Overview

The Microsoft Office 365 integration monitors your organization’s Microsoft Office 365 environment: user accounts, MFA enrollment, mailbox security settings, license assignments, and audit logs. LowerPlane uses read-only access via Microsoft Graph API with OAuth 2.0.

Prerequisites

Ensure you have Global Administrator or Application Administrator access on your Microsoft Office 365 tenant to authorize the connection.

How to Connect

1

Open Integrations

Navigate to Settings > Integrations in LowerPlane.
2

Select Microsoft Office 365

Find Microsoft Office 365 under Identity & Access and click Connect.
3

Authorize with Microsoft

You will be redirected to the Microsoft login page. Sign in with your admin credentials and review the requested permissions.
4

Grant Consent

Click Accept to authorize LowerPlane to read your organization’s directory and security data. Admin consent is required for organization-wide access.
5

Confirm Connection

Once authorized, you will be redirected back to LowerPlane confirming the successful integration. The initial sync will begin automatically.

Permissions Requested

LowerPlane requests the following Microsoft Graph API permissions (all read-only):
PermissionWhat It GrantsWhy LowerPlane Needs It
User.Read.AllRead all user profilesList all users for access reviews, MFA verification, and offboarding checks
Organization.Read.AllRead organization dataRead tenant settings, license assignments, and subscription details
Reports.Read.AllRead usage reportsAccess MFA registration status and credential usage reports
Directory.Read.AllRead directory dataRead group memberships, roles, and organizational structure
AuditLog.Read.AllRead audit logsCollect sign-in and directory audit events for compliance evidence
LowerPlane does not request write permissions. It cannot modify users, reset passwords, send emails, or change any settings in your Microsoft Office 365 tenant.

What LowerPlane Collects

User Accounts

All Microsoft Office 365 users with profile data: name, email, department, job title, account status (enabled/disabled), and last sign-in.

MFA Status

Multi-factor authentication enrollment status per user, including registered authentication methods.

License Assignments

License assignments per user (E3, E5, Business Premium, etc.) to verify appropriate access levels.

Mailbox Security

Mailbox forwarding rules, auto-reply configurations, and external sharing settings.

Groups & Roles

Security groups, Microsoft Office 365 groups, and administrative role assignments.

Audit Logs

Directory and sign-in audit events for security monitoring and compliance evidence.

Compliance Mapping

FrameworkControlsWhat It Proves
SOC 2CC6.1, CC6.2, CC6.3User access controls, authentication, and authorization are managed
ISO 27001A.5.15, A.5.16, A.5.17, A.8.2Access control policy, user registration, and authentication management
HIPAA164.312(a), 164.312(d)Access controls and person authentication for ePHI systems
GDPRArt. 5(1)(f), Art. 32Security of processing and appropriate technical measures

FAQ

Microsoft Office 365 covers the full productivity suite — users, licenses, mailbox settings, and usage reports. Microsoft Entra ID (Azure AD) focuses on identity infrastructure — conditional access policies, enterprise applications, and advanced sign-in analytics. You can connect both for comprehensive coverage.
Basic user and MFA data works with any Microsoft Office 365 plan. Some features like detailed sign-in logs and conditional access reports require Azure AD Premium P1 or P2.
Microsoft Office 365 data syncs every 24 hours by default. You can trigger a manual sync from the integration settings.
Yes. If your organization uses multiple Microsoft Office 365 tenants, you can connect each one as a separate integration instance.
No. LowerPlane only reads mailbox settings (forwarding rules, auto-reply status). It does not access email content, attachments, or calendar events.