Azure AD Premium?
Does this require Azure AD Premium?
How often does LowerPlane sync?
How often does LowerPlane sync?
Microsoft Office 365 data syncs every 24 hours by default. You can trigger a manual sync from the integration settings.
Can I connect multiple Microsoft Office 365 tenants?
Can I connect multiple Microsoft Office 365 tenants?
Yes. If your organization uses multiple Microsoft Office 365 tenants, you can connect each one as a separate integration instance.
Does LowerPlane read email content?
Does LowerPlane read email content?
No. LowerPlane only reads mailbox settings (forwarding rules, auto-reply status). It does not access email content, attachments, or calendar events.